13 IoT Forensics
219
13.3.1 General Issues
There is a lack of a methodology and framework for IoT forensics. Even in digital
forensics there is no single universally accepted methodology, but there are a few
that are recognized and used by practitioners and researchers. IoT forensics is still
in its infancy and relies on methodologies and frameworks from standard digital
forensics that might not be fully adequate.
There is a lack of appropriate tools for IoT forensics. New software and hardware
will be needed. A good overview of available forensics tools and their suitability for
IoT is given in [559]. After a thorough analysis the authors concluded that existing
traditional computer forensic tools are insufficient for cyber-crime investigations in
IoT systems.
Since IoT is everywhere, it might be difficult to establish which jurisdiction a
case might fall under as there will often be more than one involved. IoT systems
can have devices in different jurisdictions as well as different cloud locations and
providers. This is not too dissimilar to the Internet with its worldwide reach. IoT
just expands the issue from the digital to the physical world.
13.3.2 Evidence Identification, Collection and Preservation
With IoT forensics the first thing to do is to identify the available sources of
evidence. The investigator must establish which devices recorded relevant data.
The question that needs to be answered is how IoT interacts with its surroundings.
The investigator can then know which of the possible available sources to use. In
addition, information on where and in which format data is saved must be obtained.
Before collecting evidence, constraints to data collection (physical, proprietary
standards, legal) should be checked.
Detecting the presence of IoT systems [258], and identification of IoT devices
that can provide evidence in an investigation can also be challenging [264]. In
addition, the device might contain data on different users not just the one(s) relevant
to the investigation. Identification of data of a particular user is not an easy task.
A wide array of different devices makes it difficult to have a standardized
approach to evidence collection. Data extraction is made difficult by the limited
capabilities of devices, their various interfaces, and their storage formats. Data
extraction without making changes to the device or data can potentially be difficult,
which is an issue in forensics and can even be considered evidence tampering.
On-board data storage is generally not accessible via traditional digital forensic
methods [576]. There are limited methods to create forensic images of a given IoT
device [152]. It can be difficult or even impossible to collect residual evidence from
the device in a forensically sound manner [188, 405]. Encryption of data can make it
difficult or impossible to collect evidence. Cumulative datasets may exist in multiple
locations [576].
Précédent

- 223/268

Suivant