Recently, IP cameras have become increasingly popular as low-cost and high-efficiency video devices due to their expanding functionalities and ease of installation and operation through mobile application integration. As a result, IP cameras are now c...
Recently, IP cameras have become increasingly popular as low-cost and high-efficiency video devices due to their expanding functionalities and ease of installation and operation through mobile application integration. As a result, IP cameras are now commonly found in everyday environments and are widely utilized as important digital evidence in criminal investigations and incident analysis, extending beyond traditional CCTV systems. However, frequent domestic and international incidents involving IP camera hacking have raised persistent concerns regarding security and privacy violations, highlighting the need for systematic countermeasures from a digital forensic perspective. Despite this, most existing studies on IP cameras primarily focus on vulnerability assessment and security issues, while research on data acquisition and analysis from a digital forensic standpoint remains relatively limited. Since IP camera data are distributed across multiple environments—such as SD cards, web, mobile applications, and cloud platforms—comprehensive forensic research that integrates these environments is required. This paper proposes data acquisition and analysis methods for four IP cameras commonly used in South Korea, focusing on SD cards, web, mobile applications, and cloud environments. IP cameras are installed and controlled via mobile applications, and video data may be stored simultaneously on SD cards and cloud servers, with some services additionally providing web-based access. Considering these characteristics, this study derives acquisition techniques for forensic artifacts, including account information, device information, user activity logs, and media data, across each access environment. Furthermore, user behavior–based artifact analysis and network traffic analysis were conducted, with a particular focus on cloud service environments. The transmission and storage structures of video data were examined through API-based analysis of cloud services. The experimental results demonstrate that logs and video files can be obtained from IP camera SD cards, where logs contain account information, device information, and user activity records. Mobile applications store manually saved video files, along with account and device information. Notably, cloud analysis linked to IP camera devices and mobile applications revealed a larger volume of stored video data, more detailed device information, and notification logs such as person detection events. The API communication structure between IP cameras and cloud servers was systematically categorized according to functional operations, including device information retrieval, video download, and notification log access. By utilizing data obtained from SD card and mobile application analysis for cloud API calls, this study verified that IP camera data acquisition can be performed more efficiently. Moreover, an open-source tool named IPCAT (IP Camera Analysis Tool) was developed to automate IP camera data acquisition. This study is significant in that it comprehensively analyzes and proposes acquisition methods for digital forensic data—such as account and device information, media data, and activity logs—by considering multiple IP camera access environments, including SD cards, web, mobile applications, and cloud platforms. In addition, the development of an open-source cloud API–based data acquisition tool contributes to improving the efficiency of IP camera forensic analysis. The findings of this study may also serve as a reference for forensic analysis of other cloud-based IoT devices. It is expected that the integrated data analysis approach proposed in this study will contribute to IP camera investigations and forensic analysis practices.