COMPUTATIONAL FORENSICS METHODOLOGY AND FORMAL VERIFICATION OF EXPERT FINDINGS
Abstract
This paper addresses the fundamental challenge of overcoming the systemic epistemological crisis in digital forensics. This crisis is driven by an expanding semantic gap between the probabilistic and stochastic nature of digital traces—frequently compromised by anti-forensic techniques—and the rigorous demands of adversarial legal proceedings for the legal certainty of evidence. The article is conceptual in nature and establishes the theoretical foundation of computational forensics as an independent scientific discipline. The study justifies a necessary paradigm shift from traditional heuristic artifact-discovery approaches and subjective expert opinions toward a rigorous methodology grounded in the principles of algorithmic reproducibility, the measurability of uncertainty, and formal verifiability. The author develops a set-theoretic ontological model of a computer incident, which is built upon the "subject–method–object" (S-M-O) triad and the axiom of process trace conservation. This model enables a one-to-one mapping of low-level technical indicators (IoA, IoB, IoC) onto the legal elements of a crime (corpus delicti). Furthermore, a methodology for the formal verification of hypothesis validity is proposed, incorporating the criteria of structural completeness, causal coherence, logical consistency, and factual grounding. For the first time, a mathematical model for assessing the reliability of expert findings using a logistic function (trust function) is introduced into scientific discourse. This model enables the calculation of the probability of a juridical fact by aggregating taxonomic compliance metrics, the strength of causal relationships within the incident graph, and an environmental entropy penalty. The application of the developed approach transforms forensic incident reconstruction from an ill-posed inverse problem into a deterministic procedure, ensuring the mathematically provable objectivity of the evidentiary base even under conditions of incomplete data and active anti-forensic countermeasures.
##article.references##
1. Sunde N., Horsman G. The challenges and complexities of digital forensics, Forensic Science Interna-tional: Digital Investigation, 2021, Vol. 36, pp. 301116. Available at: https://doi.org/10.1016/ j.fsidi.2021.301116.
2. Hussain S.J. and others. A Comprehensive Survey and Analysis on Multi-Domain Digital Forensic Tools, Techniques and Issues, Research Square (Preprint), 2022. DOI: 10.21203/rs.3.rs-1988841/v1.
3. Meshcheryakov V.A. Teoreticheskie osnovy mekhanizma sledoobrazovaniya v tsifrovoy kriminalistike: monografiya [Theoretical foundations of the trace formation mechanism in digital forensics: monograph]. Moscow: Prospekt, 2022, 176 p. ISBN 978-5-392-36806-8 (accessed 03 February 2026).
4. Bessonov A.A. Tsifrovaya kriminalisticheskaya model' prestupleniya kak osnova protivodeystviya kiber-prestupnosti [Digital forensic model of a crime as a basis for countering cybercrime], Akademicheskaya mysl' [Academic Thought], 2020, No. 4 (13), pp. 13-18.
5. Rossinskaya E.R. Teoriya i praktika sudebnoy ekspertizy v usloviyakh tsifrovizatsii: problemy i perspek-tivy [Theory and practice of forensic examination in the context of digitalization: problems and prospects], Vestnik Universiteta imeni O.E. Kutafina (MGYUA) [Courier of the Kutafin Moscow State Law Univer-sity (MSAL)], 2019, No. 5 (57), pp. 15-28.
6. Franke K., Srihari S.N. Computational Forensics: An Overview, Computational Forensics. IWCF 2008. Lecture Notes in Computer Science. Berlin, Heidelberg: Springer, 2008, Vol. 5158, pp. 1-16.
7. Arif T., Camacho D., Park J.H. Unveiling cybersecurity mysteries: A comprehensive survey on digital forensics trends, threats, and solutions in network security, Journal of Network and Computer Applica-tions, 2025, pp. 104296.
8. Karampidis K. A Survey on Big Data and Machine Learning in Digital Forensics, IEEE Access, 2021, Vol. 9, pp. 114407-114425.
9. Amrollahi M. Machine Learning in Digital Forensics: A Systematic Literature Review, arXiv preprint arXiv:2306.04965, 2023.
10. Kavrestad J., Nalle M. Automating Digital Forensic Investigations: The Impact of Machine Learning on Electronic Evidence, 2025 IEEE International Conference on Electronic Communications, Internet of Things and Big Data (ICEIB). IEEE, 2025, pp. 88-93. DOI: 10.1109/ECAI65401.2025.11095588.
11. Breitinger F., Baggili I. Leveraging LLMs for Memory Forensics: A Comparative Analysis of Malware Detection, Proceedings of the 2025 ACM Asia Conference on Computer and Communications Security, 2025. DOI: 10.1145/3748263.
12. Rizzo S., Bergadano F. Explainable AI for Digital Forensics: A Review, IEEE Access, 2024, Vol. 12, pp. 15430-15452. Available at: https://doi.org/10.1109/ACCESS.2024.3358054.
13. Kudryavtseva A.V., Kirillova N.P., Kochemirovskiy V.A., Stoyko N.G., Pristanskov V.D. Otsenka veroyatnostnykh vyvodov ekspertov v ugolovnom protsesse [Assessment of probabilistic conclusions of experts in criminal proceedings], Zhurnal Sibirskogo federal'nogo universitetata. Gumanitarnye nauki [Journal of Siberian Federal University. Humanities & Social Sciences], 2024, 17 (1), pp. 4-11. EDN: AQVACN.
14. Rudenkova Yu.S., Khaziev Sh.N., Usov A.I. Iskusstvennyy intellekt i sudebnaya komp'yuterno-tekhnicheskaya ekspertiza [Artificial intelligence and digital forensics], Teoriya i praktika sudebnoy ek-spertizy [Theory and Practice of Forensic Science], 2024, 19 (2), pp. 76-87. Available at: https://doi.org/10.30764/1819-2785-2024-2-76-87.
15. Meester R., Slooten K. Probability and Forensic Evidence: Theory, Philosophy, and Applications. Cam-bridge: Cambridge University Press, 2021, 442 p. DOI: 10.1017/9781108596176.
16. Taylor D., Kokshoorn B., Champod C. A practical treatment of sensitivity analyses in activity level eval-uations, Forensic Science International, 2024, Vol. 355, Article 111944. DOI: 10.1016/j.forsciint.2024.111944.
17. Gruber J., Humml M., Schröder L., Freiling F. Formal Verification of Necessary and Sufficient Evidence in Forensic Event Reconstruction, Proceedings of the Digital Forensics Research Conference Europe (DFRWS EU 2023), eds. E. Bajramovic, R. J. Rodríguez. Bonn, 2023, pp. 1-11.
18. Gruber J., Humml M. A Formal Treatment of Expressiveness and Relevance of Digital Evidence, Digital Threats: Research and Practice, 2023. DOI: 10.1145.
19. Morgenstern M., Fähndrich J., Honekamp W. Ontology in the Digital Forensics Domain: A Scoping Review, INFORMATIK 2022. Bonn: Gesellschaft für Informatik, 2022, pp. 71-80. Available at: https://doi.org/10.18420/inf2022_07.
20. Silva T.J., Oliveira Jr E., Zorzo A.F. How Ontologies Have Supported Digital Forensics: Review and Recommendations, Forensic Science Review, 2024, Vol. 36, No. 2, pp. 99-125.
21. Li S. Blockchain-based digital forensic evidence traceability framework, Computers & Security, 2022, Vol. 115, pp. 102604. Available at: https://doi.org/10.1016/j.cose.2022.102604.
22. Kryukov R.O., Fedorchenko E.V., Kotenko I.V. [i dr.]. Otsenka zashchishchennosti na osnove grafov atak s ispol'zovaniem bazy dannykh NVD i MITRE ATT&CK dlya geterogennykh infrastruktur [Security as-sessment based on attack graphs using NVD and MITRE ATT&CK databases for heterogeneous infra-structures], Informatsionno-upravlyayushchie sistemy [Information and Control Systems], 2024, No. 2, pp. 39-50. Available at: https://doi.org/10.31799/1684-8853-2024-2-39-50.
23. Angelini M. PERCIVAL: Proactive and rEactive attack and Response assessmenT for Cyber Incidents Using Visual AnaLytics, IEEE Symposium on Visualization for Cyber Security (VizSec), 2021, pp. 1-11. Available at: https://doi.org/10.1109/VizSec53982.2021.9645938.
24. Lallie C.G. A review of attack graph and attack tree visual syntax in cyber security, Computer Science Review, 2021, Vol. 39, pp. 100346. Available at: https://doi.org/10.1016/j.cosrev.2020.100346.
25. Uddin M. A survey of attack graph-based security analysis and network hardening, Computers & Securi-ty, 2023, Vol. 128, pp. 103157. Available at: https://doi.org/10.1016/j.cose.2023.103157.
26. Marrara S. Legal and Ethical Challenges in Digital Forensics Investigations, Digital Forensics and Cyber Crime. IGI Global, 2024, pp. 112-135. Available at: https://scholar.google.com/scholar? q=Legal+and+Ethical+Challenges+in+Digital+Forensics+Investigations.
27. Horsman G. Frameworks for digital forensic evidence presentation, Forensic Science International: Digi-tal Investigation, 2021, Vol. 38, pp. 301124. Available at: https://doi.org/10.1016/ j.fsidi.2021.301124.
28. Gevorgyan R.A., Abramov E.S. Ontologicheskiy podkhod k formalizatsii modeli komp'yuternogo intsiden-ta i metodu identifikatsii ego strukturnykh elementov v zadachakh sudebnoy ekspertizy [An ontological approach to formalizing a computer incident model and a method for identifying its structural elements in digital forensics]. Available at: https://doi.org/10.5281/zenodo.20187983.
29. Gevorgyan R.A. Abramov E.S. Analiz strukturno-funktsional'noy svyazi komp'yuternykh intsidentov i tipov prestupleniy v sfere informatsionnoy bezopasnosti. – https://doi.org/10.5281/zenodo.20187818.
30. Leonov A.S., Sharapov I.V. Vybor parametra regulyarizatsii Tikhonova v nekorrektnykh zadachakh, Zhurnal vychislitel'noy matematiki i matematicheskoy fiziki, 2021, Vol. 61, No. 4, pp. 451-466. Available at: https://doi.org/10.31857/S004446692104008X.
31. Montasari R. A Standardised Digital Forensic Investigation Process Model (SDFIPM), International Journal of Information Security, 2021, Vol. 20, No. 2, pp. 195-211. Available at: https://doi.org/ 10.1007/s10207-020-00495-2.
32. Alqahtani A., Sheldon F.T. A Survey of Formal Methods and Their Applications in Cyber Security, IEEE Access, 2022, Vol. 10, pp. 68702-68719. Available at: https://doi.org/10.1109/ ACCESS.2022.3186256.
33. Kaddour J. Causal Machine Learning: A Survey and Open Problems, arXiv preprint, 2022. Available at: https://doi.org/10.48550/arXiv.2206.15475.
34. Lande D. Adjustment of the analytic hierarchy process indicators using AI tools, Information Technolo-gies and Computer Engineering, 2025, Vol. 22, No. 1, pp. 104-112.
35. Sundaramoorthy S. Cognitive bias in digital forensics: A review, Forensic Science International: Digital Investigation, 2021, Vol. 38, pp. 301138. Available at: https://doi.org/10.1016/ j.fsidi.2021.301138.
36. Matveeva V.S. Statisticheskiy metod obnaruzheniya lokal'nykh neodnorodnostey dannykh dlya rassledo-vaniya intsidentov informatsionnoy bezopasnosti: dis. … kand. tekhn. nauk [Statistical method for detect-ing local data inhomogeneities for information security incident investigation: Cand. of eng. sc. diss.]: 05.13.19. NIYaU MIFI. Moscow, 2015.
37. Siboni S., & Cohen A. Anomaly Detection for Individual Sequences with Applications in Identifying Ma-licious Tools, Entropy, 2020, 22 (6), 649. Available at: https://doi.org/10.3390/e22060649.
38. Kim Juhwan & Son Baehoon & Yu Jihyeon & Yun Joobeom. AI-Driven Prioritization and Filtering of Windows Artifacts for Enhanced Digital Forensics, Computers, Materials & Continua, 2024, 81,
pp. 3371-3393. 10.32604/cmc.2024.057234.








