218
S. Mrdovic
The more recent development in digital forensics is the need for cloud forensics.
In its essence it should not differ much from device and network forensics,
however it does. The cloud is built on a virtual infrastructure that is shared among
many users of a particular cloud service provider. That presents a challenge for
forensics because it is hard to locate, identify and separate data or virtual resources
relevant for an investigation. In addition, there is no easy way to get access to
the cloud infrastructure needed for creation of forensics copies. Data processing is
decentralized and data cannot be collected without the cooperation of cloud service
providers. Data decentralization might mean that parts of that data are stored in
different jurisdictions where different authority can apply [483].
13.2.3 The Need for IoT Forensics
IoT forensics encompass these forensics: device, live, network and cloud. ‘Things’
might be devices with permanent storage with familiar file systems and file formats.
Such ‘things’ can be treated as any other digital device. Unfortunately, ‘things’
might use proprietary file systems and formats. They might not even have permanent
memory that holds user data and a limited power supply that severely limits duration
or even prevents live forensics. ‘Things’ might have limited amount of RAM and
transfer all their data immediately. That data can be transferred in an open standard
or a proprietary closed format. Network data can be encrypted. IoT data is often
processed in the cloud located in an unknown location that can be on the other
side of the planet. All this makes IoT forensics different and more challenging than
traditional digital forensics.
An IoT ecosystem, especially for forensic purposes, is divided into three areas:
(IoT) device forensics, network forensics and cloud forensics [592]. Although all
three of them are important, the focus of this chapter is on (IoT) device forensics.
It is in line with the focus of this book on ubiquitous computing systems. The other
two areas are more mature. Here they are briefly covered, to the extent required to
understand IoT systems forensics.
One of the first papers on IoT forensics [455] created a list of differences to
traditional digital forensics. A more recent paper [131], in an IEEE Security and
Privacy issue devoted to digital forensics, extended that list. The differences found
are the source of specific issues and opportunities in IoT forensics that are discussed
in the next two sections.
13.3 Challenges in IoT Forensics
Issues specific to IoT forensics are systematized here based on the available
literature. Initially, the general issues are presented followed by others as they occur
in successive phases of a forensic investigation.
S. Mrdovic
The more recent development in digital forensics is the need for cloud forensics.
In its essence it should not differ much from device and network forensics,
however it does. The cloud is built on a virtual infrastructure that is shared among
many users of a particular cloud service provider. That presents a challenge for
forensics because it is hard to locate, identify and separate data or virtual resources
relevant for an investigation. In addition, there is no easy way to get access to
the cloud infrastructure needed for creation of forensics copies. Data processing is
decentralized and data cannot be collected without the cooperation of cloud service
providers. Data decentralization might mean that parts of that data are stored in
different jurisdictions where different authority can apply [483].
13.2.3 The Need for IoT Forensics
IoT forensics encompass these forensics: device, live, network and cloud. ‘Things’
might be devices with permanent storage with familiar file systems and file formats.
Such ‘things’ can be treated as any other digital device. Unfortunately, ‘things’
might use proprietary file systems and formats. They might not even have permanent
memory that holds user data and a limited power supply that severely limits duration
or even prevents live forensics. ‘Things’ might have limited amount of RAM and
transfer all their data immediately. That data can be transferred in an open standard
or a proprietary closed format. Network data can be encrypted. IoT data is often
processed in the cloud located in an unknown location that can be on the other
side of the planet. All this makes IoT forensics different and more challenging than
traditional digital forensics.
An IoT ecosystem, especially for forensic purposes, is divided into three areas:
(IoT) device forensics, network forensics and cloud forensics [592]. Although all
three of them are important, the focus of this chapter is on (IoT) device forensics.
It is in line with the focus of this book on ubiquitous computing systems. The other
two areas are more mature. Here they are briefly covered, to the extent required to
understand IoT systems forensics.
One of the first papers on IoT forensics [455] created a list of differences to
traditional digital forensics. A more recent paper [131], in an IEEE Security and
Privacy issue devoted to digital forensics, extended that list. The differences found
are the source of specific issues and opportunities in IoT forensics that are discussed
in the next two sections.
13.3 Challenges in IoT Forensics
Issues specific to IoT forensics are systematized here based on the available
literature. Initially, the general issues are presented followed by others as they occur
in successive phases of a forensic investigation.
