The Internet of Things is in constant growth, with millions of devices used every day in our homes and workplaces to ease our lives. Such a strict coexistence between humans and smart devices makes the latter digital witnesses of our every-day lives through their sensor systems. This opens up to a new area of digital investigation named IoT Forensics, where digital traces produced by smart devices (network traffic, in primis) are leveraged as evidences for forensic purposes. It is therefore important to create tools able to capture, store and possibly analyse easily such digital traces to ease the job of forensic investigators. This work presents one of such tools, named Feature-Sniffer, which is thought explicitly for Wi-Fi enabled smart devices used in Smart Building/Smart Home scenarios. Feature-Sniffer is an add-on for OpenWrt-based access points and allows to easily perform online traffic feature extraction, avoiding to store large PCAP files. We present Feature-Sniffer with an accurate description of the implementation details, and we show its possible uses with practical examples for device identification and activity classification from encrypted traffic produced by IoT cameras. We release Feature-Sniffer publicly for reproducible research.
翻译:互联网在不断增长,我们的家庭和工作场所每天使用数百万个装置来方便我们的生活。这样的人类和智能装置之间的严格共存使得后一个数字证人通过感应系统看到我们每天的生活。这打开了一个新的数字调查领域,名为IoT法医,在这个领域,智能装置(网络交通,棱镜)产生的数字痕迹被作为法医证据加以利用。因此,重要的是要创造能够捕捉、储存并可能轻易分析这种数字痕迹的工具,以方便法医调查人员的工作。这项工作展示了一种名为“Featary-Sniffer”的工具,被人们清楚地认为是智能建筑/智能家庭情景中使用的Wi-Fi功能智能装置。功能Sniffer是OpenWrt接入点的附加内容,可以方便地进行在线交通特征提取,避免储存大型PCAP文件。我们展示了对实施细节的准确描述,我们用实用的例子展示了它可能用于设备识别和IoT摄像头制作的活动分类。我们公开发布Fetatriat-Sniffer用于进行加密交通研究。