13 IoT Forensics
229
13.7 Conclusion and Future Research Directions
IoT forensics is a new area open for research. There is already a need for practical
solutions to questions that arise during investigations that include IoT. That need
will help advance the research through practice.
The omnipresence of IoT makes it an ideal tool for evidence collection. As part
of its normal operation IoT collects data from its surroundings. That data, from
different IoT devices, can be correlated to create a very detailed reconstruction of
events. Suspects can easily be unaware of recordings and usually cannot destroy the
evidence.
Although this seems like a dream come true for surveillance agencies it can be
perceived as “scary” for the common citizen. IoT forensics, with data correlation,
can enable the emergence of personally identifiable information from, what seems
like, irrelevant pieces of data. The issue of privacy in IoT is a very important one
and needs to be adequately addressed.
With the opportunities it offers, IoT forensics has also some issues. New devices,
new interfaces, new storage media, new file systems, new network protocols,
dispersed cloud storage, unclear authority and jurisdiction are just some of those.
The amount of data that needs to be preserved, stored and processed is huge. Even
the presentation of the results can be challenging.
IoT forensics research so far has three main directions: the creation of new
models and interfaces, the creation of systems with a pre-prepared repository for
evidence, and forensics of real-world IoT systems. It seems to be at its beginning,
so there are definitely many opportunities for further research.
From the author’s point of view two new technologies, blockchain and SDN, can
play an important role in that future research. IoT’s distributed nature seems to be a
good fit for blockchain which is built to, among other things, ensure integrity which
is important for forensics. SDN can play a key role in relevant IoT traffic filtering
which can be set up on an ad hoc basis.
Open Access This chapter is licensed under the terms of the Creative Commons Attribution 4.0
International License (http://creativecommons.org/licenses/by/4.0/), which permits use, sharing,
adaptation, distribution and reproduction in any medium or format, as long as you give appropriate
credit to the original author(s) and the source, provide a link to the Creative Commons licence and
indicate if changes were made.
The images or other third party material in this chapter are included in the chapter’s Creative
Commons licence, unless indicated otherwise in a credit line to the material. If material is not
included in the chapter’s Creative Commons licence and your intended use is not permitted by
statutory regulation or exceeds the permitted use, you will need to obtain permission directly from
the copyright holder.
229
13.7 Conclusion and Future Research Directions
IoT forensics is a new area open for research. There is already a need for practical
solutions to questions that arise during investigations that include IoT. That need
will help advance the research through practice.
The omnipresence of IoT makes it an ideal tool for evidence collection. As part
of its normal operation IoT collects data from its surroundings. That data, from
different IoT devices, can be correlated to create a very detailed reconstruction of
events. Suspects can easily be unaware of recordings and usually cannot destroy the
evidence.
Although this seems like a dream come true for surveillance agencies it can be
perceived as “scary” for the common citizen. IoT forensics, with data correlation,
can enable the emergence of personally identifiable information from, what seems
like, irrelevant pieces of data. The issue of privacy in IoT is a very important one
and needs to be adequately addressed.
With the opportunities it offers, IoT forensics has also some issues. New devices,
new interfaces, new storage media, new file systems, new network protocols,
dispersed cloud storage, unclear authority and jurisdiction are just some of those.
The amount of data that needs to be preserved, stored and processed is huge. Even
the presentation of the results can be challenging.
IoT forensics research so far has three main directions: the creation of new
models and interfaces, the creation of systems with a pre-prepared repository for
evidence, and forensics of real-world IoT systems. It seems to be at its beginning,
so there are definitely many opportunities for further research.
From the author’s point of view two new technologies, blockchain and SDN, can
play an important role in that future research. IoT’s distributed nature seems to be a
good fit for blockchain which is built to, among other things, ensure integrity which
is important for forensics. SDN can play a key role in relevant IoT traffic filtering
which can be set up on an ad hoc basis.
Open Access This chapter is licensed under the terms of the Creative Commons Attribution 4.0
International License (http://creativecommons.org/licenses/by/4.0/), which permits use, sharing,
adaptation, distribution and reproduction in any medium or format, as long as you give appropriate
credit to the original author(s) and the source, provide a link to the Creative Commons licence and
indicate if changes were made.
The images or other third party material in this chapter are included in the chapter’s Creative
Commons licence, unless indicated otherwise in a credit line to the material. If material is not
included in the chapter’s Creative Commons licence and your intended use is not permitted by
statutory regulation or exceeds the permitted use, you will need to obtain permission directly from
the copyright holder.
