Today’s smart spaces deploy various IoT devices to offer services for occupants. Such devices are exposed to security risks that may pose serious threats to network services and users’ privacy. To avoid the disruption of normal operations, self-protecting solutions have been developed to allow IoT networks to autonomously respond to cyber threats in real-time. However, existing self-protecting systems focus solely on architectural adaptations to respond to cyber threats, overlooking the mitigation actions described in cybersecurity standards –which represent the correct cybersecurity posture– as well as the impact of the adaptation strategies on the Quality-of-Service (QoS) performance. To overcome these existing limitations, this paper presents SPARQ, a novel framework for designing self-protecting IoT systems that considers both the security exposure to cyber attacks and the QoS performance. We leverage Attack Graph as a threat model for analyzing the cyber exposure of the system and Queuing Network Models to analyze QoS in IoT systems. Based on the analysis outcomes, SPARQ provides mitigation plans to reduce the cyber risk while also minimizing the impact on QoS. We evaluate the proposed approach on two use cases from real-world scenarios including a critical infrastructure and a smart home. The experimental evaluation shows that SPARQ is capable of reducing the cyber risk significantly while also improving the QoS performance by 35% compared to existing approaches.

SPARQ: a QoS-Aware framework for mitigating cyber risk in self-protecting IoT systems / Palma, Alessandro; Hajj Hassan, Houssam; Bouloukakis, Georgios. - (2025), pp. 159-170. ( 20th IEEE/ACM Symposium on Software Engineering for Adaptive and Self-Managing Systems, SEAMS 2025 Ottawa, Ontario, Canada ) [10.1109/SEAMS66627.2025.00025].

SPARQ: a QoS-Aware framework for mitigating cyber risk in self-protecting IoT systems

Alessandro Palma
Primo
;
2025

Abstract

Today’s smart spaces deploy various IoT devices to offer services for occupants. Such devices are exposed to security risks that may pose serious threats to network services and users’ privacy. To avoid the disruption of normal operations, self-protecting solutions have been developed to allow IoT networks to autonomously respond to cyber threats in real-time. However, existing self-protecting systems focus solely on architectural adaptations to respond to cyber threats, overlooking the mitigation actions described in cybersecurity standards –which represent the correct cybersecurity posture– as well as the impact of the adaptation strategies on the Quality-of-Service (QoS) performance. To overcome these existing limitations, this paper presents SPARQ, a novel framework for designing self-protecting IoT systems that considers both the security exposure to cyber attacks and the QoS performance. We leverage Attack Graph as a threat model for analyzing the cyber exposure of the system and Queuing Network Models to analyze QoS in IoT systems. Based on the analysis outcomes, SPARQ provides mitigation plans to reduce the cyber risk while also minimizing the impact on QoS. We evaluate the proposed approach on two use cases from real-world scenarios including a critical infrastructure and a smart home. The experimental evaluation shows that SPARQ is capable of reducing the cyber risk significantly while also improving the QoS performance by 35% compared to existing approaches.
2025
20th IEEE/ACM Symposium on Software Engineering for Adaptive and Self-Managing Systems, SEAMS 2025
Self-protection; Attack Graph; Quality of Service; Cyber Risk
04 Pubblicazione in atti di convegno::04b Atto di convegno in volume
SPARQ: a QoS-Aware framework for mitigating cyber risk in self-protecting IoT systems / Palma, Alessandro; Hajj Hassan, Houssam; Bouloukakis, Georgios. - (2025), pp. 159-170. ( 20th IEEE/ACM Symposium on Software Engineering for Adaptive and Self-Managing Systems, SEAMS 2025 Ottawa, Ontario, Canada ) [10.1109/SEAMS66627.2025.00025].
File allegati a questo prodotto
File Dimensione Formato  
Palma_postprint_SPARQ_2025.pdf.pdf

accesso aperto

Note: DOI: 10.1109/SEAMS66627.2025.00025
Tipologia: Documento in Post-print (versione successiva alla peer review e accettata per la pubblicazione)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 2.02 MB
Formato Adobe PDF
2.02 MB Adobe PDF
Palma_SPARQ_2025.pdf

solo gestori archivio

Tipologia: Versione editoriale (versione pubblicata con il layout dell'editore)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 4.99 MB
Formato Adobe PDF
4.99 MB Adobe PDF   Contatta l'autore

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/1736231
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact