226
S. Mrdovic
Yet another framework is proposed in [318]. That framework is created to comply
with ISO/IEC 27043:2015, the international standard for incident investigation
principles and processes. The authors hope that their approach to the standardization
and creation of a framework will enable tool development. Their framework consists
of distinct processes: proactive process, IoT forensics, and the reactive process.
The proactive process is similar to the preparation phase in other models and
frameworks. IoT forensics is the same as in [592]. The reactive process consists
of initialization, acquisition and investigation which happens after an incident is
identified in an IoT-based environment.
Harbawi and Varol [258] propose a theoretical framework that should improve
the evidence acquisition model for IoT forensics. They address the problem of the
identification of the main source of digital evidence in IoT. A Last-on-Scene (LoS)
algorithm is proposed, consisting of seven steps for things-of-interest identification.
It extends ideas from [455] and [470]. After things of interest are defined, a modified
digital forensic procedure consisting of seven steps is proposed. The authors also
propose an online management platform that manages and clusters IoT digital
forensic cases, but the paper does not elaborate further than platform general
specifications.
Zia et al. [602] propose adding application specific forensics to digital forensics
model. They argue that to ensure the collection of evidence in the context of specific
IoT applications it is important to have application-specific forensics in place. This
application specific component feeds data into the digital forensics component of
their model. It provides relevant data for the IoT application in question. That
enables focused extraction of artifacts relevant to the investigation. The authors
picked the top three most popular IoT applications at the time of writing: Smart
Home, Wearables and Smart City. For each of these they defined items of forensic
interest in a complete IoT system: device, network and cloud. With this approach
the IoT forensic process should be focused on important data but is still holistic.
Privacy protection in IoT forensics is the focus of [440]. It proposes a Privacyaware IoT forensics model (PRoFIT) that takes into consideration the privacy
requirements established by the ISO/IEC 29100:2011 privacy framework. The
model, similarly to others, relies on a preparatory phase. In this phase a piece
of software may be installed to assist and advise the user about the information
contained in the device according to privacy policies and forensic restrictions. Data
collection is based on informed user consent. The logic is that enough IoT users will
provide this consent and have the software installed. In that case at the time of the
investigation a lot of data will be readily available. There might always be a need for
court-ordered data collection but less than without the preparation step. The model
presents privacy protection aspects through the rest of the investigation process. It
includes asking the user’s consent whenever there is a need in the investigation to
share user data with someone who was not included in previous consents.
The same authors combined their work on PRoFIT [440] with Digital witness [442] to advance IoT forensics while providing user control of private data
in [441]. Digital Witness is, exactly what its name suggests, a device which is able
to collaborate in the management of electronic evidence. To stimulate a willingness
S. Mrdovic
Yet another framework is proposed in [318]. That framework is created to comply
with ISO/IEC 27043:2015, the international standard for incident investigation
principles and processes. The authors hope that their approach to the standardization
and creation of a framework will enable tool development. Their framework consists
of distinct processes: proactive process, IoT forensics, and the reactive process.
The proactive process is similar to the preparation phase in other models and
frameworks. IoT forensics is the same as in [592]. The reactive process consists
of initialization, acquisition and investigation which happens after an incident is
identified in an IoT-based environment.
Harbawi and Varol [258] propose a theoretical framework that should improve
the evidence acquisition model for IoT forensics. They address the problem of the
identification of the main source of digital evidence in IoT. A Last-on-Scene (LoS)
algorithm is proposed, consisting of seven steps for things-of-interest identification.
It extends ideas from [455] and [470]. After things of interest are defined, a modified
digital forensic procedure consisting of seven steps is proposed. The authors also
propose an online management platform that manages and clusters IoT digital
forensic cases, but the paper does not elaborate further than platform general
specifications.
Zia et al. [602] propose adding application specific forensics to digital forensics
model. They argue that to ensure the collection of evidence in the context of specific
IoT applications it is important to have application-specific forensics in place. This
application specific component feeds data into the digital forensics component of
their model. It provides relevant data for the IoT application in question. That
enables focused extraction of artifacts relevant to the investigation. The authors
picked the top three most popular IoT applications at the time of writing: Smart
Home, Wearables and Smart City. For each of these they defined items of forensic
interest in a complete IoT system: device, network and cloud. With this approach
the IoT forensic process should be focused on important data but is still holistic.
Privacy protection in IoT forensics is the focus of [440]. It proposes a Privacyaware IoT forensics model (PRoFIT) that takes into consideration the privacy
requirements established by the ISO/IEC 29100:2011 privacy framework. The
model, similarly to others, relies on a preparatory phase. In this phase a piece
of software may be installed to assist and advise the user about the information
contained in the device according to privacy policies and forensic restrictions. Data
collection is based on informed user consent. The logic is that enough IoT users will
provide this consent and have the software installed. In that case at the time of the
investigation a lot of data will be readily available. There might always be a need for
court-ordered data collection but less than without the preparation step. The model
presents privacy protection aspects through the rest of the investigation process. It
includes asking the user’s consent whenever there is a need in the investigation to
share user data with someone who was not included in previous consents.
The same authors combined their work on PRoFIT [440] with Digital witness [442] to advance IoT forensics while providing user control of private data
in [441]. Digital Witness is, exactly what its name suggests, a device which is able
to collaborate in the management of electronic evidence. To stimulate a willingness
