216
S. Mrdovic
The chapter is organized in the following way. Section 13.2 provides a short
introduction to general and then digital forensics, and ends with IoT forensics
specifics. Open questions and hurdles that IoT forensics faces are presented in
Sect. 13.3. Section 13.4 deals with opportunities that IoT forensics provide. An
example of an IoT forensics case is presented in Sect. 13.5. An overview of IoT
research with a focus on new approaches is the subject of Sect. 13.6. The last section
presents conclusions and future research directions.
13.2 Forensics
Forensic science, usually called forensics, encompasses scientific methods used
with the purpose of answering legal questions that generally arise in court cases and
criminal investigations. One of the main activities in forensics is evidence collection
and analysis. Evidence collection and handling has its procedures that should ensure
that [286]:
• evidence is obtained legally, by court order or by order of an authorized
institution or person;
• there is a chain of custody, which ensures that collected evidence is unaltered
from the moment it was collected until the moment it is presented.
13.2.1 Digital Device Forensics
Digital forensics deals with evidence in a digital form. Digital, or sometimes called
electronic, evidence is easy to change. Every access to a file on a digital device (PC,
smart phone, IoT device) changes the file’s last access time, and thus changes the file
in a way that might constitute evidence. This is an example of a change that is neither
malicious nor substantial but might be considered evidence tampering. An even
bigger issue is the possibility of intentional malicious alterations. To ensure digital
evidence integrity and its usability in court, procedures for electronic evidence and
handling are in use [208].
The first step is the creation of a forensically correct evidence copy. The forensic
copy is bit-by-bit identical to an original digital record. This must be done by tools
developed for this purpose that are evaluated and tested to confirm their operation
in accordance with a requirements specification [305]. Before and after copying
bits, the tools create a cryptographic hash of the original and copied data to confirm
data integrity during the copy making process. These tools also keep a log of all
steps taken to ensure the existence of the mentioned chain of evidence. Further
evidence analysis is performed on the copy, which ensures that the original evidence
is unaltered and available in case it’s needed for new analysis.
Précédent

- 220/268

Suivant