| International Journal of Computer Applications |
| Foundation of Computer Science (FCS), NY, USA |
| Volume 187 - Number 120 |
| Year of Publication: 2026 |
| Authors: Fajar Eko Prastyo, Imam Riadi |
10.5120/ijca345c896a2b0d
|
Fajar Eko Prastyo, Imam Riadi . Digital Forensic Analysis of Virtual Private Network Services using National Institute of Standards and Technology Method. International Journal of Computer Applications. 187, 120 ( Jun 2026), 54-60. DOI=10.5120/ijca345c896a2b0d
The use of Virtual Private Networks (VPNs) is on the rise to protect the privacy and security of network communications. However, the use of VPNs also complicates digital forensic investigations due to the encryption of data traffic. This study aims to analyze network traffic under conditions with and without a VPN using the National Institute of Standards and Technology (NIST) methodology. Data collection was conducted through internet activity simulations recorded using Wireshark and analyzed using NetworkMiner. The results show that VPNs can hide users’ IP addresses and encrypt network communications, but digital artifacts such as the VPN server’s IP address, DNS requests, communication sessions, timestamps, and network metadata can still be identified. Additionally, differences in network communication patterns were found between conditions without a VPN and with a VPN, particularly regarding the use of the TLS/SSL protocol. Based on these results, the NIST method proved effective in supporting digital forensic investigations of VPN-based network traffic in a systematic and structured manner.