220
S. Mrdovic
A crime scene in IoT involves physical things and the environment. It can
be very difficult to preserve it in its entirety. IoT elements might be interacting
autonomously. That can make it impossible to identify the boundaries of a crime
scene and separate it from its surroundings [152].
There is a practical question if an IoT device needs to be kept as evidence or not.
By its removal from the IoT environment there is an obvious loss of functionality.
13.3.3 Evidence Analysis and Correlation
The first issue for a digital forensics investigator when faced with an IoT system
is how to analyze evidence from the physical world. IT knowledge might not be
enough and expertise from related disciplines can be required [374].
The main issue at this stage of the investigation is the amount of data that an IoT
system might produce. That amount can be overwhelming for an investigator [455]
and the tools used [559]. The number of possible evidence sources in IoT is much
higher than in standard digital forensics. Each source might produce a lot of data,
for instance if it is a sensor that measures some physical property in small time
intervals.
Since the evidence comes from a high number of heterogeneous sources it is
more difficult to correlate. Creating a time-line is important in forensics. With a
variety of devices with possibly unsynchronized clocks it can be very challenging
to do [152]. All this is an issue in reconstructing events of interest. More evidence
should mean better reconstruction but requires a lot of effort that might not be worth
it [131].
The issue of privacy is most present in this phase. Aggregation and analysis
enables pieces of evidence to be put together, and to establish someone’s identity
and actions. That is a good thing if the identity belongs to the person being
investigated, however it is difficult to know in advance. Data collected from an
IoT system might contain a lot of information on individuals not relevant to the
investigation [440]. It is best to filter that data out at the time of collection but
it is generally not possible due to time and resource limitations in that phase.
Even the data on individuals relevant to the investigation might contain personal
information that is not important. This issue also exists for standard digital forensics,
however in IoT the data is collected continuously and indiscriminately from within
the sensors’ reach, and usually when individuals are involved this happens without
their knowledge.
13.3.4 Presentation
Presenting forensic findings in a case involving IoT can be challenging. It is a new
forensics and legal field. The courts are just learning to accept virtual evidence and
this physical/virtual combination that IoT brings might be confusing.
Précédent

- 224/268

Suivant