History Management for Network Information of IoT Devices
In an Internet of Things (IoT) environment, forensics is commonly used to perform accident analysis through network communication data and the existing memory and logs in a device. Network traffic and memory are volatile data, however, and IoT device logs pose difficulties in information retrieval as opposed to a PC environment due to device and environmental constraints. To do this, we will discuss history management of network information to analyze an accident. History management can be performed on 13 items including IP, firmware version, port number, protocol, service version, and vulnerability information associated with it, and selection of the time and object of infringement can be done by using the Euclidean distance for changeable data.
KeywordsIoT History management Network forensics
This work was supported by Institute for Information & Communications Technology Promotion (IITP) grant funded by the Korea government (MSIT) (No. 2016-0-00193, IoT Security Vulnerabilities Search, Sharing and Testing Technology Development).
- 1.Wireshark: Wireshark Foundation. https://www.wireshark.org/
- 2.Nmap Security Scanner. https://nmap.org/
- 3.Shodan. https://www.shodan.io/
- 4.Censys: University of Michigan. https://censys.io/
- 5.Durumeric, Z., Wustrow, E., Halderman, J.A.: ZMap: fast internet-wide scanning and its security applications. In: Proceedings of the USENIX Security Symposium, August 2013Google Scholar
- 6.Xianping, G.: Pattern Matching in Financial Time Series Data (1998)Google Scholar
- 7.Keogh, E.: A fast and robust method for pattern matching in time-series databases. In: Proceedings of the 9th International Conference on Tools with Artificial Intelligence, pp. 578–584 (1997)Google Scholar
- 8.Keogh, E., Smyth, P.: A probabilistic approach to fast pattern matching in time series databases. In: The Third Conference on Knowledge Discovery in Database and Data Mining, pp. 24–30 (1997)Google Scholar
- 10.Ge, X., Smyth, P.: Deformable Markov model templates for time-series pattern matching. In: Proceedings of the 6th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Boston, MA, vol. 20, no. 23, pp. 81–90 (2000) Google Scholar
- 12.Khan, B.H.: A Framework for Web-Based Learning. Educational Technology Publications, Englewood Cliffs (2000)Google Scholar