Internet of things (IoT) ecosystems introduce significant cybersecurity challenges due to device heterogeneity, firmware opacity, constrained resources, distributed deployment, and the integration of devices within wider socio-technical systems where they are used. Existing approaches to address IoT cybersecurity typically address isolated aspects of this problem, such as vulnerability enumeration, anomaly detection, or risk assessment; but without integrating them across the full lifecycle of devices and systems. This paper presents an extensible architecture that unifies cybersecurity testing, runtime monitoring, contextual risk modelling, secure update mechanisms, and auditable evidence management for IoT ecosystems that aims to address these challenges. The framework supports both device under test and system under test perspectives and integrates component-level techniques (such as SBOM generation, network fuzzing, machine learning-based anomaly detection, and access control risk evaluation) with system-level, knowledge-based, risk modelling to capture threat propagation across interconnected assets. A distributed ledger-backed auditable data infrastructure ensures integrity and traceability of indicators, results, and decisions. Automated workflow orchestration enables flexible tool chaining and lifecycle-aware execution aligned with established security development lifecycles. The approach is validated through three industrial use cases in aviation cargo monitoring, smart manufacturing, and telecommunication residential gateways. Results demonstrate the feasibility of combining static analysis, runtime indicators, and dynamic risk assessment to prioritise vulnerabilities contextually, detect anomalous behaviour, and support secure patch deployment in resource-constrained environments. The work advances lifecycle-integrated, system-aware cybersecurity assurance for IoT ecosystems and highlights the need for contextualised, interoperable tooling to address systemic vulnerability and risk propagation in complex systems where IoT, ICT and people interact.
We describe a framework and tool specification that represents a step towards cybersecurity testing and monitoring of IoT ecosystems. We begin with challenges from a previous paper and discuss an integrated approach and tools to enable testing and monitoring to address these challenges. We also describe exemplary use cases of IoT ecosystems and propose approaches to address the challenges using the framework and tools. The current status of this work is that the specification and conceptualisation is complete, use cases are understood with clear challenges and implementation / extension of the tools and framework is underway with tools at different stages of development. Several key observations have been made throughout this work, as follows. 1) Tools may be used in multiple different combinations, and ad-hoc use is also encouraged, where one tool may provide clues and other tools executed to undertake further investigations based on initial results. 2) Automated execution of tool chains is supported by workflows. 3) support for immutable storage of audit records of tests and results is an important requirement. 4) Indicators (observations or measurements representing information of relevance for assessment of cyber security) are a key mechanism for intercommunication between one tool and another, or with the operator. 5) Mapping this work to established security development lifecycles is a useful means of determining applicability and utility of the tools and framework. 6) There is a key interplay between devices and systems. 7) Anomaly detection in multiple forms is a key means of runtime monitoring. 8) Considerable investigation is needed related to the specifics of each device / system as an item of further work.
An edge data center can host applications that require low-latency access to nearby end devices. If the resource requirements of the applications exceed the capacity of the edge data center, some non-latency-critical application components may be offloaded to the cloud. Such offloading may incur financial costs both for the use of cloud resources and for data transfer between the edge data center and the cloud. Moreover, such offloading may violate data protection requirements if components process sensitive data. The operator of the edge data center has to decide which components to keep in the edge data center and which ones to offload to the cloud, with the objective of minimizing financial costs, subject to constraints on latency, data protection, and capacity. In this paper, we formalize this problem and prove that it is strongly NP-hard. To address this problem, we introduce an optimization algorithm that (i) is fast enough to be run online for dynamic and automatic offloading decisions, (ii) guarantees that the solution satisfies hard constraints on latency, data protection, and capacity, and (iii) achieves near-optimal costs. We also show how the algorithm can be extended to handle multiple edge data centers. Experiments performed with up to 450 components show that the cost of the solution found by our algorithm is on average only 2.7% higher than the optimum. At the same time, our algorithm is very fast: it optimizes the placement of 450 components in less than 300 milliseconds on a commodity computer.
Network slicing enables operators to virtually partition network resources and instantiate different virtual networks, supporting flexible quality of service, in the form of service level agreements (SLAs). Optimizing resource allocation for network slicing is a complex task, given the dynamicity and randomness of network conditions. Leveraging principles of reinforcement learning, we propose an algorithmic solution to optimize the SLA success rate across a radio access network. Tailoring the algorithm to the problem at hand, and leveraging some prior knowledge on the system to be optimized, we ensure fast convergence, data efficiency, and safe exploration. The solution is scalable both in the number of cells and in the number of slices. Extensive numerical evaluations on a simulated environment show the effectiveness of the proposed solution and its advantages versus both simple baselines and sophisticated solutions based on deep reinforcement learning, in terms of speed of convergence and SLA success rate.
Data produced by end devices like smartphones, sensors or IoT devices can be stored and processed across a continuum of compute resources, from end devices via fog nodes to the cloud, enabling reduced latency, increased processing speed and energy savings. However, the data may be sensitive (e.g., personal data or confidential commercially sensitive information), with regulatory or other requirements for its protection. Protecting sensitive data in the dynamic, heterogeneous, and decentralized cloud-to-edge continuum is very challenging. This paper describes a solution: FogProtect, an integrated set of four technologies to protect data in the cloud-to-edge continuum. Fog-Protect addresses four concerns: (i) control and enforcement of distributed data access and usage; (ii) management of distributed data protection policies; (iii) risk assessment for data assets in the cloud-to-edge continuum; (iv) automated optimisation and adaptation to address identified risks. FogProtect operates dynamically, reacting to system changes or detected vulnerabilities to keep the data secure across the cloud- to-edge continuum. This paper describes an overview of the FogProtect concept, discusses each of the four approaches, and illustrates their usage for the protection of data in three real-world use cases.
Wireless networks are becoming more and more complex. New radio access technologies and cell densification have provided increased efficiency and met the needs of an increasing traffic demand. On the other hand, such increment in complexity poses new challenges to legacy network management and optimization solutions. Traditionally, network optimization has been performed by applying static, rule-based schemes. Both in academia and industry, there is a consensus about the need to transit from static optimization approaches to more automated, dynamic, cognitive techniques. In this paper we embrace this perspective and we propose a set of cognitive algorithms for network performance optimization. We leverage the electric antenna tilt to achieve improved network performance. The proposed algorithms rely on reinforcement learning principles and are validated in a simulated environment.
Computing resources are being moved towards the edge of the network, in the form of so-called fog nodes, providing benefits in terms of reduced latency, increased processing speed, data locality, and energy savings. Data produced in end devices like smartphones, sensors or IoT devices can be stored, processed and analysed across a continuum of computing resources, from end devices via fog nodes to cloud services. Data related to critical domains, such as healthcare, public surveillance or home automation, requires tailored data protection mechanisms, spanning the whole computing continuum. The FogProtect project aims to provide novel advanced technologies and methodologies to ensure end-to-end protection of such sensitive data. Our generic solutions facilitate the provisioning and usage of applications and services in the computing continuum, by combining four technology innovations: (1) secure data container technology for data portability and mobility, (2) data-protection-aware adaptive service and resource management, (3) advanced data protection policy management, (4) dynamic data protection risk management models and tools. The applicability and impact of those solutions is evaluated and demonstrated on three complementary real-world use cases in the area of (1) smart cities, (2) smart manufacturing, and (3) smart media.
AbstractTo drive innovation and competitiveness, organisations need to foster the development and broad adoption of data technologies, value-adding use cases and sustainable business models. Enabling an effective data ecosystem requires overcoming several technical challenges associated with the cost and complexity of management, processing, analysis and utilisation of data. This chapter details a community-driven initiative to identify and characterise the key technical research priorities for research and development in data technologies. The chapter examines the systemic and structured methodology used to gather inputs from over 200 stakeholder organisations. The result of the process identified five key technical research priorities in the areas of data management, data processing, data analytics, data visualisation and user interactions, and data protection, together with 28 sub-level challenges. The process also highlighted the important role of data standardisation, data engineering and DevOps for Big Data.
The original version of the chapter was inadvertently published with an error. The affiliation of the author Davide Dalle Carbonare has now been corrected to “Engineering Ingegneria Informatica, Rome, Italy”.
Fog computing uses geographically distributed fog nodes that can supply nearby end devices with low-latency access to cloud-like compute resources. If the load of a fog node exceeds its capacity, some non-latency-critical application components may be offloaded to the cloud. Using commercial cloud offerings for such offloading incurs Ąnancial costs. Optimally deciding which application components to keep in the fog node and which ones to offload to the cloud is a difficult combinatorial problem. We introduce an optimization algorithm that (i) guarantees that the deployment always satisĄes capacity constraints and affinity requirements, (ii) achieves near-optimal cloud usage costs, and (iii) is fast enough to be run online. The practical use of the algorithm is illustrated by applying it to optimizing the applications in a mobile factory.
Fog computing uses geographically distributed fog nodes that can supply nearby end devices with low-latency access to cloud-like compute resources. If the load of a fog node exceeds its capacity, some non-latency-critical application components may be offloaded to the cloud. Using commercial cloud offerings for such offloading incurs financial costs. Optimally deciding which application components to keep in the fog node and which ones to offload to the cloud is a difficult combinatorial problem. We introduce an optimization algorithm that (i) guarantees that the deployment always satisfies capacity constraints, (ii) achieves near-optimal cloud usage costs, and (iii) is fast enough to be run online. Experimental results show that our algorithm can optimize the deployment of hundreds of components in a fraction of a second on a commodity computer, while leading to only slightly higher costs than the optimum.
Zoltán Ádám Mann合作论文数Department of Computer Science and Information Theory
Budapest University of Technology and Economics5
Ioannis Krontiris合作论文数Athens Information Technology1