123
Internet of Nano-Things Forensics
process in the IoT environment. Oriwoh et al. (2013) proposed two methods for digital
investigation in the IoT environment which are 1-2-3 Zones Digital Forensics and NextBest-Thing Triage:
1. 1-2-3 Zones Digital Forensics: This approach divides the IoT infrastructure
into  three areas or zones to help in performing digital investigation process.
These zones are zone 1, zone 2, and zone 3, as shown in Figure 7.2:
a. Zone 1: This zone is called the internal zone that includes all IoT smart devices
like a smart refrigerator and TV that can contain valuable data about a crime
committed in the IoT infrastructure.
b. Zone 2: This zone includes all intermediate components that reside between
the  internal and external networks to support the communication process.
These devices may be protection devices such as intrusion detection and
prevention systems (IDS/IPS) and firewalls. The digital investigators can find
evidential data that help them to extract facts about a crime committed in
relation to IoT.
c. Zone 3: This zone includes hardware and software components that reside
in the external part of the IoT Infrastructure such as cloud services and other
service providers that use IoT devices and users. These components with hardware devices and software in zone 1 and zone 2 will help digital practitioners
to perform their investigation mission in a timely fashion manner.
Zone 1
Zone 2
Z one 3
Gateway and
boundary services
(firewalls, etc.)
Internet, cloud, web
services, etc.
Internal network
Middle
Outside external
network
n1
n2
n3
n4
n5
n6
n7
n8
Things, e.g., home
appliances
FIGURE 7.2
1-2-3 Zones of digital forensics. (From Oriwoh, E., et al. Internet of things forensics: Challenges and approaches.
Collaborative Computing: Networking, Applications and Worksharing (Collaboratecom), 2013 9th International Conference
on IEEE, 2013.)
Précédent

- 148/358

Suivant