Coffee forensics — Reconstructing data in IoT devices running Contiki OS
Autor: | André Årnes, Katrin Franke, Habtamu Abie, Jens-Petter Sandvik |
---|---|
Rok vydání: | 2021 |
Předmět: |
File system
Code review business.industry Computer science Digital forensics computer.software_genre Flash memory Computer Science Applications Pathology and Forensic Medicine Medical Laboratory Technology Software Data_FILES Operating system Version history Internet of Things business Law computer Information Systems |
Zdroj: | Forensic Science International: Digital Investigation |
ISSN: | 2666-2817 |
DOI: | 10.1016/j.fsidi.2021.301188 |
Popis: | The ability to examine evidence and reconstruct files from novel IoT operating systems, such as Contiki with its Coffee File System, is becoming vital in digital forensic investigations. Two main challenges for an investigator facing such devices are that (i) the forensic artifacts of the file system are not well documented, and (ii) there is a lack of available forensic tools. To meet these challenges, we use code review and an emulator to gain insight into the Coffee file system, including its functionality, and implement reconstruction of deleted and modified data from extracted flash memory in software. We have integrated this into a forensic tool, COFFOR, and analyzed the Coffee File System to reconstruct deleted and modified files. This paper presents an overview of the artifacts in the file system and implements methods for the chronological ordering of the deleted file versions, and discusses these methods’ limitations. Our results demonstrate that forensic acquisition and analysis of devices running the Contiki operating system can reveal live and deleted files, as well as file version history. In some cases, a complete, chronological ordering of the version history can be reconstructed. |
Databáze: | OpenAIRE |
Externí odkaz: |