122
Internet of Things (IoT)
• Extraction: In this phase, a digital investigator extracts digital evidence from different types of media, for example, hard disk, cell phone, e-mail, and much more.
• Analysis: In this phase, a digital investigator interprets and correlates the available data to arrive at a conclusion, which can prove or disprove an incident.
• Examination: In this phase, an investigator extracts and inspects the data and
their characteristics.
• Report: In this process, a digital investigator makes an organized report stating
his or her findings of the incident which have to be appropriate enough to present
to the jury.
7.2.2 Internet of Things Forensics
Currently, the IoT has become an attractive research topic where interconnected devices
known as “things” or “objects” with embedded processing abilities are employed to extend
the usage of Internet capabilities to several application domains such as medical, industry,
and military. The IoT is considered as a new environment that provides rich sources of
data such as sensors that generate data. These sources can be used in conjunction with one
another in the same IoT environment for certain purpose. The variety of these sources provides different challenges to the various forensics communities, especially the investigators who will be required to interact with this new technology to investigate crimes related
to the IoT environment. In the IoT environment, a lot of devices or machines operate, such
as wireless sensors, radio frequency identification (RFID), the Internet connection, intelligent or smart grids, cloud computing, and vehicle networks that can integrate to each
other in an intelligent manner. However, interconnecting of various “machines” also refers
to the possibility of interconnecting various different threats and attacks. For example, a
malware can easily propagate through the IoT at an unprecedented rate. In the following
four design aspects of the IoT system, there may be various threats and attacks as follows
(Giuliano et al. 2015):
1. Data Perception and Collection: In this aspect, typical attacks include data
leakage, sovereignty, and authentication.
2. Data Storage: The following attacks may occur: denial-of-service attacks (attacks
on availability), integrity attacks, impersonation, and modification of sensitive
data.
3. Data Processing: In this side, there may exist computational attacks that aim to
generate wrong data processing results.
4. Data Transmission: During the transmission process, severe types of attacks
may occur like session hijacks, routing attacks, flooding, and channel attacks.
Therefore, efficient and effective defense procedures and strategies are of extreme
importance to ensure the security of the IoT infrastructure.
In this remaining part, we will present the previous work in the area of IoT forensics that may help researchers and scientists in the digital forensics field to introduce
and propose new procedures and techniques in digital forensics in the field of IoNT
because very little work was done in the field of IoNT Fx till writing this work. Some
work has been done to explain the concept of “IoT forensics.” Also, new procedures and
methodologies have been proposed and introduced to perform the digital investigation
Internet of Things (IoT)
• Extraction: In this phase, a digital investigator extracts digital evidence from different types of media, for example, hard disk, cell phone, e-mail, and much more.
• Analysis: In this phase, a digital investigator interprets and correlates the available data to arrive at a conclusion, which can prove or disprove an incident.
• Examination: In this phase, an investigator extracts and inspects the data and
their characteristics.
• Report: In this process, a digital investigator makes an organized report stating
his or her findings of the incident which have to be appropriate enough to present
to the jury.
7.2.2 Internet of Things Forensics
Currently, the IoT has become an attractive research topic where interconnected devices
known as “things” or “objects” with embedded processing abilities are employed to extend
the usage of Internet capabilities to several application domains such as medical, industry,
and military. The IoT is considered as a new environment that provides rich sources of
data such as sensors that generate data. These sources can be used in conjunction with one
another in the same IoT environment for certain purpose. The variety of these sources provides different challenges to the various forensics communities, especially the investigators who will be required to interact with this new technology to investigate crimes related
to the IoT environment. In the IoT environment, a lot of devices or machines operate, such
as wireless sensors, radio frequency identification (RFID), the Internet connection, intelligent or smart grids, cloud computing, and vehicle networks that can integrate to each
other in an intelligent manner. However, interconnecting of various “machines” also refers
to the possibility of interconnecting various different threats and attacks. For example, a
malware can easily propagate through the IoT at an unprecedented rate. In the following
four design aspects of the IoT system, there may be various threats and attacks as follows
(Giuliano et al. 2015):
1. Data Perception and Collection: In this aspect, typical attacks include data
leakage, sovereignty, and authentication.
2. Data Storage: The following attacks may occur: denial-of-service attacks (attacks
on availability), integrity attacks, impersonation, and modification of sensitive
data.
3. Data Processing: In this side, there may exist computational attacks that aim to
generate wrong data processing results.
4. Data Transmission: During the transmission process, severe types of attacks
may occur like session hijacks, routing attacks, flooding, and channel attacks.
Therefore, efficient and effective defense procedures and strategies are of extreme
importance to ensure the security of the IoT infrastructure.
In this remaining part, we will present the previous work in the area of IoT forensics that may help researchers and scientists in the digital forensics field to introduce
and propose new procedures and techniques in digital forensics in the field of IoNT
because very little work was done in the field of IoNT Fx till writing this work. Some
work has been done to explain the concept of “IoT forensics.” Also, new procedures and
methodologies have been proposed and introduced to perform the digital investigation
