13 IoT Forensics
225
13.6 Research Overview
Here we present and analyze the research directions in the literature that address the
above-described issues and proposed solutions. IoT forensics research is in its early
stages. It did not really start until 2013. It seems that researchers are just beginning
to scratch the surface of this vast area. This opens up opportunities for young
researchers to join in and offer fresh ideas. Most of the published papers expand
on previous results in standard digital, network, cloud and mobile forensics. Several
research directions can be identified. The following overview is organized into
subsections, with papers that propose similar ideas grouped together and ordered by
publication year. Some papers might belong to multiple subsections but are referred
to in just the one that corresponds to its main contribution.
13.6.1 New Models and Frameworks
The biggest number of papers belongs to this group. It is understandable as models
and frameworks need to define and provide some direction and standardization
for researchers and professionals. Unfortunately, none of the proposed models
and frameworks has been widely accepted and most of the proposals are still of
theoretical nature. A brief overview of papers follows.
In addition to defining challenges and IoT differences, as mentioned in
Sect. 13.2.3, [455] proposed some approaches to address challenges. Authors
proposed a zone-based method for approaching IoT related investigations. They
call them 1-2-3 zones. Zones loosely correspond to three areas of IoT forensics:
device, network and cloud. Zone 1 is an internal network with all devices and
software. Zone 2 covers hardware and software at the network border that provides
communication services from outside networks. It can include a firewall and IDS.
Zone 3 is everything outside of the network being investigated and includes cloud
and ISP, among other things. Zones enable work in parallel or they focus on the
one that is most urgent. Authors also propose a preparation phase for IoT forensics
methodology. Future papers confirm the need for the phase where data collection
devices are installed in advance. The paper proposes another important concept,
Next Best Thing (NBT). It can be expected that in IoT some sources of evidence will
not be available or reliable. The NBT model suggests that forensically interesting
data can be acquired from devices that are either directly connected or somehow
related to the object of forensic interest, as authors call it.
Another IoT digital forensic investigation model is presented in [470]. The model
divides IoT into a number of zones, similar to [455]. It includes concepts for base
device identification, a location finder represented by zones. The conceptual idea
is on the right track, but the paper does not propose how the model could be
implemented.
Précédent

- 229/268

Suivant