228
S. Mrdovic
it. It logs states with time stamps in secure storage with hashes for integrity. The
authors provide a proof of concept implementation of their controller using an open
source IoT device controller, OpenHAB. It is connected to one device (IP camera),
one controller (Insteon Hub) and a cloud account for a device (Nest thermostat).
Analysis of the logged states enables reconstruction of scenarios of events in the
physical world.
Wang et al. [572] propose a system that ensures data provenance. It ensures
that it is possible to establish where a piece of data came from as well as
the processes and methodology by which it was produced. It enables a holistic
explanation of the system activities, including malicious behaviors. With data
provenance, the sequences of activities in an IoT system can be connected with
causal relationships. It replaces isolated logging and the analysis of individual
devices. The authors implemented this idea with a centralized auditing system for
a Samsung SmartThings platform called ProvThing. They showed that, through
optimization, real-time system auditing is possible with minimal overhead.
13.6.3 Real-World Systems
The paper “Digital forensic approaches for Amazon Alexa ecosystem” [145]
discusses practical issues when carrying out the forensic analysis of IoT systems
present in many households. It proposes a combination of cloud-native forensics
with forensics of companion devices, and this is called client-side forensics. Since
Alexa is a cloud based assistant, most of its data is in the cloud. The authors used
unofficial Alexa APIs to access its cloud data. Analysis of network traffic with
the Alexa cloud-using proxy, enabled the authors to establish that the data are
returned in the JSON format. This reveals issues with cloud forensics retrieving
data that might not be available in its raw form but only through calls to predefined
query functions, and these functions might not be documented. In this manner the
authors were able to obtain some Alexa-native artifacts. Alexa is usually managed
through a mobile application or the web. The authors apply forensics of mobile
applications and web browsers to retrieve additional artifacts from the client. To
automate this process of data collection, visualization and evaluation, the authors
created CIFT (Cloud-based IoT Forensic Toolkit). The paper emphasizes the need
for a holistic approach to data collection and analysis. The DFRWS Challenge,
presented previously, had a practical scenario with more popular home IoT devices,
including Alexa Echo, a smart speaker that is part of the Alexa Echo system.
In [494] the authors investigate what data can be collected in IoT attacks and what
can be reconstructed from that data. They used a hub and sensors from “sen.se” as
well as the Samsung hub, both for the home environment. After a 20-day period
of operation, the collected data was analyzed. The authors explain the challenges
they faced even with this small system. The paper shows how with a small number
of simple sensors different attack scenarios can be identified, interpreted, data
preserved and analyzed and presented in a way that is easy to understand. It clearly
demonstrates the power and opportunities that come from IoT forensics.
S. Mrdovic
it. It logs states with time stamps in secure storage with hashes for integrity. The
authors provide a proof of concept implementation of their controller using an open
source IoT device controller, OpenHAB. It is connected to one device (IP camera),
one controller (Insteon Hub) and a cloud account for a device (Nest thermostat).
Analysis of the logged states enables reconstruction of scenarios of events in the
physical world.
Wang et al. [572] propose a system that ensures data provenance. It ensures
that it is possible to establish where a piece of data came from as well as
the processes and methodology by which it was produced. It enables a holistic
explanation of the system activities, including malicious behaviors. With data
provenance, the sequences of activities in an IoT system can be connected with
causal relationships. It replaces isolated logging and the analysis of individual
devices. The authors implemented this idea with a centralized auditing system for
a Samsung SmartThings platform called ProvThing. They showed that, through
optimization, real-time system auditing is possible with minimal overhead.
13.6.3 Real-World Systems
The paper “Digital forensic approaches for Amazon Alexa ecosystem” [145]
discusses practical issues when carrying out the forensic analysis of IoT systems
present in many households. It proposes a combination of cloud-native forensics
with forensics of companion devices, and this is called client-side forensics. Since
Alexa is a cloud based assistant, most of its data is in the cloud. The authors used
unofficial Alexa APIs to access its cloud data. Analysis of network traffic with
the Alexa cloud-using proxy, enabled the authors to establish that the data are
returned in the JSON format. This reveals issues with cloud forensics retrieving
data that might not be available in its raw form but only through calls to predefined
query functions, and these functions might not be documented. In this manner the
authors were able to obtain some Alexa-native artifacts. Alexa is usually managed
through a mobile application or the web. The authors apply forensics of mobile
applications and web browsers to retrieve additional artifacts from the client. To
automate this process of data collection, visualization and evaluation, the authors
created CIFT (Cloud-based IoT Forensic Toolkit). The paper emphasizes the need
for a holistic approach to data collection and analysis. The DFRWS Challenge,
presented previously, had a practical scenario with more popular home IoT devices,
including Alexa Echo, a smart speaker that is part of the Alexa Echo system.
In [494] the authors investigate what data can be collected in IoT attacks and what
can be reconstructed from that data. They used a hub and sensors from “sen.se” as
well as the Samsung hub, both for the home environment. After a 20-day period
of operation, the collected data was analyzed. The authors explain the challenges
they faced even with this small system. The paper shows how with a small number
of simple sensors different attack scenarios can be identified, interpreted, data
preserved and analyzed and presented in a way that is easy to understand. It clearly
demonstrates the power and opportunities that come from IoT forensics.
