13 IoT Forensics
217
There is an ethical question of data privacy regarding digital evidence from any
device that holds personal data. Digital devices are part of our everyday life. All of
them, ranging from personal devices such as smart phones or personal computers to
cloud and IoT devices, process and store huge amounts of data about personal users’
private lives. Most of that data is not relevant in any particular case that triggered
evidence collection from that digital device. Nevertheless, a forensic investigator
frequently needs to examine a variety of files to be able to establish which ones are
relevant to an investigation and which ones are not. Digital device examination is a
significant invasion of privacy. For this reason, it is necessary to clearly define what
kind of data and evidence an investigator should look for, to protect user privacy as
much as possible. This issue in regard to IoT will be further addressed later.
The fact that digital evidence can be on a number of different devices in a variety
of formats represents an additional challenge. These devices can be computers,
smart phones, digital cameras, GPS devices, or any other device (thing) that stores
data in a digital form (and it seems that it will eventually include everything).
Each of these devices might store data on a different medium in a different way.
Luckily there is some de facto standardization that usually makes it a little easier.
Digital records on devices are created by different software that use different data
formats. To read and understand a particular data format one needs specialized
knowledge and tools. For this reason, evidence collection from special devices is
often performed by a specialist in that area.
13.2.2 Other Digital Forensics
There are other sources of digital forensic data. Collecting data from those has some
issues that are similar to IoT forensics. In reviewing them we can identify what
differentiates IoT evidence collection.
All issues mentioned in the previous subsection relate to digital evidence that
exist in the memory of a device. That memory is usually non-volatile. Volatile,
working memory, like RAM, can contain forensically interesting data. The creation
of an evidence copy of such memory must be done without powering down the
device, this is known as live forensics. That procedure generally alters memory
content and must be thoroughly documented.
Similar issues exist within network forensics. Some of the evidence can be
collected from network devices, like routers, firewalls, etc., but most of it exists
only in flight. That data can be captured only at the time it passes through a
device processing it. There are devices and procedures for storing that network data.
Nevertheless, it is impractical to capture and save all network data, due to its volume,
however there are other issues such as the number and location of sniffing devices
needed [174]. The question of privacy here is much larger as the network data might
include a lot of information that is not related to the legal case in question [10].
Therefore, a narrow investigation focus is of utmost importance.
Précédent

- 221/268

Suivant