Internet of Things digital forensics: a systematic review of evolution, methods, and the unresolved gap between design and evidence
This systematic review traces the evolution of IoT digital forensics through four developmental phases to reveal a critical mismatch between theoretical designs and empirical evidence, highlighting that while a consensus exists on core principles like chain of custody, the field remains hindered by unresolved disputes over acquisition timing and governance, alongside a reliance on unvalidated simulations that fail to address the practical constraints of resource-poor edge devices and border-crossing clouds.
Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine a world where the smallest objects around us—from a smart thermostat to a medical implant—constantly whisper data about their surroundings. This is the Internet of Things, a vast network of connected devices that has turned the physical world into a source of digital information. For investigators, this means that evidence of a crime is no longer just hidden in a computer's hard drive; it is scattered across billions of tiny sensors, moving through private networks, and stored in distant clouds. The old rules of digital investigation, which relied on seizing a machine and copying its contents, simply do not work here. The devices are too small to hold much memory, they change their data constantly, and the information they hold often belongs to someone else or lives in a different country. This creates a difficult puzzle: how do you find, preserve, and prove the truth when the evidence is fleeting, fragmented, and spread across the globe?
A recent systematic review by researcher Adrian Ramlal tackles this exact problem by looking at a decade of research to understand how the field has changed, what it has learned, and where it is still stuck. The study acts as a map, tracing the journey of "IoT forensics" from its early days of trying to define the problem to its current state of developing complex, high-tech solutions. The review reveals that the field has moved through four distinct stages. It began by simply drawing boundaries around where evidence might be found, then shifted to figuring out how to grab data before it vanished from a device's temporary memory. Next, researchers turned their attention to analyzing the massive flood of network traffic using artificial intelligence. Now, the focus has moved to using distributed ledgers—systems that record data across many computers to prevent tampering—to keep track of evidence as it moves between different legal jurisdictions.
Despite this progress, the review uncovers a significant gap between what researchers have designed and what has actually been proven to work. The most popular ideas, particularly those involving blockchain technology and advanced cryptography, are often the least tested in the real world. Many of these proposals have only been demonstrated in computer simulations under ideal conditions, where everything runs smoothly. In reality, the devices are often too weak to run these complex systems, and the legal rules for handling evidence across borders remain unclear. The study finds that while scientists have become very good at detecting that an attack happened, they are struggling to prove exactly how it happened in a way that a court would accept. This is because the tools used to analyze data often cannot run on the tiny devices themselves, and the methods used to secure evidence often conflict with privacy laws or the limited power of the hardware.
The review also highlights a critical shortage of specialized tools. The standard software used to investigate computers fails when faced with the unique, proprietary systems of IoT devices. Furthermore, the datasets used to train artificial intelligence to spot crimes are often outdated or based on simulated attacks that do not reflect the messy reality of actual device traffic. The author argues that the field has become too focused on building new algorithms and not enough on testing them on real hardware or solving the legal hurdles that prevent evidence from being used in court. They point out that even if investigators can technically recover data, it may be useless if there are no agreed-upon standards for how to handle it or if the legal system does not recognize the method used to collect it.
Ultimately, the paper concludes that solving the mystery of IoT forensics requires more than just better technology. It demands a shift in how the field is approached, recognizing that the problem is not just technical but also social and legal. The researchers suggest that future work must move away from theoretical models and focus on rigorous testing in real-world environments. They call for the development of tools that can work on the limited hardware of everyday devices, the creation of new legal frameworks to handle cross-border evidence, and a better understanding of how to preserve the chain of custody without relying on a single central authority. Until these gaps are filled, the promise of using the Internet of Things to solve crimes will remain partially unfulfilled, with many potential leads lost to the very constraints that make these devices so useful in the first place.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.