222
S. Mrdovic
a yearly forensics challenge, and in 2017 the focus was on IoT. The challenge is
open to the public but it is particularly directed towards forensic researchers and
practitioners. It is intended to motivate new approaches to IoT forensic analysis.
The submitted solutions had to include source code openly available under a free
software license with supporting documentation. Explanations of the procedure used
to analyze the data needed for reaching conclusions were also required. There were
four submissions. The winners were announced in May 2018. The challenge details
and all submissions with explanations and tools used are available on a github
repository for the challenge [302]. All people interested in practical aspects of IoT
forensics are strongly advised to read the challenge and check out all proposed
solutions. It is state of the art in this area at the time of writing. A lot can be learned
from the solutions, explanations and tools.
The case scenario is simple. A woman has been murdered. Her husband has
called an ambulance. The husband claims to have been at home at the time of the
murder. Contestants had to analyze available artifacts for forensically interesting
information and try to conclude who killed the woman.
An overview of general IoT forensics issues, analyzed in Sect. 13.3.1, as they
relate to this case are given below.
• Tools: The fact that there is a challenge to develop new tools shows that existing
tools, either free open source or proprietary commercial, are inadequate for
IoT forensics. All submitted solutions used a combination of existing and tools
specifically developed for this purpose.
• Jurisdiction: In this case there were no jurisdiction issues. Investigators had
access to all data collected. In this case the husband provided credentials for
cloud stored data. In reality, such credentials might be missing and a court
warrant can be required to obtain cloud data that can potentially be in a different
country.
Evidence identification, collection and preservation challenges, described in
Sect. 13.3.2, which this case brings are presented next. In this particular case
the investigators were provided with a list of digital devices found on the scene and
the images or data from the devices including the cloud provider network traffic
dump. A quick overview of issues police might have faced during relevant data
collection is provided.
• Identification of devices with relevant evidence: There are some obvious
devices that might contain relevant data such as the victim’s mobile phone and
the smart wristband she was wearing, as well as the husband’s mobile phone.
Since the husband claimed to have been watching TV using a Raspberry Pi
as a smart device at the time of the murder, data from that Raspberry Pi is
also of interest. There was a smart Amazon Echo speaker in the apartment that
might have recorded something of interest for the investigation. Three sensors,
a main sensor, a bedroom door sensor, and a motion sensor, connected to a
Samsung SmartThings hub were found. A Google OnHub AP/Router provided
Internet access and it had forensically interesting data. It was connected to the
Précédent

- 226/268

Suivant