Abstract
The rapid growth of the IoT has revolutionized digital communication by providing universal connectivity to resource-constrained embedded devices. However, many of the IoT deployments still lack adequate forensic readiness mechanisms to preserve the digital evidence during security incidents. Most of the existing forensic logging techniques Most existing forensic logging techniques target resource-rich computing environments and frequently depend on persistent local storage or costly logging mechanisms. for resource-rich computing environments and often rely on persistent local storage or computationally expensive logging mechanisms. Therefore, they are not suitable for ESP32-based IoT devices with limited memory, processing capability, and storage. This limitation results in a large research gap for developing lightweight forensic logging solutions that can preserve evidence integrity without degrading device performance. This study addresses this challenge by proposing a lightweight forensic logging framework for ESP32-based IoT ecosystems that supports continuous evidence collection with minimal computational and communication overhead. The framework uses an optimized MQTT-based logging protocol to transmit, in real-time, filtered event logs from ESP32 devices to the ELK, where Logstash normalizes the data and Elasticsearch provides centralized storage and forensic analysis. The proposed framework for evidence preservation and reliability of logging and communication performance was evaluated with simulated deauthentication and MitM attack scenarios. Experimental results show the framework can successfully preserve the continuous forensic evidence while maintaining the end-to-end log transmission latency below 200 ms and without disturbing the primary functions of the IoT devices. These results suggest that lightweight remote logging increases forensic readiness in constrained IoT environments, allowing reliable evidence collection with minimal operational overhead. However, the evaluation was limited to ESP32 devices and two representative attack scenarios, which might limit the generalizability of the results to other IoT platforms and more complex attack models. Future work includes investigation of the scalability of the framework in different IoT environments, adding more attack scenarios and integrating automated forensic analytics to improve incident investigation and response capabilities.
References
Balasubramanian, P., Nazari, S., Kholgh, D. K., Mahmoodi, A., Seby, J., & Kostakos, P. (2025). A cognitive platform for collecting cyber threat intelligence and real-time detection using cloud computing. Decision Analytics Journal, 14, 100545.
Bonaventura, D., Esposito, S., & Bella, G. (2025). A case of smart devices that compromise home cybersecurity. Computers & Security, 151, 104286.
Djenna, A., Harous, S., & Saidouni, D. E. (2021). Internet of things meet internet of threats: New concern cyber security issues of critical cyber infrastructure. Applied Sciences, 11(10), 4580.
Elgazzar, K., Khalil, H., Alghamdi, T., Badr, A., Abdelkader, G., Elewah, A., & Buyya, R. (2022). Revisiting the internet of things: New trends, opportunities and grand challenges. In (Vol. 1, pp. 1073780): Frontiers Media SA.
González-Granadillo, G., González-Zarzosa, S., & Diaz, R. (2021). Security information and event management (SIEM): analysis, trends, and usage in critical infrastructures. Sensors, 21(14), 4759.
Islam, U., Alatawi, M. N., Alamro, S., Alwageed, H. S., Ullah, H., & Khan, N. (2025). Enhancing physical security in IIoMT environments. Internet of Things, 33, 101653.
Jesus, B., Lins, F., & Laranjeiro, N. (2025). An approach to assess robustness of MQTT-based IoT systems. Internet of Things, 31, 101590.
Khan, I. H., & Javaid, M. (2022). Role of Internet of Things (IoT) in adoption of Industry 4.0. Journal of Industrial Integration and Management, 7(04), 515-533.
Khan, S., Dilshad, N., Ahmad, N., Noor, S., & AlQahtani, S. A. (2025). Integrating AI in security information and event management for real time cyber defense. Scientific Reports, 15(1), 35872.
Mir, M. M., Tan, W. L., & Awrangjeb, M. (2025). A comprehensive review of IoT device fingerprinting: Insights into techniques, trends, challenges, and future directions. Internet of Things, 101758.
Okolie, S., Amadi, C., Odii, J., Nwokorie, E., & Onyemauche, U. (2025). Anomaly Detection in Heterogeneous Cybersecurity Data. Franklin Open, 100426.
Piroddi, A., Lam, C.-T., Pau, G., Girau, R., & Melis, A. (2026). Anomaly detection of cyber threats in industrial iot networks via hybrid digital twins and continual learning. Internet of Things, 101915.
Praharaj, L., Gupta, D., & Gupta, M. (2025). Efficient federated transfer learning-based network anomaly detection for cooperative smart farming infrastructure. Smart Agricultural Technology, 10, 100727.
Ramadan, M. N., Ali, M. A., Khoo, S. Y., & Alkhedher, M. (2024). AI-powered IoT and UAV systems for real-time detection and prevention of illegal logging. Results in Engineering, 24, 103277.
Serepas, F., Papias, I., Christakis, K., Dimitropoulos, N., & Marinakis, V. (2025). Lightweight embedded IoT gateway for smart homes based on an ESP32 microcontroller. Computers, 14(9), 391.
Shahri, E., Pedreiras, P., Almeida, L., & Sousa, J. (2023). Scalable SDN-based MQTT real-time communications for edge networks. 2023 IEEE 28th International Conference on Emerging Technologies and Factory Automation (ETFA),
Szymoniak, S., & Pyrkosz-Dziubczyk, A. (2025). Device-to-device IoT System-based Security Protocol for Agreeing on Social Meetings. Computer Networks, 111762.
Tleuberdin, S., Issainova, A., Adamova, A., Aidynov, T., Samashova, G., & Satybaldina, D. (2025). Analysis of Vulnerabilities and Practical Attacks on WPA3-Enterprise in Corporate Wireless Networks. Procedia Computer Science, 272, 613-618.
Wang, Y., Castillejo, P., Martínez-Ortega, J.-F., & Díaz, V. H. (2025). A survey on Identity and Access Management for future IoT services. Computer Networks, 111718.
Wibowo, B., & Hidayat, T. (2025). Strategi efektif dalam meningkatkan kesadaran keamanan siber terhadap ancaman phishing di lingkungan perusahaan PT. XYZ. Jurnal Pengabdian Masyarakat Sultan Indonesia, 2(1), 1-9.
Wibowo, B., Nurrohman, A., & Hafiz, L. (2025). Deep Learning in Wazuh Intrusion Detection System to Identify Advanced Persistent Threat (APT) Attacks. International Journal of Science Education and Cultural Studies, 4(1), 1-10.
Yalli, J. S., Hasan, M. H., Jung, L. T., & Al-Selwi, S. M. (2025). Authentication schemes for Internet of Things (IoT) networks: A systematic review and security assessment. Internet of Things, 30, 101469.