Chapter 13
IoT Forensics
Sasa Mrdovic
Abstract This chapter provides an overview of research opportunities and issues
in IoT forensics. It gives a quick introduction to forensics and digital forensics. Key
specifics of IoT forensics are explained. Issues that arise from IoT related challenges
in all phases of a forensic investigation are presented. Some opportunities that IoT
brings to forensics are pointed out. An example of an IoT forensics case is provided.
A detailed research overview is given, providing information on the main research
directions with a brief overview of relevant papers. The chapter concludes with some
ideas for future research.
13.1 Introduction
IoT, like any other system, needs a way to analyze things that happened within a
system. When such analysis is performed for legal reasons it is called forensics.
IoT brings many opportunities and issues in its forensics. Collection of forensic
data from devices with very limited interfaces and capabilities for data storage
and processing is challenging. On the other hand, aggregation of little data pieces
from these devices can provide an unprecedented picture of events from various
perspectives. That opens up a new chapter in digital forensics.
The future prevalence of connected things will provide an abundance of forensically relevant data. Our digitally connected lives leave traces that might lead to a
golden age of forensics. Hard evidence will replace unreliable human recollection.
The opportunities of IoT forensics come with a price. The first issue that comes
to mind is privacy. Fortunately, researchers are aware of this challenge and are
working on addressing it, in general IoT and especially in IoT forensics. The focus
of this chapter is mostly on the difficulties that a forensic investigator faces with IoT
specific challenges.
S. Mrdovic ()
University of Sarajevo, Sarajevo, Bosnia and Herzegovina
e-mail: smrdovic@etf.unsa.ba
© The Author(s) 2021
G. Avoine, J. Hernandez-Castro (eds.), Security of Ubiquitous Computing Systems,
https://doi.org/10.1007/978-3-030-10591-4_13
215
IoT Forensics
Sasa Mrdovic
Abstract This chapter provides an overview of research opportunities and issues
in IoT forensics. It gives a quick introduction to forensics and digital forensics. Key
specifics of IoT forensics are explained. Issues that arise from IoT related challenges
in all phases of a forensic investigation are presented. Some opportunities that IoT
brings to forensics are pointed out. An example of an IoT forensics case is provided.
A detailed research overview is given, providing information on the main research
directions with a brief overview of relevant papers. The chapter concludes with some
ideas for future research.
13.1 Introduction
IoT, like any other system, needs a way to analyze things that happened within a
system. When such analysis is performed for legal reasons it is called forensics.
IoT brings many opportunities and issues in its forensics. Collection of forensic
data from devices with very limited interfaces and capabilities for data storage
and processing is challenging. On the other hand, aggregation of little data pieces
from these devices can provide an unprecedented picture of events from various
perspectives. That opens up a new chapter in digital forensics.
The future prevalence of connected things will provide an abundance of forensically relevant data. Our digitally connected lives leave traces that might lead to a
golden age of forensics. Hard evidence will replace unreliable human recollection.
The opportunities of IoT forensics come with a price. The first issue that comes
to mind is privacy. Fortunately, researchers are aware of this challenge and are
working on addressing it, in general IoT and especially in IoT forensics. The focus
of this chapter is mostly on the difficulties that a forensic investigator faces with IoT
specific challenges.
S. Mrdovic ()
University of Sarajevo, Sarajevo, Bosnia and Herzegovina
e-mail: smrdovic@etf.unsa.ba
© The Author(s) 2021
G. Avoine, J. Hernandez-Castro (eds.), Security of Ubiquitous Computing Systems,
https://doi.org/10.1007/978-3-030-10591-4_13
215
