Hybrid Hierarchical Runtime Verification for Edge-IoT Security: Combining MonPoly and RTLola

📅 2026-10-07
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenges of cross-device collaborative attack detection, bandwidth constraints, and silent-node evasion in secure edge IoT monitoring by proposing a three-tier hierarchical runtime verification framework. The approach integrates a dual-engine architecture combining MonPoly and RTLola with event-triggered and time-triggered mechanisms, wherein MonPoly processes temporal correlations and RTLola performs periodic monitoring, thereby overcoming the inability of single-engine systems to detect silent attacks. Docker-based testbed experiments demonstrate that the proposed framework efficiently captures both collaborative attacks and silent evasion behaviors while achieving microsecond-level edge latency and low alert delays. Furthermore, it exhibits high-accuracy device attribution capabilities, offering a robust solution for real-time security enforcement in resource-constrained edge environments.
📝 Abstract
Security monitoring of edge-IoT fleets faces three structural challenges. (i) A per-node monitor is cheap but cannot see attacks that coordinate across devices. (ii) A cloud monitor sees the full fleet but pays for that view in bandwidth. (iii) Even at the cloud, a monitor built on a single RV engine can be fooled by an attacker who compromises a device, raises one malicious request, and then goes silent: once the events stop, an event-triggered monitor has nothing left to evaluate. We propose a three-layer hierarchical runtime-verification framework that addresses all three. The edge layer classifies events as they happen, the gateway layer aggregates short windows of per-device behaviour, and the cloud layer runs two complementary RV engines. MonPoly handles first-order temporal correlation over the merged alert stream: coordinated overflow (which genuinely quantifies across devices) plus per-device multi-vector APT, escalation, and persistent-campaign patterns. RTLola handles a time-triggered silent-node property that an event-triggered engine cannot detect within a bounded delay under fleet silence. We evaluate the framework on a 15-actor Docker testbed covering eight attack profiles plus a silent-bypass scenario. In the controlled labelled testbed, every device-attributable incident the framework raises names an attacker-labelled device, and the RTLola tier catches silent-bypass attempts the event-triggered tier misses. Per-event monitoring stays in the microsecond range at the edge and gateway, with low end-to-end alert-to-incident latency at the cloud.
Problem

Research questions and friction points this paper is trying to address.

Edge-IoT Security
Runtime Verification
Cross-device Attacks
Silent-node Bypass
Security Monitoring
Innovation

Methods, ideas, or system contributions that make the work stand out.

Hierarchical Runtime Verification
Edge-IoT Security
MonPoly
RTLola
Silent-node Detection
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
N
Nikolaos Kekatos
Clone Systems, Larnaca, Cyprus
M
Marinelio Chintri
International Hellenic University, Serres, Greece
Panagiotis Katsaros
Panagiotis Katsaros
Professor of Computer Science, Aristotle University of Thessaloniki, Greece
Software SecurityVerificationModel CheckingFormal MethodsSoftware Architecture
Alexios Lekidis
Alexios Lekidis
University of Thessaly
Smart Energy SystemsIndustrial Internet of ThingsNetwork Security
T
Tom Nianios
Clone Systems, Larnaca, Cyprus
I
Ioannis Seitoglou
International Hellenic University, Serres, Greece
A
Anastasios Temperekidis
Clone Systems, Larnaca, Cyprus
S
Stylianos Basagiannis
International Hellenic University, Serres, Greece