Home / Finance / Problems in IoT Paradise: What if Things Get Out of Control?!

Problems in IoT Paradise: What if Things Get Out of Control?!

More or less everything we could digitalize to make our lives easier, we have done. From mobile phones that are our assistants in every step of our private and business lives, heaters that think about the ideal temperature instead of us, climate devices that we control from our smartphones, smartwatches that track our daily activities… Millions of devices connected to each other via communication networks have been part of our daily lives for some time now. Meanwhile, the desire for smart solutions that affect our lifestyle is not declining but is growing exponentially. This is even more pronounced in business life.

The Benefits of the 2020s

In recent years, there has been an expansion in the development of the Internet of Things (IoT), various connected devices, and applications. IoT has evolved into various everyday applications and phenomena, including smart homes, smart buildings, smart cities, navigation systems, logistics systems, medical implants, and sensors or tag readers used in public transport systems or financial services.

By 2025, there could reportedly be more than 30 billion IoT connections, with an average of four IoT devices per person, ultimately developing billions of sensors that connect and interact on these devices, according to the portal iot-analytics. However, while few would voluntarily give up all these benefits of the 21st century, even in ‘technological paradise’ we must be aware that there are various dangers. The IoT network is vulnerable and subject to risks from cyber attacks. While most users are engaged with the advantages of IoT services, the responsibility of experts in so-called IoT forensics is increasing.

How does the Internet of Things even work? The essential elements of IoT are devices that collect data, all done using sensors embedded in each electronic device. Data collected from all devices is sent to the cloud, where it is stored via connection media such as mobile networks, WiFi, Bluetooth, satellite networks… and when the data reaches the cloud, it begins to analyze them. All collected and analyzed information must be accessible to the end user, and the user interface is usually found in a web browser or application.

However, not everything is as simple and ideal as it seems. Because, aside from the fact that numerous conspiracy theorists could certainly explain how world spies, under the guise of making life easier, threaten your privacy, with the growth of this market, the risks of cybersecurity indeed increase. Cyber threat actors have increased the number of attacks on IoT devices to steal millions of user data related to those devices.

At the same time, given that IoT is a combination of many major technological areas, including cloud computing, mobile devices, computers and tablets, sensors… investigating this type of crime is becoming increasingly challenging. While some experts believe that states can help with these issues by providing a legal framework, so-called digital forensics experts play an increasingly important role in the emerging field of IoT forensics as they can extract data from devices and track digital footprints leading to suspects of crimes.

Criminals Under Scrutiny

So what exactly is IoT forensics and how does it differ from ‘ordinary’ digital forensics? Simply put, it is an extension of the digital forensic investigation process that deals with IoT infrastructure and investigations within the IoT environment. And although it is part of digital forensics, this one related to IoT solutions is far more complicated as conventional tools and techniques cannot be applied. IoT forensics issues include everything from tracking to discovering IoT devices, as well as the relevance of discovered evidence, accountability, blurred boundaries, improper evidence handling, ensuring the chain of custody, and lack of standardization.

Regarding evidence, in ‘ordinary’ digital forensics, they are most often in electronic or standard format, while in the IoT case, any format is possible, and attackers can be identified through motion detectors, microphones, cameras, and other sensors. However, ‘ordinary’ and IoT forensics share a common platform for authority and control.

There are various types of techniques used in IoT forensics to extract and analyze forensic evidence from IoT devices. They can be conducted using traditional methods, which involve a static approach where investigations are conducted after attacks on devices. On the other hand, there is also a dynamic approach, in which data is retrieved from live systems. This can help in recovering evidence from device memory, network logs, and running processes, which can produce evidence more relevant to the investigative process.

IoT forensics consists of three levels: device level, network level, and cloud level, each of which can play a crucial role in gathering information for investigators. At the device level, forensic investigators collect data directly from the local memory of the physical device for analysis. At the network level, more details can be obtained that can identify patterns, sources, destinations, or even confirm the identity of the attacker. However, the cloud level is the most important and challenging segment for investigation. Most IoT devices push their data to cloud servers for storage due to the limited storage and processing capacity of the physical device, and data stored in the cloud can be distributed globally, which can also open various legal issues in different countries.

Always Challenges

But to make it not too simple, what are the key challenges faced by IoT forensics experts? First of all, it is the identification of potential evidence in the IoT environment. Namely, they are not limited to one computer or data center, but are dispersed in the cloud, individual storage units connected to the network, cryptocurrency wallets, social networks… Even when investigators know the location, it is possible that they are not with the IoT devices and the underlying infrastructure.

Moreover, even when they identify a potential source of evidence, the question arises as to how they can be obtained and preserved since some IoT devices may not have permanent memory containing user data and limited power. Then, there is also the analysis of collected evidence, which can be complicated as it depends on the format in which the data was collected. The main question at this point in the investigation is the amount of data that an IoT device can generate, and the potential amount of evidence in IoT is significantly greater than in traditional digital forensics. Additionally, the issue of privacy is important as the analysis can compile evidence and determine identity and actions.

In general, security in IoT manifests itself in a multitude of issues in terms of forensic analysis. Therefore, experts in the field of forensics are in constant search for new methods and devices for collecting and preserving evidence. While high-end devices improve people’s lives, they also serve as a platform for attackers to spread their malware. Despite the fact that high-end tools for digital forensics are available, for investigating digital crimes involving IoT devices, there are still several pain points that require further research and innovation to close the gap between the real and digital worlds.

Tagged: