IoT forensics: Exploiting log records from the DAHUA technology CCTV systems

J Forensic Sci. 2024 Jan;69(1):117-130. doi: 10.1111/1556-4029.15401. Epub 2023 Oct 10.

Abstract

CCTV surveillance systems are ubiquitous IoT appliances. Their forensic examination has proven critical for investigating crimes. DAHUA Technology is a well-known manufacturer of such products. Despite its global market share, research regarding digital forensics of DAHUA Technology CCTV systems is scarce and currently limited to extracting their video footage, overlooking the potential presence of valuable artifacts within their log records. These pieces of evidence remain unexploited by major commercial forensic software, yet they can hide vital information for an investigation. For instance, these log records document user actions, such as formatting the CCTV system's hard drive or disabling camera recording. This information can assist in attributing nefarious actions to specific users and hence can be invaluable for understanding the sequence of events related to incidents. Therefore, in this paper, several DAHUA Technology CCTV systems are thoroughly analyzed for these unexplored pieces of evidence, and their forensic value is presented.

Keywords: CCTV; CCTV AI capabilities; DAHUA technology; DAHUA technology log records; DVR; IP camera; IoT forensics; NVR; SQLite.