发表机构
Clone Systems; International Hellenic University; Aristotle University of Thessaloniki; University of Thessaly(Clone Systems公司; 国际希腊大学; 塞萨洛尼基亚里士多德大学; 色萨利大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对边缘物联网监控的结构性挑战,提出三层分层运行时验证框架,结合 MonPoly 与 RTLola,实现跨设备协调攻击与静默绕过检测,并在 Docker 测试平台上验证了其有效性与低延迟。
AI 中文摘要
边缘物联网设备群的安全监控面临三个结构性挑战。(i) 每节点监控器成本低廉,但无法察觉跨设备协调的攻击。(ii) 云监控器能观察整个设备群,但为此付出带宽代价。(iii) 即使在云端,基于单一运行时验证引擎构建的监控器也可能被攻击者欺骗:攻击者攻陷一台设备,发起一次恶意请求,然后保持沉默——一旦事件停止,事件触发型监控器便无内容可评估。我们提出一个三层分层运行时验证框架,以应对上述全部三个挑战。边缘层对事件进行实时分类,网关层聚合每台设备行为的短时间窗口,云层则运行两个互补的运行时验证引擎。MonPoly 处理合并告警流上的一阶时序关联:协调溢出(真正跨设备量化)以及每设备多向量高级持续性威胁、升级和持续活动模式。RTLola 处理时间触发型静默节点属性,该属性在设备群静默时,事件触发型引擎无法在有限延迟内检测到。我们在一个包含八个攻击场景及一个静默绕过场景的 15 个参与者 Docker 测试平台上评估了该框架。在受控的带标签测试平台中,框架产生的每个可归因于设备的事件均指向攻击者标记的设备,且 RTLola 层能捕获事件触发型层遗漏的静默绕过尝试。边缘和网关的每事件监控保持在微秒级,云端端到端的告警到事件延迟较低。
英文摘要
Security monitoring of edge-IoT fleets faces three structural challenges. (i) A per-node monitor is cheap but cannot see attacks that coordinate across devices. (ii) A cloud monitor sees the full fleet but pays for that view in bandwidth. (iii) Even at the cloud, a monitor built on a single RV engine can be fooled by an attacker who compromises a device, raises one malicious request, and then goes silent: once the events stop, an event-triggered monitor has nothing left to evaluate. We propose a three-layer hierarchical runtime-verification framework that addresses all three. The edge layer classifies events as they happen, the gateway layer aggregates short windows of per-device behaviour, and the cloud layer runs two complementary RV engines. MonPoly handles first-order temporal correlation over the merged alert stream: coordinated overflow (which genuinely quantifies across devices) plus per-device multi-vector APT, escalation, and persistent-campaign patterns. RTLola handles a time-triggered silent-node property that an event-triggered engine cannot detect within a bounded delay under fleet silence. We evaluate the framework on a 15-actor Docker testbed covering eight attack profiles plus a silent-bypass scenario. In the controlled labelled testbed, every device-attributable incident the framework raises names an attacker-labelled device, and the RTLola tier catches silent-bypass attempts the event-triggered tier misses. Per-event monitoring stays in the microsecond range at the edge and gateway, with low end-to-end alert-to-incident latency at the cloud.
Comments19 pages, 2 figures, 7 tables. Published in Availability, Reliability and Security (ARES 2026), EU Projects Symposium Workshops, Springer LNCS
Journal refAvailability, Reliability and Security (ARES 2026), EU Projects Symposium Workshops, LNCS, Springer, 2027, pp. 222-240
DOI:10.1007/978-3-032-37218-5_14