Industrial IoT cross-layer forensic investigation
- US Air Force Institute of Technology, Wright-Patterson AFB, OH (United States)
- Oak Ridge National Lab. (ORNL), Oak Ridge, TN (United States). Global Security Directorate
Cross-layer forensic investigation is addressed for Industrial Internet of Things (IIoT) device attacks in Critical Infrastructure (CI) applications. The operational motivation for cross-layer investigation is provided by the desire to directly correlate bit-level network anomaly detection with physical layer (PHY) device connectivity and/or status (normal, defective, attacked, etc.) at the time of attack. The technical motivation for developing cross-layer techniques is motivated by (a) having considerable capability in place for Higher-Layer Digital Forensic Information exploitation—real-time network cyberattack and postattack analysis, (b) having considerably less capability in place for Lowest-Layer PHY Forensic Information exploitation—the PHY domain remains largely under exploited, and (c) considering cyber-physical integration as a means to jointly exploit higher-layer digital and lowest-layer PHY forensic information to maximize investigative benefit in IIoT cyber forensics. A delineation of higher-layer digital and lowest-layer PHY elements is provided for the standard network Open Systems Interconnection model and the specific Perdue Enterprise Reference Architecture commonly used in IIoT Industrial Control System/Supervisory Control and Data Acquisition applications. Finally, a forensics work summary is provided for each delineated area based on selected representative publications and provides the basis for presenting the envisioned cross-layer forensic investigation.
- Research Organization:
- Oak Ridge National Laboratory (ORNL), Oak Ridge, TN (United States)
- Sponsoring Organization:
- USDOE
- Grant/Contract Number:
- AC05-00OR22725
- OSTI ID:
- 1491327
- Journal Information:
- WIREs. Forensic Science, Journal Name: WIREs. Forensic Science Journal Issue: 1 Vol. 1; ISSN 2573-9468
- Publisher:
- WileyCopyright Statement
- Country of Publication:
- United States
- Language:
- English
Similar Records
Challenge Paper: Validation of Forensic Techniques for Criminal Prosecution
Conference
·
Tue Apr 10 00:00:00 EDT 2007
·
OSTI ID:983450