{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T13:08:36Z","timestamp":1784034516275,"version":"3.55.0"},"reference-count":27,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2023,11,15]],"date-time":"2023-11-15T00:00:00Z","timestamp":1700006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"UK HEIF fund from the Cyber Security Research Center","award":["RES02M3732"],"award-info":[{"award-number":["RES02M3732"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>The use of the unindexed web, commonly known as the deep web and dark web, to commit or facilitate criminal activity has drastically increased over the past decade. The dark web is a dangerous place where all kinds of criminal activities take place, Despite advances in web forensic techniques, tools, and methodologies, few studies have formally tackled dark and deep web forensics and the technical differences in terms of investigative techniques and artefact identification and extraction. This study proposes a novel and comprehensive protocol to guide and assist digital forensic professionals in investigating crimes committed on or via the deep and dark web. The protocol, named D2WFP, establishes a new sequential approach for performing investigative activities by observing the order of volatility and implementing a systemic approach covering all browsing-related hives and artefacts which ultimately resulted in improving the accuracy and effectiveness. Rigorous quantitative and qualitative research has been conducted by assessing the D2WFP following a scientifically sound and comprehensive process in different scenarios and the obtained results show an apparent increase in the number of artefacts recovered when adopting the D2WFP which outperforms any current industry or opensource browsing forensic tools. The second contribution of the D2WFP is the robust formulation of artefact correlation and cross-validation within the D2WFP which enables digital forensic professionals to better document and structure their analysis of host-based deep and dark web browsing artefacts.<\/jats:p>","DOI":"10.3390\/jcp3040036","type":"journal-article","created":{"date-parts":[[2023,11,16]],"date-time":"2023-11-16T08:19:43Z","timestamp":1700122783000},"page":"808-829","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":14,"title":["D2WFP: A Novel Protocol for Forensically Identifying, Extracting, and Analysing Deep and Dark Web Browsing Activities"],"prefix":"10.3390","volume":"3","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7067-7848","authenticated-orcid":false,"given":"Mohamed Chahine","family":"Ghanem","sequence":"first","affiliation":[{"name":"Cyber Security Research Centre, London Metropolitan University, London N7 8DB, UK"},{"name":"Department of Computer Science, University of Liverpool, Liverpool L69 3BX, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Patrick","family":"Mulvihill","sequence":"additional","affiliation":[{"name":"Cyber Threat Intelligence, Grant Thornton UK LLP, London EC2A 1AG, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Karim","family":"Ouazzane","sequence":"additional","affiliation":[{"name":"Cyber Security Research Centre, London Metropolitan University, London N7 8DB, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ramzi","family":"Djemai","sequence":"additional","affiliation":[{"name":"Cyber Security Research Centre, London Metropolitan University, London N7 8DB, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-7376-0477","authenticated-orcid":false,"given":"Dipo","family":"Dunsin","sequence":"additional","affiliation":[{"name":"Cyber Security Research Centre, London Metropolitan University, London N7 8DB, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,11,15]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"141273","DOI":"10.1109\/ACCESS.2021.3119724","article-title":"Forensic Analysis of Tor Browser on Windows 10 and Android 10 Operating Systems","volume":"9","author":"Arshad","year":"2021","journal-title":"IEEE Access"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Brinson, R., Wimmer, H., and Cheng, L. (2022, January 24\u201326). Dark Web Forensics: An investigation of tracking dark web activity with digital forensics. Proceedings of the Interdisciplinary Research in Technology and Management (IRTM), Kolkata, India.","DOI":"10.1109\/IRTM54583.2022.9791646"},{"key":"ref_3","unstructured":"Balduzzi, M., and Ciancaglini, V. (2015, January 10\u201313). Cybercrime in the Deep Web. Proceedings of the 2015 Black Hat EU Conference, Amsterdam, The Netherlands."},{"key":"ref_4","unstructured":"Baronia, D. (2022, October 12). Dark Web and Tor Forensic. Available online: https:\/\/informaticss.com\/dark-web-and-tor-forensic\/."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Gehl, R.W. (2018). Weaving the Dark Web: Legitimacy on Freenet, Tor, and I2P, MIT Press.","DOI":"10.7551\/mitpress\/11266.001.0001"},{"key":"ref_6","unstructured":"Cherty, A., and Sharma, U. (2019, January 13\u201315). Memory forensic analysis for investigation of online crime- A review. Proceedings of the IEEE 6th International Conference on Computing for Sustainable Global Development, New Delhi, India."},{"key":"ref_7","unstructured":"European Monitoring Centre for Drugs and Drug Addiction and Europol (2017). Drugs and the Darknet: Perspectives for Enforcement, Research and Policy, Publications Office of the European Union."},{"key":"ref_8","unstructured":"Forensic-Pathways (2022, October 12). Dark Web Investigations\/Monitoring. Available online: https:\/\/www.forensic-pathways.com\/dark-web-investigationsmonitoring\/."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Godawatte, K., Raza, M., Murtaza, M., and Saeed, A. (2019, January 5\u20137). Dark Web Along with the Dark Web Marketing and Surveillance. Proceedings of the 2019 20th International Conference on Parallel and Distributed Computing, Applications and Technologies (PDCAT), Gold Coast, QLD, Australia.","DOI":"10.1109\/PDCAT46702.2019.00095"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Goodison, S.E., Woods, D., Barnum, J.D., Kemerer, A.R., and Jackson, B.A. (2019). Identifying Law Enforcement Needs for Conducting Criminal Investigations Involving Evidence on the Dark Web, RAND Corporation. Research Report.","DOI":"10.7249\/RR2704"},{"key":"ref_11","first-page":"30","article-title":"Dark Web, Its Impact on the Internet and the Society: A Review","volume":"7","author":"Handalage","year":"2020","journal-title":"J. Comput. Commun."},{"key":"ref_12","unstructured":"Protrka, N. (2021). Modern Police Leadership, Palgrave Macmillan."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Rafiuddin, M.F.B., Minhas, H., and Dhubb, P.S. (2017, January 21\u201322). A dark web story in-depth research and study conducted on the dark web-based on forensic computing and security in Malaysia. Proceedings of the 2017 IEEE International Conference on Power, Control, Signals and Instrumentation Engineering (ICPCSI), Chennai, India.","DOI":"10.1109\/ICPCSI.2017.8392286"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Leng, T., and Yu, A. (2021, January 23\u201325). A framework of darknet forensics. Proceedings of the International Conference on Advanced Information Science and Systems, Depok, Indonesia.","DOI":"10.1145\/3503047.3503082"},{"key":"ref_15","unstructured":"Maisammaguda, D. (2022, December 04). Digital Notes on Computer Forensics, India: Malla Reddy College of Engineering and Technology. Maryville University, 2017. Available online: https:\/\/online.maryville.edu\/blog\/data-analysis-techniques\/#qualitative."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Matic, S., Kotzias, P., and Caballero, J. (2015, January 12\u201316). Caronte: Detecting location leaks for deanonymizing tor hidden services. Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, New York, NY, USA.","DOI":"10.1145\/2810103.2813667"},{"key":"ref_17","first-page":"2023070982","article-title":"Cryptographically Upgrading TOR Network to Enforce Anonymity by Enhancing Security and Improving Performances","volume":"1","author":"Ghanem","year":"2023","journal-title":"Preprints.org"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Nazah, S., Huda, S., Abawajy, J., and Hassan, M.M. (2020). The Evolution of Dark Web Threat and Detection: A Systematic Approach, IEEE.","DOI":"10.1109\/ACCESS.2020.3024198"},{"key":"ref_19","unstructured":"Rogers, B. (2017). Tor: Beginners to Expert Guide to Accessing the DarkNet, TOR Browsing, and Remaining Anonymous Online, CreateSpace Independent Publishing Platform. [1st ed.]."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Zeid, R.B., Moubarak, J., and Bassil, C. (2020, January 15\u201319). Investigating the darknet. Proceedings of the International Wireless Communications and Mobile Computing (IWCMC), Limassol, Cyprus.","DOI":"10.1109\/IWCMC48107.2020.9148422"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Ozkaya, E., and Islam, R. (2019). Inside the Dark Web, CRC Press.","DOI":"10.1201\/9780367260453"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Popov, O., Bergman, J., and Valassi, C. (2018, January 15\u201316). A framework for forensically sound harvesting the dark web. Proceedings of the Central European Cybersecurity Conference, Ljubljana, Slovenia.","DOI":"10.1145\/3277570.3277584"},{"key":"ref_23","unstructured":"Holland, B.J. (2020). Encyclopedia of Criminal Activities and the Deep Web, IGI Global."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Jardine, E. (2015). The Dark Web Dilemma: Tor, Anonymity and Online Policing, Centre for International Governance Innovation.","DOI":"10.2139\/ssrn.2667711"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"329","DOI":"10.3390\/jcp2020018","article-title":"SoK: An Evaluation of the Secure End User Experience on the Dark Net through Systematic Literature Review","volume":"2","author":"Tazi","year":"2022","journal-title":"J. Cybersecur. Privacy"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3409289","article-title":"Proactively identifying emerging hacker threats from the dark web: A diachronic graph embedding framework","volume":"23","author":"Samtani","year":"2020","journal-title":"ACM Trans. Priv. Secur. (TOPS)"},{"key":"ref_27","first-page":"280","article-title":"\u2018The Use of Artificial Intelligence in Digital Forensics and Incident Response in a Constrained Environment\u2019, World Academy of Science, Engineering and Technology, Open Science Index 188","volume":"16","author":"Dunsin","year":"2022","journal-title":"Int. J. Inf. Commun. Eng."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/3\/4\/36\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T21:23:14Z","timestamp":1760131394000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/3\/4\/36"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":27,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["jcp3040036"],"URL":"https:\/\/doi.org\/10.3390\/jcp3040036","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,11,15]]}}}