Open Access Academic Publishing | Indexed in Google Scholar | CC BY-NC-ND 4.0
Book Chapter

Incident Response and Forensics in Compromised IoT Systems

Download PDF
J. Srilatha
Assistant Professor, Department of Computer Science and Engineering, G Narayanamm Institute of Technology and Science, Hyderabad, Telangana, India.
j.srilatha@gnits.ac.in
Pages: 144-154
Keywords: IoT Forensics; Incident Response; Anomaly Detection; Network Security; Machine Learning.

Abstract

The rapid proliferation of Internet of Things (IoT) devices has fundamentally transformed the digital landscape, introducing unprecedented connectivity and automa tion across industrial, commercial, and consumer sectors. However, this expansion has concurrently broadened the attack surface, rendering IoT networks highly susceptible to sophisticated cyber threats. This chapter presents a comprehensive examination of in cident response and digital forensics methodologies specifically tailored for compromised IoT systems. A hybrid machine learning-based framework for anomaly detection and au tomated incident triage is proposed and evaluated using the CIC IoT 2023 dataset. The research methodology integrates network traffic analysis, forensic evidence collection, and timeline reconstruction to facilitate rapid containment and eradication of threats. Sim ulation results demonstrate that the proposed hybrid model achieves a 97.6% detection accuracy, significantly outperforming traditional classification algorithms. Furthermore, automated response orchestration reduces containment time by 83% compared to man ual processes. This chapter addresses the unique challenges of IoT forensics, including resource constraints, heterogeneous architectures, and volatile data preservation, offering scalable solutions for securing modern IoT infrastructures.

References

  1. Abdulghani Ali Ahmed et al. “IoT forensics: current perspectives and future direc tions”. In: Sensors 24.16 (2024), p. 5210.
  2. Santoshi Rudrakar, Parag Rughani, and Lakshminarayana Sadineni. “Digital foren sics and incident response management model for IoT based agriculture”. In: Sci entific Reports 15.1 (2025), p. 17797.
  3. Oxygen Forensics. “What is digital forensics”. In: Oxygen Forensics (2023).
  4. George Grispos, Hudan Studiawan, and Saed Alrabaee. Internet of things (IoT) forensics and incident response: The good, the bad, and the unaddressed. 2024.
  5. Incident Handling Guide. Techniques into Incident Response.
  6. Sadegh Torabi et al. “A scalable platform for enabling the forensic investigation of exploited IoT devices and their generated unsolicited activities”. In: Forensic Science International: Digital Investigation 32 (2020), p. 300922.
  7. Shu-Ming Tseng, Yan-Qi Wang, and Yung-Chung Wang. “Multi-class intrusion de tection based on transformer for IoT networks using CIC-IoT-2023 dataset”. In: Future Internet 16.8 (2024), p. 284.
SECURE AND SCALABLE INTERNET OF THINGS SECURE AND SCALABLE INTERNET OF THINGS