IP Library › Granted Patent US 12,400,023
Granted Patent B1
US 12,400,023 · App. 17/984,800 · Granted Aug 26, 2025

Framework for identifying host-based artifacts in dark web investigations

Inventor: Arica Kulm (Madison, SD)
Assignee: Dakota State University
G06F21/6245G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,400,023
App. No.
17/984,800
Granted
Aug 26, 2025
Kind
B1
Abstract

A non-transitory computer readable medium is disclosures. The non-transitory medium may store a dark web artifact framework program including a set of program instructions, configured to cause the one or more processors to: identify an operating system of the target device; identify a dark web software installation method; recursively execute a series of nodes until a plurality of artifact descriptors are generated, the series of nodes associated with the identified operating system and the identified dark web software installation method, the plurality of artifact descriptors associated with one or more host-based artifacts indicative of the dark web activity, the plurality of artifact descriptors including at least one of file locations of the one or more host-based artifacts or actions required to obtain the one or more host-based artifacts; and identify the one or more host-based artifacts on the target device based on the generated plurality of artifact descriptors.

Claims (58)

1. A method, the method comprising:

receiving a first operating system selection for a target device;

receiving a first dark web software installation method selection for the target device;

recursively selecting, based on one or more forensic choices associated with the first operating system selection, a first series of selectable nodes of a dark web artifact framework until a first plurality of artifact descriptors for the target device are generated, the first series of selectable nodes associated with the first selected operating system of the target device and the selected dark web software installation method selection, a selectable node of the first series of selectable nodes coupled to an additional node of the first series of selectable nodes via one or more branch segments, the first plurality of artifact descriptors including at least one of file locations of one or more host-based artifacts or actions required to obtain the one or more host-based artifacts;

receiving a second operating system selection for the target device,

wherein the second operating system selection is for a different operating system than the first operating system selection;

receiving a second dark web installation method selection for the target device;

recursively selecting, based on one or more forensic choices associated with the second operating system selection, a second series of selectable nodes of a dark web artifact framework until a second plurality of artifact descriptors for the target device are generated, the second series of selectable nodes associated with the second selected operating system of the target device and the selected second dark web software installation method selection, a selectable node of the second series of selectable nodes coupled to an additional node of the second series of selectable nodes via one or more branch segments, the second plurality of artifact descriptors including at least one of file locations of one or more host-based artifacts or actions required to obtain the one or more host-based artifacts;

identifying the one or more host-based artifacts on the target device based on the generated first or second plurality of artifact descriptors, the one or more host-based artifacts indicative of dark web activity on the target device; and

displaying one or more visual indicators indicating one or more user selections of the first series of selectable nodes or the second series of selectable nodes.

2. The method of claim 1 , wherein the dark web activity comprises:

use of a dark web software program.

3. The method of claim 2 , wherein the dark web software program comprises:

an anonymized browser.

4. The method of claim 2 , wherein the dark web software program comprises:

The Onion Browser (TOR).

5. The method of claim 2 , wherein at least one of the one or more host-based artifacts includes an artifact indicative of installation of the dark web software.

6. The method of claim 2 , wherein at least one of the one or more host-based artifacts includes an artifact indicative of operation of the dark web software.

7. The method of claim 2 , wherein at least one of the one or more host-based artifacts includes an artifact indicative of content of dark web activity using the dark web software.

8. The method of claim 1 , wherein the selection of an operating system of the target device comprises:

selection of the operating system from at least one of Windows, macOS, or Tails.

9. The method of claim 1 , wherein receiving an operating system selection for a target device comprises:

receiving the operating system selection for the target device from a user input device of a user device, wherein the user device is configured to display an interactive graphical user interface including the dark web artifact framework.

10. The method of claim 1 , wherein the selection of a dark web software installation method comprises:

selection of the dark web software installation method from at least one of locally installed or installed via a computer readable medium.

11. A non-transitory computer readable medium storing a dark web artifact framework program including a set of program instructions, when executed by one or more processors on a target device, cause the one or more processors to:

identify a first operating system of the target device;

identify a first dark web software installation method;

recursively execute, based on one or more forensic choices associated with the first operating system, a first series of selectable nodes of the dark web artifact framework until a first plurality of artifact descriptors for the target device are generated, the first series of selectable nodes associated with the identified first operating system of the target device and the identified first dark web software installation method selection, a node of the first series of selectable nodes coupled to an additional node of the first series of selectable nodes via one or more branch segments, the first plurality of artifact descriptors associated with one or more host-based artifacts indicative of dark web activity, the first plurality of artifact descriptors including at least one of file locations of the one or more host-based artifacts or actions required to obtain the one or more host-based artifacts;

identify a second operating system of the target device,

wherein the second operating system is different from the first operating system;

identify a second dark web software installation method;

recursively execute, based on one or more forensic choices associated with the second operating system, a second series of selectable nodes of the dark web artifact framework until a second plurality of artifact descriptors for the target device are generated, the second series of selectable nodes associated with the identified second operating system of the target device and the identified second dark web software installation method selection, a node of the second series of selectable nodes coupled to an additional node of the second series of selectable nodes via one or more branch segments, the second plurality of artifact descriptors associated with one or more host-based artifacts indicative of dark web activity, the second plurality of artifact descriptors including at least one of file locations of the one or more host-based artifacts or actions required to obtain the one or more host-based artifacts;

identify the one or more host-based artifacts on the target device based on the generated plurality of artifact descriptors; and

display one or more visual indicators indicating one or more user selections of the first series of selectable nodes or the second series of selectable nodes.

12. The non-transitory computer readable medium of claim 11 , wherein the one or more processors are further configured to:

generate a dark web activity prediction report including one of the generated plurality of artifact descriptors or the identified one or more host-based artifacts on the target device.

13. The non-transitory computer readable medium of claim 12 , wherein the one or more processors are further configured to:

generate one or more controls signals configured to cause a display of the target device to display the generated dark web activity prediction report.

14. The non-transitory computer readable medium of claim 12 , wherein the one or more processors are further configured to:

provide the generated dark web activity prediction report to a user device for display on the user device.

15. The non-transitory computer readable medium of claim 12 , wherein the generated dark web activity prediction report comprises an HTML document report.

16. The non-transitory computer readable medium of claim 11 , wherein the non-transitory computer readable medium comprises:

a flash drive, a floppy disk, or a CD-ROM.

17. The non-transitory computer readable medium of claim 11 , wherein the executable file comprises an .exe file.

18. The non-transitory computer readable medium of claim 11 , wherein the one or more host-based artifacts include one or more .onion sites.

19. A system, the system comprising:

a user device including a display and a user input device, the display configured to display an interactive graphical user interface (GUI) including a dark web artifact framework, the dark web artifact framework including a first series of selectable nodes, a second series of selectable nodes, a series of branch segments, and a plurality of end-nodes, the series of branch segments configured to link a node of the first or second series of selectable nodes to one or more additional nodes of the first or second series of selectable nodes responsive to a selection via the user input device, the plurality of end-nodes associated with a plurality of artifact descriptors;

the user device configured to:

receive, via the user input device and the interactive GUI, a first operating system selection for a target device;

receive, via the user input device and the interactive GUI, a first dark web software installation method selection for the target device; and

recursively receive, via the user input device and the interactive GUI, one or more user selections of the first series of selectable nodes until a first plurality of artifact descriptors for the target device are generated, the one or more user selections of the first series of selectable nodes based on one or more forensic choices of the user, the first series of selectable nodes associated with a first selected operating system of the target device and a first selected dark web software installation method, the generated first plurality of artifact descriptors associated with one or more host-based artifacts, the first plurality of artifact descriptors including at least one of file locations of one or more host-based artifacts or actions required to obtain the one or more host-based artifacts;

receive, via the user input device and the interactive GUI, a second operating system selection for a target device;

receive, via the user input device and the interactive GUI, a second dark web software installation method selection for the target device;

recursively receive, via the user input device and the interactive GUI, one or more user selections of the second series of selectable nodes until a second plurality of artifact descriptors for the target device are generated, the one or more user selections of the second series of selectable nodes based on one or more forensic choices of the user, the second series of selectable nodes associated with a second selected operating system of the target device and a second selected dark web software installation method, the generated second plurality of artifact descriptors associated with the one or more host-based artifacts, the second plurality of artifact descriptors including at least one of file locations of one or more host-based artifacts or actions required to obtain the one or more host-based artifacts; and

display one or more visual indicators indicating one or more user selections of the first series of selectable nodes or the second series of selectable nodes.

20. The system of claim 19 , further comprising:

the target device including the one or more host-based artifacts indicative of dark web activity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2023
From: KULM, ARICA
To: DAKOTA STATE UNIVERSITY
Reel/Frame 062397/0364 →
Continuity (1)
Provisional Application 63277864 · Nov 10, 2021
References Cited (47)
US 9288219B2 · Abuelsaad · 2016 [cited by examiner]
US 11301522B1 · Kim · 2022 [cited by examiner]
US 11477226B2 · Alabdulhadi · 2022 [cited by examiner]
US 20150040217A1 · Abuelsaad · 2015 [cited by examiner]
US 20160321466A1 · Smyth · 2016 [cited by examiner]
US 20170012942A1 · Wittenschlaeger · 2017 [cited by examiner]
US 20180081934A1 · Byron · 2018 [cited by examiner]
US 20190007440A1 · Lavi · 2019 [cited by examiner]
US 20190317968A1 · De Los Santos Vilchez · 2019 [cited by examiner]
US 20190349351A1 · Verma · 2019 [cited by examiner]
M. R. Arshad, M. Hussain, H. Tahir, S. Qadir, F. I. Ahmed Memon and Y. Javed, “Forensic Analysis of Tor Browser on Windows 10 and Android 10 Operating Systems,” in IEEE Access, vol. 9, p. 141273-141294, 2021, doi: 10.11… [cited by examiner]
1. Pizzolante, Raffaele, et al. “A machine learning-based memory forensics methodology for TOR browser artifacts.” Concurrency and Computation: Practice and Experience 33.23 (2021): (Year: 2021). [cited by examiner]
“How to: Use Tor on macOS”, Surveillance Self-Defense, Jul. 10, 2023, Retrieved Aug. 23, 2020, from https://ssd.eff.org/en/module/how-use-tor-macos. [cited by applicant]
“Knowledge is Power! Using the macOS/iOS knowledgeC.db Database to Determine Precise User and Application Usage, Aug. 6, 2018”, www.mac4n6.com; Retrieved Aug. 23, 2020, from https://www.mac4n6.com/blog/2018/8/5/knowledg… [cited by applicant]
“Mac OS Daily Logs” Salt Forensics, Dec. 11, 2018, Retrieved Aug. 23, 2020, from https://salt4n6.com/2018/12/11/mac-os-daily-logs/. [cited by applicant]
“Uninstalling” Tor Project, Tor Browser Manual, Retrieved Aug. 16, 2020, from https://tb-manual.torproject.org/uninstalling/. [cited by applicant]
“Welcome to Tor Metrics”, Retrieved Sep. 29, 2019, from https://metrics.torproject.org/. [cited by applicant]
Al Jawaheri, et al. (2020). Deanonymizing Tor hidden service users through Bitcoin transactions analysis. Computers & Security, vol. 89, 101684. https://doi.org/10.1016/j.cose.2019.101684. [cited by applicant]
Baryamureeba, Venansius et al. (2004). The enhanced digital investigation process model; Proceedings of the Digital Forensic Research Conference, DFRWS 2004 USA, 1-9. [cited by applicant]
Bazli, B. et al. (2017). The dark side of I2P, a forensic analysis case study. Systems Science and Control Engineering, 5(1), 278-286. https://doi.org/10.1080/21642583.2017.1331770. [cited by applicant]
Bischoff, Paul, “How to Access the Dark Net and Deep Web Safely—Step by Step Guide”, Retrieved Dec. 29, 2019, from https://www.comparitech.com/blog/vpn-privacy/how-to-access-the-deep-web-and-darknet/. [cited by applicant]
Cardenas-Haro, et al. (2016). Tails linux operating system: The amnesiac incognito system in times of high surveillance, its security flaws, limitations, and strengths in the fight for democracy. Security Solutions for … [cited by applicant]
Carrier, B., et al. (2004). An Event-Based Digital Forensic Investigation Framework; Digital Forensic Research Conference. Retrieved from https://www.dfrws.org/sites/default/files/session-files/paper-an_event-based_digi… [cited by applicant]
Clarke, Ian et al. “Protecting Free Expression Online with Freenet”, IEEE Internet Computing; Jan.-Feb. 2002; http://computer.org/internet/, pp. 40-49. [cited by applicant]
Cox, J., (2016) “Operation Hyperion” Targets Suspected Dark Web Users Around The World—VICE. Retrieved Dec. 26, 2019, from https://www.vice.com/en_us/article/z438d8/operation-hyperion-targets-suspected-dark- web-users-a… [cited by applicant]
Creswell, J. W. (2014). Third Edition, Research Design Qualitative, Quantitative, and Mixed Methods Approaches. Sage Publications. [cited by applicant]
Darcie, W. et al. (2015). Online Anonymity: Forensic Analysis of the Tor Browser Bundle, Retrieved from http://www.marshall.edu/forensics/files/WinklerDarcie_ResearchPaper_8-6-141.pdf. [cited by applicant]
Dayalamurthy, D. (2013). “Forensic Memory Dump Analysis And Recovery Of The Artefacts Of Using Tor Bundle Browser—The Need”, Australian Digital Forensics Conference. https://doi.org/10.4225/75/57b3c7f3fb86e. [cited by applicant]
Digvijaysinh Rathod (2017), “Darknet Forensics”; International Journal of Emerging Trends & Technology in Computer Science (IJETTCS), vol. 6, Issue 4 (Jul.-Aug. 2017), pp. 77-79. Retrieved from https://github.com/HelloZ… [cited by applicant]
Dingledine, R. et al. (2004), “Tor: The second-generation onion router”, USENIX Association, Proceedings of the 13th Conference of USENIX Security Symposium, San Diego, CA. https://doi.org/10.1.1.4.6896. [cited by applicant]
Doran, M. D. (2014). “A Forensic Look at Bitcoin Cryptocurrency”, SANS Institute, A Capstone Project Submitted to the Faculty of Utica College May 2014 in Partial Fulfillment of the Requirements for the Degree of Master… [cited by applicant]
European Monitoring Centre for Drugs and Drug Addiction (2017); “Drugs and the darknet, Perspectives for enforcement, research and policy”, https://doi.org/10.2810/783427. [cited by applicant]
Jacoby, Corianna et al. Dec. 15, 2016, “The Onion Router and the Darkweb” Retrieved from https://guardianproject. [cited by applicant]
Jadoon, Abid Khan et al. (2019), “Forensic Analysis of Tor Browser: A Case Study for Privacy and Anonymity on the Web”, Forensic Science International, vol. 299, Jun. 2019, pp. 59-73, https://doi.org/10.1016/j.forsciint… [cited by applicant]
Kent, Karen et al. “Guide to Integrating Forensic Techniques into Incident Response,” National Institute of Standards and Technology (NIST), Special Publication 800-86, Computer Security Division, Gaithersburg, Aug. 200… [cited by applicant]
Michael Kohn et al. (2006) “Framework for a Digital Forensic Investigation”, Information and Computer Security Architectures Research Group, Dept. of Computer Science, University of Pretoria, https://doi.org/10.14943/jj… [cited by applicant]
Nordine, J., Osint Framework. Retrieved from https://github.com/lockfale/osint- framework. [cited by applicant]
Paul, Katie A. (2018) “Ancient Artifacts vs. Digital Artifacts: New Tools for Unmasking the Sale of Illicit Antiquities on the Dark Web”, Arts 2018, 7, 12. https://doi.org/10.3390/arts7020012. [cited by applicant]
Pollitt, M. M. (1995), Computer Forensics: An Approach to Evidence in Cyberspace, 487-491, 18th National Information Systems Security Conference, Oct. 10-13, 1995, Baltimore Convention Cen.pdf. [cited by applicant]
Pollitt, Mark, “A History of Digital Forensics”, Advances in Digital Forensics VI, pp. 3-15, https://doi.org/10.1007/978-3-642-15506-2_1T. [cited by applicant]
Popular Computer Forensics Top 21 Tools. (2019). Retrieved Sep. 28, 2019, from Infosec website: https://resources.infosecinstitute.com/computer-forensics-tools/#/gref. [cited by applicant]
Reith, Mark et al. (2009). Two models of digital forensic examination. 4th International Workshop on Systematic Approaches to Digital Forensic Engineering, SADFE 2009, 1(3), 42-53. https://doi.org/10.1109/SADFE.2009.8. [cited by applicant]
Richard III, Golden G. et al. (2014) “In lieu of swap : Analyzing compressed RAM in Mac OS X and Linux”, Digital Investigation, vol. 11, Supplement 2, Aug. 2014, pp. S3-S12. https://doi.org/10.1016/j.diin.2014.05.011. [cited by applicant]
The Washington Post. (n.d.). NSA report on the Tor encrypted network. Retrieved Oct. 26, 2019, from The Washington Post website: https://www.washingtonpost.com/apps/g/page/world/nsa-report-on-the-tor-encrypted-network/5… [cited by applicant]
Wadas, D. J., Bitcoin and Blockchain Forensics, Apr. 2018. [cited by applicant]
Warren, Aron (2017). TOR Browser Artifacts in Windows 10, SANS Institute 2021. [cited by applicant]
Zajacz Rita (2017) “Silk Road: The market beyond the reach of the state”, The Information Society, vol. 33, Issue 1, Jan.-Feb. 2017, pp. 23-34. https://doi.org/10.1080/01972243.2016.1248612. [cited by applicant]