Digital Evidence Integrity System Using SHA-256 Hashing for Digital Forensic Data Tracking

Authors

  • Yuda perwira STMIK Pelita Nusantara
  • Humala Simangunsong STMIK Pelita Nusantara
  • Yogi Irwan Syahputra STMIK Pelita Nusantara
  • Selvi Yolanda STMIK Pelita Nusantara

DOI:

https://doi.org/10.30865/ijics.v10i2.9999

Keywords:

Digital Forensics, Data Integrity, Audit Trail, SHA-256, Hashing

Abstract

This study presents the design and implementation of a digital forensic system that integrates an audit trail mechanism with the SHA-256 hashing algorithm to track data changes and detect unauthorized manipulation, without depending on a blockchain architecture. Using a Design Science Research approach, the system called the Digital Evidence Integrity System was built as a web application with PHP and MySQL, covering requirement identification, model design, implementation, an integrity validation mechanism, and testing and evaluation. Evaluation began with a pilot of five records under authorized and unauthorized update scenarios that simulated direct database access, then was expanded to sixteen scenarios spanning seven manipulation categories: insert, update, deletion, replay, concurrent access, stored-hash alteration, and audit-trail-log manipulation. Across the fourteen scenarios usable for a confusion matrix, the system correctly flagged 4 of 9 genuine manipulation attempts (a 44.4% detection rate) with zero false positives on legitimate changes, while consistently failing to detect four categories of manipulation: outright deletion of a record, replay of a superseded but internally valid data-hash pair, an attacker recomputing and overwriting the stored hash together with the data, and tampering with the audit-trail log itself. A repeated one-character perturbation test (60 trials) confirmed the avalanche effect of SHA-256, with a mean Hamming distance of 126.42 of 256 bits (49.38%, SD 8.52) between the hash of the original and the perturbed input. Taken together, these findings indicate that an audit trail combined with SHA-256 hashing is computationally lightweight and reliably detects manipulation that alters data without also updating its stored hash, but is not, in its current form, a sufficient safeguard against an attacker capable of also controlling the hash or the log; protecting the audit-trail log itself, adding a genuine user-authentication mechanism, and closing the deletion, replay, and stored-hash-alteration gaps identified here are the priorities for further development before the system could be relied upon in an operational forensic setting.

References

[1] E. Casey and E. Casey, “The chequered past and risky future of digital forensics The chequered past and risky future of digital forensics,” Aust. J. Forensic Sci., vol. 00, no. 00, pp. 1–16, 2019, doi: 10.1080/00450618.2019.1554090.

[2] C. Hargreaves, F. Breitinger, L. Dowthwaite, H. Webb, and M. Scanlon, “Forensic Science International : Digital Investigation DFPulse : The 2024 digital forensic practitioner survey,” Forensic Sci. Int. Digit. Investig., vol. 51, no. November, p. 301844, 2024, doi: 10.1016/j.fsidi.2024.301844.

[3] C. Gilbert and M. A. Gilbert, “Exploring Secure Hashing Algorithms for Data Integrity Verification,” vol. 7, no. 11, pp. 373–390, 2025.

[4] Q. Kester and I. B. Senkyire, “Validating of Digital Forensic Images Using SHA-256,” pp. 1–5, 2019.

[5] D. Singh, H. Kaur, C. Verma, N. Kumar, and Z. Illés, “Original article A novel 3-D image encryption algorithm based on SHA-256 and chaos theory,” Alexandria Eng. J., vol. 122, no. March, pp. 564–577, 2025, doi: 10.1016/j.aej.2025.03.026.

[6] F. Frieyadie, “Penggunaan Metode Profile Matching Untuk Sistem Penunjang Keputusan Kenaikan Jabatan Pada Instansi Pemerintah,” Paradig. - J. Komput. dan Inform., vol. 18, no. 2, pp. 75–80, 2016, [Online]. Available: http://ejournal.bsi.ac.id/ejurnal/index.php/paradigma/article/view/1228

[7] H. M. Elgohary and S. M. Darwish, “Improving Uncertainty in Chain of Custody for Image Forensics Investigation Applications,” IEEE Access, vol. 10, no. 1, pp. 14669–14679, 2022, doi: 10.1109/ACCESS.2022.3147809.

[8] H. F. Atlam, N. Ekuri, M. A. Azad, and H. S. Lallie, “Blockchain Forensics : A Systematic Literature Review of Techniques , Applications , Challenges , and Future Directions,” Electronics, 2024, doi: https://doi.org/10.3390/electronics13173568.

[9] S. Johri, “Strengthening Digital Forensics with Blockchain Technology and Algorithms,” World J. Adv. Res. Rev., vol. 24, no. October, pp. 459–467, 2024.

[10] D. R. Rani, T. Karthik, T. Narasimha, and K. Rajesh, “Blockchain Based Framework for Securing Digital Evidence,” vol. 2, pp. 488–493, 2025, doi: 10.5220/0013885300004919.

[11] O. S. Igonor and M. B. Amin, “The Application of Blockchain Technology in the Field of Digital Forensics : A Literature Review,” 2025.

[12] D. Batista et al., “Exploring Blockchain Technology for Chain of Custody Control in Physical Evidence : A Systematic Literature Review,” 2023.

[13] F. F. Alruwaili, “CustodyBlock : A Distributed Chain of Custody Evidence Framework,” 2021.

[14] K. E. N. Peffers, T. Tuunanen, and M. A. Rothenberger, “A Design Science Research Methodology for Information Systems Research,” vol. 24, no. 3, pp. 45–77, 2007, doi: 10.2753/MIS0742-1222240302.

[15] S. A. Crosby and D. S. Wallach, “Efficient Data Structures for Tamper-Evident Logging,” Dep. Comput. Sci. Rice Univ., 2009.

Downloads

Published

2026-07-29

How to Cite

perwira, Y., Humala Simangunsong, Yogi Irwan Syahputra, & Selvi Yolanda. (2026). Digital Evidence Integrity System Using SHA-256 Hashing for Digital Forensic Data Tracking. The IJICS (International Journal of Informatics and Computer Science), 10(2), 167–176. https://doi.org/10.30865/ijics.v10i2.9999

Issue

Section

Articles