发表机构
Clone Systems; International Hellenic University; Aristotle University of Thessaloniki; University of Thessaly(Clone Systems公司; 国际希腊大学; 塞萨洛尼基亚里士多德大学; 色萨利大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
提出基于形式化运行时验证的分层边缘物联网安全监控框架,以量化成本平衡检测能力与资源限制,实现跨设备攻击检测并生成可审计警报。
AI 中文摘要
边缘物联网部署中的网络韧性从根本上是一个经济问题:检测必须使关键流程在攻击下持续运行,但防御资源(计算、带宽、操作员注意力)是有限的。集中式云监控提供了跨设备的高表达性检测,但带宽成本过高;纯边缘本地监控成本低,但对协调的多设备攻击视而不见,在这种攻击中,不对称平衡有利于攻击者。我们提出了一种轻量级分层安全监控框架,基于形式化运行时验证方法,以量化成本占据了实用的中间地带。每个边缘设备运行一个轻量级TeSSLa流规范(大小、负载有效性、速率和时间戳漂移谓词),每个聚合窗口发出四值判定,每事件成本低于微秒;网关运行一个参数化一阶MonPoly监控器,对每设备判定流进行监控,每判定成本为微秒级。边缘到网关的上行链路每节点每个聚合窗口大约携带一个布尔值,比原始数据包流小几个数量级。网关层检测到任何单节点监控器都无法看到的协调攻击模式,将不对称成本平衡转向防御者。每个警报都携带一个见证集,命名设备、监控层和触发的谓词,提供决策的可审计记录。我们在一个容器主机测试平台上评估了该框架,该平台涵盖正常节点和攻击节点,涉及四类攻击(缓冲区溢出、时间欺骗、拒绝服务以及混合高级持续性威胁模式),并描述了边缘层和网关层的规范以及随着监控器级别的增加而出现的成本与覆盖范围的权衡。
英文摘要
Cyber resiliency in edge-IoT deployments is fundamentally an economic problem: detection must keep critical processes operating under attack, but defender resources (compute, bandwidth, operator attention) are bounded. Centralised cloud monitoring offers expressive cross-device detection at prohibitive bandwidth cost; purely edge-local monitoring is cheap but blind to coordinated multi-device attacks where the asymmetric balance favours the attacker. We propose a lightweight hierarchical security-monitoring framework, built on formal runtime-verification methods, that occupies the practical middle ground at quantified cost. Each edge device runs a lightweight TeSSLa stream specification (size, payload validity, rate, and timestamp-drift predicates) that emits a four-valued verdict per aggregation window at sub-microsecond per-event cost; the gateway runs a parametric first-order MonPoly monitor over the per-device verdict streams at microsecond-scale per-verdict cost. The edge-to-gateway uplink carries roughly one Boolean per aggregation window per node, orders of magnitude smaller than the raw packet stream. The gateway tier detects coordinated attack patterns that no single-node monitor can see, shifting the asymmetric cost balance toward the defender. Every alert carries a witness set naming the device, the monitor tier, and the predicate that fired, providing an auditable record of the decision. We evaluate the framework on a container-host testbed spanning nominal and attacker nodes across four attack classes (buffer overflow, time spoofing, denial-of-service, and mixed advanced-persistent-threat patterns), and describe the edge- and gateway-tier specifications together with the cost-versus-coverage trade-off as monitor levels are added.
Comments7 pages, 1 figure, 2 tables. Accepted at the 2026 IEEE International Conference on Cyber Security and Resilience (IEEE CSR 2026)