A Survey on the Internet of Things (IoT) Forensics: Challenges, Approaches, and Open Issues

Обзор компьютерной криминалистики Интернета вещей (IoT): проблемы, подходы и нерешённые вопросы
Evangelos Pallis, Maria Stoyanova, Yannis Nikoloudakis, Spyros Panagiotakis, Evangelos Markakis
2020-01-01

IoT forensicsblockchain-based evidence integritydigital evidencedigital forensicsprivacy-preserving data extraction
Today is the era of the Internet of Things (IoT). The recent advances in hardware and information technology have accelerated the deployment of billions of interconnected, smart and adaptive devices in critical infrastructures like health, transportation, environmental control, and home automation. Transferring data over a network without requiring any kind of human-to-computer or human-to-human interaction, brings reliability and convenience to consumers, but also opens a new world of opportunity for intruders, and introduces a whole set of unique and complicated questions to the field of Digital Forensics. Although IoT data could be a rich source of evidence, forensics professionals cope with diverse problems, starting from the huge variety of IoT devices and non-standard formats, to the multi-tenant cloud infrastructure and the resulting multi-jurisdictional litigations. A further challenge is the end-to-end encryption which represents a trade-off between users' right to privacy and the success of the forensics investigation. Due to its volatile nature, digital evidence has to be acquired and analyzed using validated tools and techniques that ensure the maintenance of the Chain of Custody. Therefore, the purpose of this paper is to identify and discuss the main issues involved in the complex process of IoT-based investigations, particularly all legal, privacy and cloud security challenges. Furthermore, this work provides an overview of the past and current theoretical models in the digital forensics science. Special attention is paid to frameworks that aim to extract data in a privacy-preserving manner or secure the evidence integrity using decentralized blockchain-based solutions. In addition, the present paper addresses the ongoing Forensics-as-a-Service (FaaS) paradigm, as well as some promising cross-cutting data reduction and forensics intelligence techniques. Finally, several other research trends and open issues are presented, with emphasis on the need for proactive Forensics Readiness strategies and generally agreed-upon standards.
1
End-to-end encryption creates a fundamental trade-off between protecting user privacy and enabling successful forensic investigations.
2
IoT deployments create rich potential sources of digital evidence across critical infrastructures, while introducing diverse and complex forensic challenges.
3
IoT investigations are hindered by heterogeneous devices, non-standard data formats, multi-tenant cloud environments, and resulting multi-jurisdictional legal issues.
4
Reliable IoT evidence acquisition and analysis require validated tools and techniques that preserve the chain of custody for volatile digital evidence.
5
The survey reviews privacy-preserving extraction frameworks, blockchain-based evidence-integrity solutions, Forensics-as-a-Service, data-reduction methods, forensic intelligence techniques, and open research issues.

Internet of Things (IoT) forensic investigations / IoT-based digital evidence sources and environments

Legal, privacy, cloud-security, evidence-integrity, and data-acquisition challenges and approaches in IoT forensics

Publication Details
Publication Date
2020-01-01
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Evangelos Pallis
Maria Stoyanova
Yannis Nikoloudakis
Spyros Panagiotakis
Evangelos Markakis
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%