论文标题

Stitcher:将数字法医证据相关联

STITCHER: Correlating Digital Forensic Evidence on Internet-of-Things Devices

论文作者

Tok, Yee Ching, Wang, Chundong, Chattopadhyay, Sudipta

论文摘要

当需要在这些新平台上对网络犯罪进行调查时,对数字法医研究人员和执法机构的新挑战的采用越来越多。但是,尚无正式研究来记录调查人员面临的实际挑战,以及现有工具是否帮助他们的工作。鉴于物联网设备的众多证据来源,诸如数字法医证据中的相关性和一致性问题等先前的问题也已成为一个紧迫的关注。在这些观察结果的推动下,我们与来自公共和私营部门的39个数字法医研究人员进行了一项用户研究,以记录他们在传统和物联网数字取证中面临的挑战。我们还创建了一个工具Stitcher,该工具解决了调查人员处理IoT数字取证调查时面临的技术挑战。我们模拟了一个物联网犯罪,该犯罪模仿了复杂的网络犯罪分子,并邀请我们的用户研究参与者利用Stitcher调查犯罪。我们的研究结果证实了Stitcher的功效,其中96.2%的用户表示Stitcher协助他们处理犯罪,而使用Stitcher的用户中有61.5%的用户完全解决了犯罪。

The increasing adoption of Internet-of-Things (IoT) devices present new challenges to digital forensic investigators and law enforcement agencies when investigation into cybercrime on these new platforms are required. However, there has been no formal study to document actual challenges faced by investigators and whether existing tools help them in their work. Prior issues such as the correlation and consistency problem in digital forensic evidence have also become a pressing concern in light of numerous evidence sources from IoT devices. Motivated by these observations, we conduct a user study with 39 digital forensic investigators from both public and private sectors to document the challenges they faced in traditional and IoT digital forensics. We also created a tool, STITCHER, that addresses the technical challenges faced by investigators when handling IoT digital forensics investigation. We simulated an IoT crime that mimics sophisticated cybercriminals and invited our user study participants to utilize STITCHER to investigate the crime. The efficacy of STITCHER is confirmed by our study results where 96.2% of users indicated that STITCHER assisted them in handling the crime, and 61.5% of users who used STITCHER with its full features solved the crime completely.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源