A Potential Digital Evidence classification model for 5G NFV Environments Using Supervised Machine Learning Algorithms

Authors

  • Sheunesu Makura University of Pretoria
  • Lucas Blanc
  • Hein Venter University of Pretoria

DOI:

https://doi.org/10.34190/eccws.25.1.4736

Keywords:

5G networks, Network Function Virtualization, Machine Learning, Potential Digital Evidence, Digital Forensic Investigation

Abstract

The adoption of fifth-generation (5G) mobile networks has increased significantly due to enhanced bandwidth, reduced latency, and support for heterogeneous services. Key enabling technologies such as Network Function Virtualisation (NFV) and network slicing introduce flexibility and scalability but also expand the attack surface for cyber threats. These threats complicate digital forensic investigations, particularly the identification and classification of Potential Digital Evidence (PDE) in dynamic virtualised environments. This paper proposes a machine learning-based classification model for PDE in 5G NFV environments to support digital forensic readiness (DFR). The model integrates digital evidence collection, preservation, and storage processes with supervised machine learning algorithms to automatically classify forensic artefacts. A Random Forest classifier was evaluated using a combined dataset consisting of CIC-IDS 2017 traffic and real 5G packet captures. Experimental results demonstrate high classification performance, achieving a weighted precision of 0.97, recall of 0.93, and F1-score of 0.95. Feature importance analysis further highlights key traffic characteristics relevant to forensic investigations. The proposed model enhances forensic readiness by enabling automated identification and categorisation of relevant evidence, reducing manual effort and improving investigation timeliness in 5G NFV environments.

Author Biographies

Sheunesu Makura, University of Pretoria

Sheunesu is a lecturer in the Department of Computer Science within the Faculty of Engineering, Built Environment and Information Technology at the University of Pretoria, South Africa. Sheunesu has industry experience as a Digital Forensic Investigator, specialising in mobile forensics and social media forensics. He has contributed to several international conferences and accredited journal publications. His research interests include digital forensic readiness, cloud forensics, mobile forensics, computer and information security, and cybersecurity.

Hein Venter, University of Pretoria

Hein Venter is a Professor and Head of Department of the Department of Computer Science at the University of Pretoria. His research interests include computer and Internet security, with a focus on network security, intrusion detection, information privacy, and digital forensics. Prof. Venter has published extensively in accredited international journals and has presented his work at numerous national and international conferences. He is actively involved in the academic community, serving on organising committees for conferences such as the Information Security for South Africa (ISSA) and the South African Institute of Computer Scientists and Information Technologists (SAICSIT).

Downloads

Published

2026-06-15