Internet of Things(IoT) digital forensic investigation model: Top-down forensic approach methodology

Author(s):  
Sundresan Perumal ◽  
Norita Md Norwawi ◽  
Valliappan Raman

Considering the large number of devices connected to the Internet of Things(IoT), identifying malicious devices for the purpose of “search & seizure” remainsa critical issue for digital investigators. Consequently, the need for techniques that automatically identify malicious devices can speed up the process of digital investigation. However, few conceptual approaches were proposed to identify malicious devices during IoT forensic investigation. To overcome that, a formal approach is proposed to automatically triage and fingerprint IoT Malicious devices with their respective states. It is expected that with the proposed formal approach, investigators can simply identify malicious devices, their states as well as determine the scope of investigation.


The advancement of Internet of Things (IoT) devices is continuously progressing and such development also enables a number of issues to arise which increases the complexity in the forensic investigation of the IoT. Globally, investigators are faced with challenges in ways of retrieving evidence from the different areas of the IoT environment, which includes Devices, Networks and the Cloud. One of the most crucial steps during forensic investigations is the writing up and creation of a case report which then needs to be presented in the court of law. In this paper, we propose models to estimate the confidence values of evidence, investigators and case reports to ensure case investigation accuracy and improve the evidential values of case presentation as well as evidence sharing of sensitive data worldwide.


2021 ◽  
Vol 104 ◽  
pp. 102210
Author(s):  
Dongming Sun ◽  
Xiaolu Zhang ◽  
Kim-Kwang Raymond Choo ◽  
Liang Hu ◽  
Feng Wang

2019 ◽  
pp. 1-9
Author(s):  
Carlos Ortega-Laurel ◽  
Jacobo Sandoval-Gutierrez ◽  
Juan Lopez-Sauceda ◽  
Adan Fernando Serrano-Orozco

In this paper we collect and observes the existing digital forensic investigation models, which are essentially the application of information systems and communications engineering for forensic purposes. In addition, a review of the federal criminal situation in Mexico is presented (through the revision of the regulations in the Federal Criminal Code), because the Code indirectly describes the reality of what can be prosecuted and admitted as evidence, criminally speaking, with the application of digital forensic investigation models in Mexico. This is due to the significant deficiency in the proposal of digital forensic investigation models, in which there is not enough emphasis on the potential admissibility of the evidence gathered through the models, to give attention to the need to provide “evidence” to Institutions responsible for the impartation of justice, as if doing digital forensic investigation to be a technological issue and not as it really is: a socio-legal-technological issue. Therefore, considering the criminal reality in Mexico, locating the practices of existing models that make sense in accordance with the norm, an abbreviated model is proposed that really helps successful prosecutions.


2019 ◽  
Vol 1 (2) ◽  
pp. 67-74
Author(s):  
Widodo Widodo ◽  
Bambang Sugiantoro

Menurut Tizen Team (2016) smartphone dengan sistem operasi tizen termasuk smartphone yang baru dan memiliki jenis aplikasi Web, Hybrid, Native/asli dengan extensi file berupa file.tpk yang berbeda dengan jenis smartphone lainnya. Dari  beberapa review penelitian sebelumnya, dapat diketahui bahwa belum ada penelitian tentang  proses penanganan smartphone tizen beserta platform whatsapp yang berada didalamnya. Sebagian besar hasil penelitian hanya meliputi tentang bagaimana ekplorasi bukti digital pada smarphone android dan membahas tizen  dari segi keamanan. Berdasarkan review dari penelitian tersebut, terdapat beberapa masalah diantaranya belum adanya metode dan penerapan framework yang cocok untuk proses penanganan smartphone tizen dan platform whatsapp yang berada didalamnya tersebut. Untuk itu, metode live forensics dan model HDFIP dapat dijadikan acuan framework yang cocok untuk mengidentifikasi karakteristik tizen dan platform whatsapp. Dimana metode live forensics akan digunakan untuk melakukan tahapan analisa secara terperinci dan teliti terhadap peangkat barang bukti digital dan dilakukan dalam sebuah perangkat elektronik dalam keadaan power on. Sehingga penelitian ini menghasilkan perbedaan mendasar artifak android dan tizen, mendapatkan karakteristik bukti digital pada  Smartphone Tizen, yaitu berbentuk logical dan berupa file dengan ektensi .CSV dan file.db, dimana hasil penelitian ini terfokus pada sistem aplikasi WhatsApp dan SMS.


Sign in / Sign up

Export Citation Format

Share Document