Internet of Things Forensics (IoTFs) is a new discipline in digital forensics science used in the detection, acquisition, preservation, rebuilding, analyzing, and the presentation of evidence from IoT environments. IoTFs discipline still suffers from several issues and challenges that have in the recent past been documented. For example, heterogeneity of IoT infrastructures has mainly been a key challenge. The heterogeneity of the IoT infrastructures makes the IoTFs very complex, and ambiguous among various forensic domain. This paper aims to propose a common investigation processes for IoTFs using the metamodeling method called Common Investigation Process Model (CIPM) for IoTFs. The proposed CIPM consists of four common investigation processes: i) preparation process, ii) collection process, iii) analysis process and iv) final report process. The proposed CIPM can assist IoTFs users to facilitate, manage, and organize the investigation tasks.
翻译:法医(IoTFs)是用于探测、获取、保存、重建、分析以及提供来自IoT环境的证据的数字法证科学的新学科。IoTFs的学科仍然受到最近记录下来的若干问题和挑战的困扰。例如,IoT基础设施的异质性主要是一个关键挑战。IoT基础设施的异质性使得IoTFs非常复杂,在各法医领域之间模糊不清。本文件的目的是利用称为IoTFs的“共同调查程序模型”(CIPM)的元模型为IoTs提出一个共同的调查程序。拟议的IPM由四个共同的调查程序组成:一) 准备过程,二) 收集过程,三) 分析过程和四) 最后报告过程。拟议的IPM可以帮助IoTs用户便利、管理和组织调查任务。