🤖 AI Summary
This study addresses the challenges of cross-device collaborative attack detection, bandwidth constraints, and silent-node evasion in secure edge IoT monitoring by proposing a three-tier hierarchical runtime verification framework. The approach integrates a dual-engine architecture combining MonPoly and RTLola with event-triggered and time-triggered mechanisms, wherein MonPoly processes temporal correlations and RTLola performs periodic monitoring, thereby overcoming the inability of single-engine systems to detect silent attacks. Docker-based testbed experiments demonstrate that the proposed framework efficiently captures both collaborative attacks and silent evasion behaviors while achieving microsecond-level edge latency and low alert delays. Furthermore, it exhibits high-accuracy device attribution capabilities, offering a robust solution for real-time security enforcement in resource-constrained edge environments.
📝 Abstract
Security monitoring of edge-IoT fleets faces three structural challenges. (i) A per-node monitor is cheap but cannot see attacks that coordinate across devices. (ii) A cloud monitor sees the full fleet but pays for that view in bandwidth. (iii) Even at the cloud, a monitor built on a single RV engine can be fooled by an attacker who compromises a device, raises one malicious request, and then goes silent: once the events stop, an event-triggered monitor has nothing left to evaluate. We propose a three-layer hierarchical runtime-verification framework that addresses all three. The edge layer classifies events as they happen, the gateway layer aggregates short windows of per-device behaviour, and the cloud layer runs two complementary RV engines. MonPoly handles first-order temporal correlation over the merged alert stream: coordinated overflow (which genuinely quantifies across devices) plus per-device multi-vector APT, escalation, and persistent-campaign patterns. RTLola handles a time-triggered silent-node property that an event-triggered engine cannot detect within a bounded delay under fleet silence. We evaluate the framework on a 15-actor Docker testbed covering eight attack profiles plus a silent-bypass scenario. In the controlled labelled testbed, every device-attributable incident the framework raises names an attacker-labelled device, and the RTLola tier catches silent-bypass attempts the event-triggered tier misses. Per-event monitoring stays in the microsecond range at the edge and gateway, with low end-to-end alert-to-incident latency at the cloud.