13 IoT Forensics
221
There is also an additional question in this phase, as well as in the others, of
whether a court will accept the methodology and tools used since they are not yet
standardized.
There are several issues that are more relevant for forensic practitioners than
researchers, but should be mentioned. How much court knowledge and understanding of IoT operations should be assumed? Should IoT devices be brought to court
and an explanation provided on how they work before presenting evidence from
them? Should an IT or an IoT expert present evidence? [374].
13.4 Opportunities of IoT Forensics
Fortunately, we do not only encounter challenges with IoT forensics. There are also
opportunities. Some of them are presented in this section.
IoT brings new sources of evidence to general forensics. IoT records events from
the physical environment, which were not recorded and stored before. They are now
even stored as digital data. That enables much easier search, filtering, cross-relating,
aggregation and other data operations that are helpful in turning data into evidence.
IoT systems can contain contextual evidence collected without the individual who
committed the crime being aware. This all happens automatically, without any user
interaction as a side effect of the IoT operation [264].
IoT evidence, both for physical and digital forensics, is also harder to
destroy [131]. It usually is not just one piece of evidence and it is generally stored
in the cloud out of the reach of people who may want to delete it. As mentioned in
the previous paragraph, usually suspects are not even aware of the evidence being
collected. If that is the case they will not see the need and will not try to delete
collected evidence.
IoT offers more evidence sources than standard digital forensics. Connected
things provide an abundance of forensically relevant data. All devices that might
collect, process, store or exchange data are interesting as possible sources of
evidence. Even the smallest sensor that transmits a single value of measurement
of a single physical quantity might be important. A composite picture of events can
be constructed from all the data collected from the IoT systems. For example, the
location of a suspect at a particular time can be established by correlating data from
different IoT devices from various locations the suspect frequents. Wearable activity
monitors can also help identify the approximate location of the suspect [592].
13.5 An Example of an IoT Forensics Case
To present how the above-mentioned IoT forensics challenges and opportunities
can relate to a “real” case, a DFRWS IoT forensics Challenge will be used. The
Digital Forensic Research Workshop (DFRWS) is a top forensics conference. It has
221
There is also an additional question in this phase, as well as in the others, of
whether a court will accept the methodology and tools used since they are not yet
standardized.
There are several issues that are more relevant for forensic practitioners than
researchers, but should be mentioned. How much court knowledge and understanding of IoT operations should be assumed? Should IoT devices be brought to court
and an explanation provided on how they work before presenting evidence from
them? Should an IT or an IoT expert present evidence? [374].
13.4 Opportunities of IoT Forensics
Fortunately, we do not only encounter challenges with IoT forensics. There are also
opportunities. Some of them are presented in this section.
IoT brings new sources of evidence to general forensics. IoT records events from
the physical environment, which were not recorded and stored before. They are now
even stored as digital data. That enables much easier search, filtering, cross-relating,
aggregation and other data operations that are helpful in turning data into evidence.
IoT systems can contain contextual evidence collected without the individual who
committed the crime being aware. This all happens automatically, without any user
interaction as a side effect of the IoT operation [264].
IoT evidence, both for physical and digital forensics, is also harder to
destroy [131]. It usually is not just one piece of evidence and it is generally stored
in the cloud out of the reach of people who may want to delete it. As mentioned in
the previous paragraph, usually suspects are not even aware of the evidence being
collected. If that is the case they will not see the need and will not try to delete
collected evidence.
IoT offers more evidence sources than standard digital forensics. Connected
things provide an abundance of forensically relevant data. All devices that might
collect, process, store or exchange data are interesting as possible sources of
evidence. Even the smallest sensor that transmits a single value of measurement
of a single physical quantity might be important. A composite picture of events can
be constructed from all the data collected from the IoT systems. For example, the
location of a suspect at a particular time can be established by correlating data from
different IoT devices from various locations the suspect frequents. Wearable activity
monitors can also help identify the approximate location of the suspect [592].
13.5 An Example of an IoT Forensics Case
To present how the above-mentioned IoT forensics challenges and opportunities
can relate to a “real” case, a DFRWS IoT forensics Challenge will be used. The
Digital Forensic Research Workshop (DFRWS) is a top forensics conference. It has
