134
Internet of Things (IoT)
7.3.3 Challenges
The IoNT contains a large-scale source of potential evidence. However, due to the heterogeneous nature of the IoNT devices, the ways in which data are distributed, aggregated,
and processed present challenges to digital forensics investigations. New methods, techniques, and tools are required to overcome these challenges and leverage the architecture
and processes employed in IoNT to gain access to this rich source of potential evidence.
Current tools and techniques that are used for digital investigation are not suitable to investigate crimes in the IoNT environment due to new communication and standard protocols
that will be used to adapt to this environment. There are many challenges and implications
in the IoNT for performing the digital forensics in a timely fashion and effective manner. The digital investigation process consists of six main stages and various steps. These
six steps are identification, collection, extraction, analysis, examination, and reporting, as
shown in Figure 7.1, where each step has the following new challenges in the IoNT domain:
1. Identification: In the IoNT environment, there are billions of nanodevices which
will generate enormous amount of data. This huge amount of data needs more time
and special processing tools to identify evidential data that will help the examiners and digital investigators to find any traces about an incident. This amount of
generated data requires big data tools such as Hadoop for data processing and
handling.
2. Collection: In this process, an investigator identifies and collects digital evidence
from the crime scene. The digital investigators collect evidence to extract valuable
information about crimes committed in the IoNT environment and finds facts that
will help build evidence against the attackers. The collection process is very important for any digital investigator because it will complete the subsequent phases of the
digital investigation process, with errors, if any, propagating to the remaining investigation stages; hence, this phase is considered the most crucial phase. In the IoNT,
the collection process becomes more difficult and harder due to the massive amount
of nanodevices that are connected together. The IoNT environment can contain large
numbers of nanodevices that are connecting and communicating using new nanoelectromagnetic and MC systems. A digital investigator may find it an intricate challenge to collect data from this environment which has new properties. Within IoNT,
expect to see a large amount of generated data from interconnected nanomachines
that cannot be managed using traditional mining methods and procedures.
3. Extraction: In this phase, investigators extract digital evidence from different
evidential sources as well as preserve the integrity of the evidence. In the IoNT,
evidential data extracted from collected digital evidence will take more time,
especially volatile data from massive and complex connected nanodevices.
4. Analysis: This phase is a vital phase in the digital investigation for interpreting
and analyzing of extracted evidential data to make a conclusion about an incident
that occurred in the IoNT environment. The massive amount of data in the IoNT
needs new processing and analysis tools and techniques to deal with these data in
a timely fashion and forensically sound manner.
5. Examination: In the examination phase, an investigator inspects the data and
their characteristics. In this phase, we expect to develop new tools to examine
digital evidence that extract from nano-things such as bio-things and multimedia
nano-things.
Internet of Things (IoT)
7.3.3 Challenges
The IoNT contains a large-scale source of potential evidence. However, due to the heterogeneous nature of the IoNT devices, the ways in which data are distributed, aggregated,
and processed present challenges to digital forensics investigations. New methods, techniques, and tools are required to overcome these challenges and leverage the architecture
and processes employed in IoNT to gain access to this rich source of potential evidence.
Current tools and techniques that are used for digital investigation are not suitable to investigate crimes in the IoNT environment due to new communication and standard protocols
that will be used to adapt to this environment. There are many challenges and implications
in the IoNT for performing the digital forensics in a timely fashion and effective manner. The digital investigation process consists of six main stages and various steps. These
six steps are identification, collection, extraction, analysis, examination, and reporting, as
shown in Figure 7.1, where each step has the following new challenges in the IoNT domain:
1. Identification: In the IoNT environment, there are billions of nanodevices which
will generate enormous amount of data. This huge amount of data needs more time
and special processing tools to identify evidential data that will help the examiners and digital investigators to find any traces about an incident. This amount of
generated data requires big data tools such as Hadoop for data processing and
handling.
2. Collection: In this process, an investigator identifies and collects digital evidence
from the crime scene. The digital investigators collect evidence to extract valuable
information about crimes committed in the IoNT environment and finds facts that
will help build evidence against the attackers. The collection process is very important for any digital investigator because it will complete the subsequent phases of the
digital investigation process, with errors, if any, propagating to the remaining investigation stages; hence, this phase is considered the most crucial phase. In the IoNT,
the collection process becomes more difficult and harder due to the massive amount
of nanodevices that are connected together. The IoNT environment can contain large
numbers of nanodevices that are connecting and communicating using new nanoelectromagnetic and MC systems. A digital investigator may find it an intricate challenge to collect data from this environment which has new properties. Within IoNT,
expect to see a large amount of generated data from interconnected nanomachines
that cannot be managed using traditional mining methods and procedures.
3. Extraction: In this phase, investigators extract digital evidence from different
evidential sources as well as preserve the integrity of the evidence. In the IoNT,
evidential data extracted from collected digital evidence will take more time,
especially volatile data from massive and complex connected nanodevices.
4. Analysis: This phase is a vital phase in the digital investigation for interpreting
and analyzing of extracted evidential data to make a conclusion about an incident
that occurred in the IoNT environment. The massive amount of data in the IoNT
needs new processing and analysis tools and techniques to deal with these data in
a timely fashion and forensically sound manner.
5. Examination: In the examination phase, an investigator inspects the data and
their characteristics. In this phase, we expect to develop new tools to examine
digital evidence that extract from nano-things such as bio-things and multimedia
nano-things.
