Chapter 10
Chapter 10
Chapter 10
Digitalization is pervading in all walks of the life and vehicle industry is no exception for
example the rise of complex driver assistance systems, Driver less cars etc. Vehicle with
all the digital implementations is becoming an important source of digital evidence in a
technical issue or a crime investigation. Today the digital forensics has become panacea
in case of the Digital Vehicle’s warranty claims analysis, Automobile accident
investigations, and Security based implementations and scrutiny etc. The crime
investigation is by far the most important application of digital forensics for vehicle
industry. Traditionally, the crime investigation when a vehicle was involved, fingerprints
and DNA material used to get collected and other evidences that are not usually digital in
nature. However, the today car is smart and stores huge digital information such as
routes, destinations, frequent locations, call logs, videos music etc. Hence, Digital
Vehicle Forensics is a newly emerged field which provide investigators to preserve wide
range of information that can serve as digital evidence from the motor vehicles.
Modern day vehicles are important source of digital evidence. Existing approaches for
vehicle forensics mostly focus on the acquisition and analysis phase only rather than
discussing the whole procedure [1]. There are different forensics challenges also that are
associated with the investigation process. This chapter throw light on the Digital Vehicle
Forensics process, the telematics system and the challenges that an investigator can face
during the forensics process.
Till the year 2014, these telematics systems were useless for the forensics investigators as
the data collected remained inaccessible. Physical data acquisition of data can be done on
the telematics or infotainment system. This is the most beneficial process for the data
acquisition. Investigator can acquire all the information, bit by bit from the hard drive,
even the deleted files. The only drawback is that it takes much longer time as compared
to the logical extraction. Acquisition can also be done by de-mounting the memory chip,
which is known as chip-off method but this technique is a very difficult way to acquire
data without any damage. FTK imager and Sleuth kit autopsy can be best option
available. The physical acquisition is reliable source of data retrieval from a smartphone
but the method faces some issues in digital vehicle forensics due to lack of the forensics
tools that are specific for the vehicles.
US based company Berla corporation had released a forensic toolkit for digital vehicle
forensics in 2014. The name of the toolkit is iVe [3]. It is first of its kind, check the
database to determine if the vehicle is supported for data acquisition, instructions for the
data acquisition and data analysis algorithm. Depending on the type and model of the
vehicle, the data acquisition can be as long as 25 GB. The data acquired using the iVe is
time stamped. Time stamping is possible with GPS tracker, it records location as well as
the time stamps. The data acquired can have information from many last years, hence can
give the information of all the connected devices to the vehicle that are now connected or
some time in the life of vehicle they got connected. Consequently, these logs can provide
essential information to the investigator.
Forensic Types and Acquisition Methods:
For automobile/ vehicle forensic two types of forensics can do a good job.
1. Live forensics:
As the name suggests the data is collected in a run-time scenario. Live forensics is
mostly useful to collect data from the volatile memory. However, the drawback is
the corruption of data evidence.
2. Post-Mortem Forensics:
The traditional way of the digital forensics in which all the system is forced to stop
to acquire the data. A good thing about this method is that there very little risk of
data corruption is present. However, the disadvantage is, it does not acquire the
volatile data that can have a lot of useful information regarding the crime scene.
According to the forensics types discussed, data acquisition can also be done using the
following methods other than physical acquisition.
1. Online acquisition:
Software based techniques are used to acquire data. For example, using Volatility
to acquire the volatile RAM data. These methods are fast and reliable. The amount
of data collected depends on the digital vehicle parts memory capacity. The
memory capacity for any vehicle is different from other and is decided by the
manufacturer.
2. Offline Acquisition:
The data acquisition takes place in a switched off mode. This can include a chip
off method in which desoldering of logical and embedded circuits takes place. The
process is not only more time consuming but also there is a high chance to corrupt
the data files due to careless desoldering process.
2. Diversity
The data acquired may be in different formats. The big volumes of data from the
vehicles can be divided into smaller sections, that can help to perform the digital
forensics process in less time.