Cloud computing has been regarded as the technology enabler for the Internet of Things (IoT). To ensure the most effective collection of IoT-based evidence, it is vital for forensic practitioners to possess a contemporary understanding of the artefacts from different cloud services. In this paper, we seek to determine the data remnants from the use of BitTorrent Sync version 2.0. Findings from our research using mobile and computer devices running Windows 8.1, Mac OS X Mavericks 10.9.5, Ubuntu 14.04.1 LTS, iOS 7.1.2, and Android KitKat 4.4.4 suggested that artefacts relating to the installation, uninstallation, log-in, log-off, and file synchronisation could be recovered, which are potential sources of IoT forensics. We also present a forensically sound investigation methodology for BitTorrent Sync.
翻译:云计算被视为“物联网”的技术促进器。为了确保最有效地收集基于IoT的证据,法医从业人员必须掌握来自不同云服务的手工艺品的当代知识。在本文件中,我们力求确定使用BitTorrent Sync 2.0版产生的数据残余。我们利用运行视窗8.1、Mac OS X Mavericks 10.9.5、Ubuntu 14.04.1 LTS、iOS 7.1.2和Android KitKat 4.4.4的移动和计算机设备进行的研究的结果,表明与安装、拆除、登录、登入和文件同步有关的工艺品可以回收,这是IoT法医的潜在来源。我们还为BitTorrent Sync提供了一种法医上合理的调查方法。