IDENTIFYING USER BEHAVIORAL PATTERNS IN WEB BROWSER ACTIVITY USING THE K-NEAREST NEIGHBORS ALGORITHM

Authors

DOI:

https://doi.org/10.37943/BTTB5517

Keywords:

web browser forensics , user behavior analysis , digital forensics , machine learning , k-nearest neighbors , cybersecurity

Abstract

The rapid growth of internet usage has significantly increased the volume of digital traces created by users, making web browsers a critical source of evidence in digital forensics. Web browsers store extensive user-related data, including browsing history, search queries, visited domains, cookies, and cache files, which collectively reflect behavioral patterns and decision-making processes. However, existing forensic tools primarily focus on manually extracting and visualizing browser artifacts, providing limited capabilities for automated behavioral analysis. This study addresses this shortcoming by proposing an automated method for identifying and analyzing user behavioral patterns based on web browser activity using machine learning techniques. The proposed approach is based on extracting and structuring browser history data from personal computers, followed by similarity-based classification using the k-nearest neighbors algorithm. Behavioral characteristics are extracted from recurring search queries, domain frequency, and content categories of visited websites, enabling the creation of a structured behavioral dataset. To justify the model selection, the k-nearest neighbors classifier was evaluated alongside logistic regression and Gaussian naive Bayes classifiers using standard performance metrics, including accuracy, precision, recall, F1-score, and area under the curve. Experimental results show that the k-nearest neighbors model achieves the highest recall and F1-score, indicating superior performance in identifying clustered and nonlinear patterns of user behavior compared to the baseline and probabilistic models. The results confirm that similarity-based classification is particularly effective for browser activity analysis, where user actions tend to form localized groups in high-dimensional feature spaces. The proposed method enables the transformation of raw browser data into interpretable user behavior profiles that integrate interests, behavioral indicators, and visit frequency statistics. This improves the practical applicability of web browser analysis by supporting structured behavioral assessment rather than raw data analysis. Overall, the study demonstrates the feasibility and effectiveness of integrating machine learning-based behavioral analysis into web browser forensics workflows and lays the foundation for future research incorporating temporal features, larger datasets, and hybrid learning approaches.

References

. Akintola, G. B. (2024). Performance evaluation of four different forensic tools for web browser analysis. International Journal of Scientific Research in Multidisciplinary Studies, 10(10), 68–82. Retrieved from International Journal of Scientific Research in Multidisciplinary Studies website:http://isroset.org/journal/IJSRMS/full_paper_view.php?paper_id=3655

. Rasool, A., & Jalil, Z. (2020). A review of web browser forensic analysis tools and techniques.Researchpedia Journal of Computing, 1(1), 15–21. Retrieved from Researchgate website:https://www.researchgate.net/publication/342338294_A_Review_of_Web_Browser_Forensic_Analysis_Tools_and_Techniques

. Majeti, K. V. P. S. G., Sai Sundar, Y. V. L. S., Ulichi, S. S., Mohanty, S. N., & Sudha, S. V. (2023). Digital forensic advanced evidence collection and analysis of web browser activity. EAI Endorsed Transactions on Scalable Information Systems, 10 (5). https://doi.org/10.4108/eetsis.3357

. Qazi, E. U. H., Khan, M. A., & Ahmed, S. (2024). Examining the behavior of web browsers using popular forensic tools. International Journal of Digital Crime and Forensics, 16(1), 1–19. https://doi.org/10.4018/IJDCF.349218

. Laperdrix, P., Bielova, N., Baudry, B., & Avoine, G. (2020). Browser fingerprinting: A survey. ACM Transactions on the Web, 14(2), Article 8, 1–33. https://doi.org/10.1145/3386040

. StatCounter GlobalStats. (2026). Browser market share. Retrieved from StatCounter GlobalStats website:https://gs.statcounter.com/browser-market-share

. Chromium Project. (2026). Multi-process architecture. Chromium Design Documents. Retrieved from Chromium Project website: https://www.chromium.org/developers/design-documents/multi-process-architecture

. Berham, J., & Morris, B. (2022). A critical comparison of Brave browser and Google Chrome forensic artefacts. Journal of Digital Forensics, Security and Law, 17(1). https://doi.org/10.15394/jdfsl.2022.1752

. Pau, K. N., Lee, V. W. Q., Ooi, S. Y., & Pang, Y. H. (2023). The development of a data collection and browser fingerprinting system. Sensors, 23(6), Article 3087 https://doi.org/10.3390/s23063087

. García, B., Ricca, F., del Álamo, J. M., & Leotta, M. (2023). Enhancing web applications observability through instrumented automated browsers. Journal of Systems and Software, 203, Article 111723. https://doi.org/10.1016/j.jss.2023.111723

. Chand, R. R., Sharma, N. A., & Kabir, M. A. (2025). Advancing web browser forensics: Critical evaluation of emerging tools and techniques. SN Computer Science, 6, Article. https://doi.org/10.1007/s42979-025-03921-6

. Nuswantara, D. A., & Maulidi, A. (2021). Psychological factors: Self- and circumstances-caused fraud triggers. Journal of Financial Crime, 28(1), 228–243. https://doi.org/10.1108/JFC-05-2020-0086

. Jawadi, F., Mallick, S. K., Idi Cheffou, A., & Augustine, A. (2021). Does higher unemployment lead to greater criminality? Revisiting the debate over the business cycle. *Journal of Economic Behavior & Organization, 182 , 448–471. https://doi.org/10.1016/j.jebo.2019.03.025

. Pang, G., Shen, C., Cao, L., & van den Hengel, A. (2021). Deep learning for anomaly detection: A review. ACM Computing Surveys, 54 (2), Article 38, 1–38. https://doi.org/10.1145/3439950

. Verma, G., Sarkar, M., & Seth, D. (2022). Visualization of online social dynamics for forensic investigation of user’s behavior. In Proceedings of International Conference on Recent Trends in Computing* (Lecture Notes in Networks and Systems, Vol. 341, pp. 173–186). Springer. https://doi.org/10.1007/978-981-16-7118-0_16

. Taunk, K., De, S., Verma, S., & Swetapadma, A. (2023). kNN classification: A review. Annals of Mathematics and Artificial Intelligence, 91*, 1–26. https://doi.org/10.1007/s10472-023-09882-x

. Rzayeva, L., Zhetpisbayeva, A., Batkuldin, A., Nyssanov, N., Ryzhova, A., & Saeed, F. (2026). An intelligent browser history forensics method for automated analysis of web activity logs, credentials, and user behavioral profiles. Algorithms, 19 (1), Article 75. https://doi.org/10.3390/a19010075

. Yi, J., & Tian, Y. (2024). Insider threat detection model enhancement using hybrid algorithms between unsupervised and supervised learning. Electronics, 13 (5), Article 973. https://doi.org/10.3390/electronics13050973

. Cunningham, P., & Delany, S. J. (2021). k-Nearest neighbour classifiers—A tutorial. ACM Computing Surveys, 54 (6), Article 128, 1–25. https://doi.org/10.1145/3459665

. Halder, R. K., Uddin, M. N., Uddin, M. A., Aryal, S., & Khraisat, A. (2024). Enhancing K-nearest neighbor algorithm: A comprehensive review and performance analysis of modifications. Journal of Big Data, 11, Article 113. https://doi.org/10.1186/s40537-024-00973-y

Downloads

Published

2026-06-30

How to Cite

Kassimova , B. ., Zhetpisbayeva , A. ., Rzayeva, L., Zhakenov, M. ., Kurmangali , E., & Dzhussupova, G. . (2026). IDENTIFYING USER BEHAVIORAL PATTERNS IN WEB BROWSER ACTIVITY USING THE K-NEAREST NEIGHBORS ALGORITHM. Scientific Journal of Astana IT University, 26(2), 76–91. https://doi.org/10.37943/BTTB5517

Issue

Section

Information Technologies