Vis enkel innførsel

dc.contributor.authorSandvik, Jens-Petter
dc.contributor.authorFranke, Katrin
dc.contributor.authorAbie, Habtamu
dc.contributor.authorÅrnes, Andrè
dc.date.accessioned2021-09-28T17:29:41Z
dc.date.available2021-09-28T17:29:41Z
dc.date.created2021-09-27T22:35:45Z
dc.date.issued2021
dc.identifier.citationForensic Science International: Digital Investigation. 2021, 37 .en_US
dc.identifier.issn2666-2825
dc.identifier.urihttps://hdl.handle.net/11250/2784436
dc.description.abstractThe ability to examine evidence and reconstruct files from novel IoT operating systems, such as Contiki with its Coffee File System, is becoming vital in digital forensic investigations. Two main challenges for an investigator facing such devices are that (i) the forensic artifacts of the file system are not well documented, and (ii) there is a lack of available forensic tools. To meet these challenges, we use code review and an emulator to gain insight into the Coffee file system, including its functionality, and implement reconstruction of deleted and modified data from extracted flash memory in software. We have integrated this into a forensic tool, COFFOR, and analyzed the Coffee File System to reconstruct deleted and modified files. This paper presents an overview of the artifacts in the file system and implements methods for the chronological ordering of the deleted file versions, and discusses these methods’ limitations. Our results demonstrate that forensic acquisition and analysis of devices running the Contiki operating system can reveal live and deleted files, as well as file version history. In some cases, a complete, chronological ordering of the version history can be reconstructed.
dc.language.isoengen_US
dc.relation.urihttps://doi.org/10.1016/j.fsidi.2021.301188
dc.rightsNavngivelse-Ikkekommersiell-DelPåSammeVilkår 4.0 Internasjonal*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-sa/4.0/deed.no*
dc.titleCoffee forensics — Reconstructing data in IoT devices running Contiki OSen_US
dc.typeJournal articleen_US
dc.typePeer revieweden_US
dc.description.versionpublishedVersion
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1
dc.identifier.doi10.1016/j.fsidi.2021.301188
dc.identifier.cristin1939382
dc.source.journalForensic Science International: Digital Investigationen_US
dc.source.volume37en_US
dc.source.pagenumber10en_US
dc.relation.projectNorges forskningsråd: 248094


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel

Navngivelse-Ikkekommersiell-DelPåSammeVilkår 4.0 Internasjonal
Med mindre annet er angitt, så er denne innførselen lisensiert som Navngivelse-Ikkekommersiell-DelPåSammeVilkår 4.0 Internasjonal