Hybrid Hierarchical Runtime Verification for Edge-IoT Security: Combining MonPoly and RTLola
A three-layer edge-IoT monitor pairs MonPoly with RTLola to catch coordinated attacks and silent compromised nodes.
The paper proposes a three-layer runtime-verification design for edge-IoT fleets: edge classification, gateway aggregation of short per-device windows, and a cloud tier running MonPoly and RTLola together. MonPoly checks first-order temporal patterns such as coordinated overflow and per-device multi-vector, escalation, and persistent-campaign activity, while RTLola checks a time-triggered silent-node property that event-triggered monitors miss once a device goes quiet. On a 15-actor Docker testbed with eight attack profiles plus a silent-bypass case, device-attributable incidents named attacker-labelled devices and RTLola caught silent bypasses. Per-event monitoring stayed in the microsecond range at the edge and gateway.
- Three layers: edge classification, gateway aggregation, and cloud MonPoly plus RTLola.
- MonPoly correlates coordinated overflow and multi-vector patterns across merged alerts.
- RTLola detects silent-node bypass that event-triggered monitors miss under fleet silence.
- Evaluated on a 15-actor Docker testbed with eight attack profiles plus silent bypass.
- Edge and gateway per-event monitoring stays in the microsecond range.
Full article225 words · extracted from arxiv.org · click to collapse
Security monitoring of edge-IoT fleets faces three structural challenges. (i) A per-node monitor is cheap but cannot see attacks that coordinate across devices. (ii) A cloud monitor sees the full fleet but pays for that view in bandwidth. (iii) Even at the cloud, a monitor built on a single RV engine can be fooled by an attacker who compromises a device, raises one malicious request, and then goes silent: once the events stop, an event-triggered monitor has nothing left to evaluate. We propose a three-layer hierarchical runtime-verification framework that addresses all three. The edge layer classifies events as they happen, the gateway layer aggregates short windows of per-device behaviour, and the cloud layer runs two complementary RV engines. MonPoly handles first-order temporal correlation over the merged alert stream: coordinated overflow (which genuinely quantifies across devices) plus per-device multi-vector APT, escalation, and persistent-campaign patterns. RTLola handles a time-triggered silent-node property that an event-triggered engine cannot detect within a bounded delay under fleet silence. We evaluate the framework on a 15-actor Docker testbed covering eight attack profiles plus a silent-bypass scenario. In the controlled labelled testbed, every device-attributable incident the framework raises names an attacker-labelled device, and the RTLola tier catches silent-bypass attempts the event-triggered tier misses. Per-event monitoring stays in the microsecond range at the edge and gateway, with low end-to-end alert-to-incident latency at the cloud.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2610.09825