Deprecated: Function curl_close() is deprecated since 8.5, as it has no effect since PHP 8.0 in /home/u483256323/domains/poorvam.com/public_html/subdomains/pore/includes/api.php on line 184
Back to Search View Original Cite This Article

Abstract

<title>Abstract</title> <p>The internet of things has become a pervasive source of digital evidence, yet the assumptions that underpin classical digital forensics, namely persistent storage, standard file systems, imageable drives, and mature extraction tools, collapse when applied to constrained, heterogeneous, cloud-dependent devices. This review synthesises a corpus of studies organised across twelve thematic groups into a single account of how the discipline has evolved, what it has settled, and what it has left unresolved. The evidence indicates that the field advanced through four phases, from drawing investigative boundaries, through preserving volatile and private state, to processing traffic at scale, and now to distributing trust across ledgers while preparing for networks that do not yet exist. This review identifies a durable consensus around a three-tier architecture, the primacy of the chain of custody, the obsolescence of legacy tools and datasets, and the necessity of proactive forensic readiness. It also identifies a frontier of active disagreement over acquisition timing, ledger governance, hashing rigour, and machine learning deployability, and argues that these disputes share a single root: a resource-poor edge and a border-crossing cloud. The central finding of the synthesis is a mismatch between design and evidence. The most cited proposals, particularly in blockchain and cryptography, remain the least empirically validated, and much of what the literature reports as validated has been demonstrated only in simulation under favourable conditions. Building on this, the review advances an information-systems reading of the field, showing that IoT forensics is a socio-technical system in which technically recoverable evidence can remain unusable for want of governance, standards, and institutional capability. It closes by connecting these findings to a set of technical, legal, and methodological gaps, and by setting out where research should now concentrate.</p>

Show More

Keywords

evidence review what digital forensics

Related Articles


Deprecated: Function curl_close() is deprecated since 8.5, as it has no effect since PHP 8.0 in /home/u483256323/domains/poorvam.com/public_html/subdomains/pore/includes/api.php on line 76
PORE

About

Connect