A Potential Digital Evidence classification model for 5G NFV Environments Using Supervised Machine Learning Algorithms
DOI:
https://doi.org/10.34190/eccws.25.1.4736Keywords:
5G networks, Network Function Virtualization, Machine Learning, Potential Digital Evidence, Digital Forensic InvestigationAbstract
The adoption of fifth-generation (5G) mobile networks has increased significantly due to enhanced bandwidth, reduced latency, and support for heterogeneous services. Key enabling technologies such as Network Function Virtualisation (NFV) and network slicing introduce flexibility and scalability but also expand the attack surface for cyber threats. These threats complicate digital forensic investigations, particularly the identification and classification of Potential Digital Evidence (PDE) in dynamic virtualised environments. This paper proposes a machine learning-based classification model for PDE in 5G NFV environments to support digital forensic readiness (DFR). The model integrates digital evidence collection, preservation, and storage processes with supervised machine learning algorithms to automatically classify forensic artefacts. A Random Forest classifier was evaluated using a combined dataset consisting of CIC-IDS 2017 traffic and real 5G packet captures. Experimental results demonstrate high classification performance, achieving a weighted precision of 0.97, recall of 0.93, and F1-score of 0.95. Feature importance analysis further highlights key traffic characteristics relevant to forensic investigations. The proposed model enhances forensic readiness by enabling automated identification and categorisation of relevant evidence, reducing manual effort and improving investigation timeliness in 5G NFV environments.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 European Conference on Cyber Warfare and Security

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.