124
Internet of Things (IoT)
This approach reduces the challenges that will be encountered in IoT environments and ensures that investigators can focus on clearly identified areas and
objects in preparation for investigations.
2. Next-Best-Thing Triage: The next-best-thing triage (NBT) can be used in conjunction with the 1-2-3 zones approach. This approach discusses to find an alternative source in the crime scene if it is unavailable after a crime occurred in the
IoT environment. The NBT approach can be used to determine what devices were
connected to the objects of forensic interest (OOFI) and find anything which was
left behind after the devices were removed from the network. Direct access to
the OOFI may not always be possible. Therefore, in such situations, the option of
identifying and considering the next best source of relevant evidence may have
to be taken. The design of a method of systematically deciding what this next
best thing might be in different scenarios and situations can be the subject of
further research.
Zawoad and Hasan (2015) introduced a forensics-aware IoT (FAIoT) model for supporting digital forensics investigations in the IoT environment in a reliable manner. The FAIoT
model provides secure evidence preservation module and secure province module as well
as access to evidence using application programming interface (API) that will reduce the
challenge in performing the investigation. To facilitate the digital investigators, a centralized trusted evidence repository in the FAIoT is used to ease the process of evidence collection and analysis. The IoT devices need to register this secure evidence repository service.
The FAIoT architecture shown in Figure 7.3 is as follows:
• Secure Evidence Preservation Module: This module will be used to monitor all
the registered IoT devices and store evidence securely in the evidence repository.
Also, segregating of the data according to the IoT devices and its owner will be
done in this module. Hadoop distributed file system (HDFS) will be used to handle
a large volume of data.
• Secure Provenance Module: This module ensures the proper chain of custody of
the evidence by preserving the access history of the evidence.
• Access to Evidence through API: In this model, a secure read-only APIs to
law enforcement agencies is proposed. Only digital investigators and the court
member will have access to these APIs. Through these APIs, they can collect the
preserved evidence and the provenance information.
Perumal et al. (2015) proposed an integrated model which is designed based on triage
model and 1-2-3 zone model for volatile based data preservation. This model started with
the following authorization, planning and obtaining a warrant as the fundamental steps
in the digital forensic investigation process as shown in Figure 7.4. Then, it starts to investigate the IoT infrastructure and finally after seizing the IoT device from the selected area
or zone, the investigator completes the digital forensic procedure which includes a chain
of custody, lab analysis, result and proof, and archive and storage.
7.2.3 Internet of Nano-Things
The concept and idea of the IoNT are proposed and introduced by Akyildiz and
Jornet (2010). The IoNT consists of connected nanodevices through the existing
Internet of Things (IoT)
This approach reduces the challenges that will be encountered in IoT environments and ensures that investigators can focus on clearly identified areas and
objects in preparation for investigations.
2. Next-Best-Thing Triage: The next-best-thing triage (NBT) can be used in conjunction with the 1-2-3 zones approach. This approach discusses to find an alternative source in the crime scene if it is unavailable after a crime occurred in the
IoT environment. The NBT approach can be used to determine what devices were
connected to the objects of forensic interest (OOFI) and find anything which was
left behind after the devices were removed from the network. Direct access to
the OOFI may not always be possible. Therefore, in such situations, the option of
identifying and considering the next best source of relevant evidence may have
to be taken. The design of a method of systematically deciding what this next
best thing might be in different scenarios and situations can be the subject of
further research.
Zawoad and Hasan (2015) introduced a forensics-aware IoT (FAIoT) model for supporting digital forensics investigations in the IoT environment in a reliable manner. The FAIoT
model provides secure evidence preservation module and secure province module as well
as access to evidence using application programming interface (API) that will reduce the
challenge in performing the investigation. To facilitate the digital investigators, a centralized trusted evidence repository in the FAIoT is used to ease the process of evidence collection and analysis. The IoT devices need to register this secure evidence repository service.
The FAIoT architecture shown in Figure 7.3 is as follows:
• Secure Evidence Preservation Module: This module will be used to monitor all
the registered IoT devices and store evidence securely in the evidence repository.
Also, segregating of the data according to the IoT devices and its owner will be
done in this module. Hadoop distributed file system (HDFS) will be used to handle
a large volume of data.
• Secure Provenance Module: This module ensures the proper chain of custody of
the evidence by preserving the access history of the evidence.
• Access to Evidence through API: In this model, a secure read-only APIs to
law enforcement agencies is proposed. Only digital investigators and the court
member will have access to these APIs. Through these APIs, they can collect the
preserved evidence and the provenance information.
Perumal et al. (2015) proposed an integrated model which is designed based on triage
model and 1-2-3 zone model for volatile based data preservation. This model started with
the following authorization, planning and obtaining a warrant as the fundamental steps
in the digital forensic investigation process as shown in Figure 7.4. Then, it starts to investigate the IoT infrastructure and finally after seizing the IoT device from the selected area
or zone, the investigator completes the digital forensic procedure which includes a chain
of custody, lab analysis, result and proof, and archive and storage.
7.2.3 Internet of Nano-Things
The concept and idea of the IoNT are proposed and introduced by Akyildiz and
Jornet (2010). The IoNT consists of connected nanodevices through the existing
