Tina Wu, DPhil Cyber Security Student, University of Oxford

Tina, you're a DPhil student in Cyber Security at the University of Oxford. What was it that first sparked your interest in digital forensics and cyber security?

I first became interested in forensics when in college, I have always had an interest in science and law subjects and found forensic science a good combination of these.I found the CSI programs fascinating and this encouraged me to take my degree in Forensic Science.

Whilst at university my interest in computing developed when I built my own PC and setup a home network, this prompted me to undertake a master’s in Digital Forensics and computer security.

Your current project focuses on the Internet of Things – where did you get the idea for it?

I worked at Airbus cyber security and digital forensics research lab where I focussed on developing forensic tools and methods for SCADA/ICS forensics. Having already a knowledge in SCADA/ICS forensics meant that I took an interest in non-traditional forensics. The Internet of Things (IoTs) has been a hot topic not just in the specialist press but also in the general media.


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

My interest in the topic grew gradually as I read more about the various security threats to IoT devices. I found the digital forensic landscape has changed from just carrying out a forensic investigation on a single component to looking at a chain of interconnected devices and services.

Can you briefly outline for us what your project entails?

I previously looked at developing novel methods to extract records stored on smart blood pressure monitors (BPM). There are currently no forensic tools or methods to extract data from smart BPMs. BPMs are capable of storing records that can contain useful information in a criminal investigation. Investigators could use the method to acquire from a range of smart health care devices for example to debate the users’ movements, time of death, etc.

I am currently conducting an online survey to investigate the understandings and interpretations of IoT forensics and to identify the research challenges faced by current forensic specialists. We want to gain an insight into what investigators consider as an IoT device, what they believe the main issues are, and research areas IoT forensics should focus on.

What's the most outlandish IoT-related investigation story you've heard so far?

We have yet to see many actual IoT investigations, but with more lightbulbs, refrigerators, sex toys, pet feeders, etc. being connected to the internet we will expect to see more bizarre forensic investigations. Researchers have already discovered that the We-Vibe sex toys collect data, which could potentially be useful in a forensic investigation to create a timeline of events.

In your opinion, what are some of the challenges associated with IoT investigations, and what might we do to address them?

Research in this area is still at an early stage and is mostly theoretical. One challenge is understanding the complex interconnections between IoT devices and where they store data. We are not only looking at the IoT device itself but we also have to consider other components. In a smart home we now have devices that are able to be a “digital witness” to events. The challenge for investigator is to find ways to access this data in a forensic manner.

The IoT survey I am currently conducting will help establish better understanding of the issues in IoT forensics a forensic investigator faces, to help develop tools, legal procedures methods, etc.

What other areas of digital forensics are you interested in?

I mentioned before I am interested in non-traditional forensics and I have also taken an interest in drone forensics. It will be interesting to see how this research area is developing with the increasing use of consumer drones. Drones can be misused to carry out illegal activities; most recently in the media where a drone crashed into a nuclear power station, this obviously poses a threat to public and national security. So it is interesting what forensic artefacts are left on the intercepted drone and whether ownership can be established.

Finally, when you're not researching, what do you enjoy doing in your spare time?

In my spare time I enjoy hiking in South Wales, recently I have been following the vale trails which takes you to interesting historical points. I also enjoy archery: having taken this up at university I have now joined a local archery club.

Find Tina's survey about Internet of Things forensics here.

Tina Wu completed her MSc in Forensic Computing and Security at the University of Derby. She then joined Airbus Group as a Research Engineer focusing on research in cyber security and forensics in industrial control systems. Her research interests are in forensics and monitoring of industrial control systems with a focus on live memory forensics, novel attack detection methods, malware analysis, side channel attacks and the Internet of Things (IoT). Now she is a DPhil student at Oxford’s CDT in Cyber Security, her research focuses on developing and improving the digital forensic process in the IoT.

Leave a Comment

Latest Videos

In this episode of the Forensic Focus podcast, Si and Desi explore how artificial intelligence is being leveraged to uncover crucial evidence in investigations involving child sexual abuse material (CSAM) and examine the importance of exercising caution when implementing these tools. 

They also discuss a recent murder case in which cyber experts played a vital role in securing a conviction, and explore the unique challenges associated with using digital evidence as an alibi.

Show Notes:

A Practitioner Survey Exploring the Value of Forensic Tools, AI, Filtering, & Safer Presentation for Investigating Child Sexual Abuse Material (CSAM) - https://dfrws.org/wp-content/uploads/2019/06/2019_USA_paper-a_practitioner_survey_exploring_the_value_of_forensic_tools_ai_filtering_safer_presentation_for_investigating_child_sexual_abuse_material_csam.pdf

Man charged with NI murder ‘faked live stream to provide alibi’ (The Guardian) - https://www.theguardian.com/uk-news/2023/feb/02/man-charged-with-ni-faked-live-stream-to-provide-alibi

A YouTuber accused of murder faked a 6-hour livestream to produce an alibi (Sportskeeda) - https://www.sportskeeda.com/esports/news-a-youtuber-accused-murder-faked-6-hour-livestream-produce-alibi

European Interdisciplinary Cybersecurity Conference (EICC) 2023 - https://www.forensicfocus.com/event/european-interdisciplinary-cybersecurity-conference-eicc-2023/#more-493234

YouTuber reportedly faked GTA livestream to have an alibi while he committed murder (Dexerto) - https://www.dexerto.com/entertainment/youtuber-reportedly-faked-gta-livestream-to-have-an-alibi-while-he-committed-murder-2052974/

Forensic Europe Expo - https://www.forensicfocus.com/event/forensic-europe-expo/#more-493225

In this episode of the Forensic Focus podcast, Si and Desi explore how artificial intelligence is being leveraged to uncover crucial evidence in investigations involving child sexual abuse material (CSAM) and examine the importance of exercising caution when implementing these tools.

They also discuss a recent murder case in which cyber experts played a vital role in securing a conviction, and explore the unique challenges associated with using digital evidence as an alibi.

Show Notes:

A Practitioner Survey Exploring the Value of Forensic Tools, AI, Filtering, & Safer Presentation for Investigating Child Sexual Abuse Material (CSAM) - https://dfrws.org/wp-content/uploads/2019/06/2019_USA_paper-a_practitioner_survey_exploring_the_value_of_forensic_tools_ai_filtering_safer_presentation_for_investigating_child_sexual_abuse_material_csam.pdf

Man charged with NI murder ‘faked live stream to provide alibi’ (The Guardian) - https://www.theguardian.com/uk-news/2023/feb/02/man-charged-with-ni-faked-live-stream-to-provide-alibi

A YouTuber accused of murder faked a 6-hour livestream to produce an alibi (Sportskeeda) - https://www.sportskeeda.com/esports/news-a-youtuber-accused-murder-faked-6-hour-livestream-produce-alibi

European Interdisciplinary Cybersecurity Conference (EICC) 2023 - https://www.forensicfocus.com/event/european-interdisciplinary-cybersecurity-conference-eicc-2023/#more-493234

YouTuber reportedly faked GTA livestream to have an alibi while he committed murder (Dexerto) - https://www.dexerto.com/entertainment/youtuber-reportedly-faked-gta-livestream-to-have-an-alibi-while-he-committed-murder-2052974/

Forensic Europe Expo - https://www.forensicfocus.com/event/forensic-europe-expo/#more-493225

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_7QiFTiuY7Vw

AI In CSAM Investigations And The Role Of Digital Evidence In Criminal Cases

Forensic Focus 22nd March 2023 12:44 pm

Throughout the past few years, the way employees communicate with each other has changed forever.

69% of employees note that the number of business applications they use at work has increased during the pandemic.

Desk phones, LAN lines and even VOIP have become technologies of the past workplace environment as employees turn to cloud applications on their computers and phones to collaborate with each other in today’s workplace environment.

Whether it’s conversations in Teams, file uploads in Slack chats, or confidential documents stored in Office 365, the amount of data stored and where it is stored, is growing quicker than IT and systems administrators can keep up with.

Corporate investigators and eDiscovery professionals need to seamlessly collect relevant data from cloud sources and accelerate the time to investigative and discovery review.

With the latest in Cellebrite’s remote collection suite of capabilities, investigators and legal professionals can benefit from secure collection with targeted capabilities for the most used workplace applications.

Join Monica Harris, Product Business Manager, as she showcases how investigators can:

- Manage multiple cloud collections through a web interface
- Cull data prior to collection to save time and money by gaining these valuable insights of the data available
- Collect data from the fastest growing cloud collaboration applications like Office365, Google Workspace, Slack and Box
- Login to a single source for workplace app collection without logging into every app and pulling data from multiple sources for every employee
- Utilize a single unified collection workflow for computer, mobile and workplace cloud applications without the need to purchase multiple tools for different types of collections – a solution unique to Cellebrite’s enterprise solution capabilities

Throughout the past few years, the way employees communicate with each other has changed forever.

69% of employees note that the number of business applications they use at work has increased during the pandemic.

Desk phones, LAN lines and even VOIP have become technologies of the past workplace environment as employees turn to cloud applications on their computers and phones to collaborate with each other in today’s workplace environment.

Whether it’s conversations in Teams, file uploads in Slack chats, or confidential documents stored in Office 365, the amount of data stored and where it is stored, is growing quicker than IT and systems administrators can keep up with.

Corporate investigators and eDiscovery professionals need to seamlessly collect relevant data from cloud sources and accelerate the time to investigative and discovery review.

With the latest in Cellebrite’s remote collection suite of capabilities, investigators and legal professionals can benefit from secure collection with targeted capabilities for the most used workplace applications.

Join Monica Harris, Product Business Manager, as she showcases how investigators can:

- Manage multiple cloud collections through a web interface
- Cull data prior to collection to save time and money by gaining these valuable insights of the data available
- Collect data from the fastest growing cloud collaboration applications like Office365, Google Workspace, Slack and Box
- Login to a single source for workplace app collection without logging into every app and pulling data from multiple sources for every employee
- Utilize a single unified collection workflow for computer, mobile and workplace cloud applications without the need to purchase multiple tools for different types of collections – a solution unique to Cellebrite’s enterprise solution capabilities

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_g6nTjfEMnsA

Tips And Tricks Data Collection For Cloud Workplace Applications

Forensic Focus 20th March 2023 12:00 pm

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles

Share to...