Edge-Enabled Anomaly Detection for Internet of Things Networks: Architectures, Learning Methods, and Security Considerations

Authors

  • Chen Author

Keywords:

edge computing, fog computing, IOT

Abstract

The proliferation of Internet of Things devices has produced distributed environments characterized by continuous data generation, heterogeneous hardware, constrained computational resources, and expanded cybersecurity attack surfaces. Traditional cloud-centric security architectures may introduce latency, bandwidth consumption, and dependence on remote connectivity that limit their effectiveness for time-sensitive anomaly detection. Edge and fog computing offer an alternative by positioning computation, storage, and security analytics closer to data-generating devices. This review examines edge-enabled anomaly and intrusion detection approaches applicable to IoT environments through 2020. It first discusses cloud, fog, and edge architectures and analyzes their implications for latency, scalability, security monitoring, and computational resource allocation. Classical statistical and machine-learning approaches are then compared with emerging deep-learning techniques including autoencoders, recurrent neural networks, and ensemble-based detection. Representative IoT intrusion-detection systems and datasets, including SVELTE, UNSW-NB15, N-BaIoT, Bot-IoT, and Kitsune, are considered in relation to traffic characteristics and deployment requirements. The review identifies persistent challenges involving highly imbalanced network traffic, concept drift, adversarial behavior, resource-constrained devices, encrypted communication, false-positive rates, and limited availability of realistic benchmark datasets. Edge intelligence is concluded to be a promising architectural foundation for responsive IoT security, provided that detection accuracy is balanced against resource and privacy constraints.

References

Shi W, Cao J, Zhang Q, Li Y, Xu L. Edge computing: vision and challenges. IEEE Internet Things J. 2016;3(5):637-646.

Satyanarayanan M. The emergence of edge computing. Computer. 2017;50(1):30-39.

Bonomi F, Milito R, Zhu J, Addepalli S. Fog computing and its role in the Internet of Things. In: Proceedings of the First Edition of the MCC Workshop on Mobile Cloud Computing. New York: ACM; 2012. p. 13-16.

Chiang M, Zhang T. Fog and IoT: an overview of research opportunities. IEEE Internet Things J. 2016;3(6):854-864.

Yi S, Li C, Li Q. A survey of fog computing: concepts, applications and issues. In: Proceedings of the 2015 Workshop on Mobile Big Data. New York: ACM; 2015. p. 37-42.

Mach P, Becvar Z. Mobile edge computing: a survey on architecture and computation offloading. IEEE Commun Surv Tutor. 2017;19(3):1628-1656.

Roman R, Lopez J, Mambo M. Mobile edge computing, Fog et al.: a survey and analysis of security threats and challenges. Future Gener Comput Syst. 2018;78:680-698.

Ahmed M, Mahmood AN, Hu J. A survey of network anomaly detection techniques. J Netw Comput Appl. 2016;60:19-31.

Chandola V, Banerjee A, Kumar V. Anomaly detection: a survey. ACM Comput Surv. 2009;41(3):15.

Patcha A, Park JM. An overview of anomaly detection techniques: existing solutions and latest technological trends. Comput Netw. 2007;51(12):3448-3470.

Denning DE. An intrusion-detection model. IEEE Trans Softw Eng. 1987;SE-13(2):222-232.

Mirsky Y, Doitshman T, Elovici Y, Shabtai A. Kitsune: an ensemble of autoencoders for online network intrusion detection. In: Network and Distributed System Security Symposium. San Diego: Internet Society; 2018.

Meidan Y, Bohadana M, Mathov Y, Mirsky Y, Shabtai A, Breitenbacher D, Elovici Y. N-BaIoT: network-based detection of IoT botnet attacks using deep autoencoders. IEEE Pervasive Comput. 2018;17(3):12-22.

Doshi R, Apthorpe N, Feamster N. Machine learning DDoS detection for consumer Internet of Things devices. In: IEEE Security and Privacy Workshops. Piscataway: IEEE; 2018. p. 29-35.

Raza S, Wallgren L, Voigt T. SVELTE: real-time intrusion detection in the Internet of Things. Ad Hoc Netw. 2013;11(8):2661-2674.

Moustafa N, Slay J. UNSW-NB15: a comprehensive data set for network intrusion detection systems. In: Military Communications and Information Systems Conference. Piscataway: IEEE; 2015. p. 1-6.

Koroniotis N, Moustafa N, Sitnikova E, Turnbull B. Towards the development of realistic botnet dataset in the Internet of Things for network forensic analytics: Bot-IoT dataset. Future Gener Comput Syst. 2019;100:779-796.

Yin C, Zhu Y, Fei J, He X. A deep learning approach for intrusion detection using recurrent neural networks. IEEE Access. 2017;5:21954-21961.

Shone N, Ngoc TN, Phai VD, Shi Q. A deep learning approach to network intrusion detection. IEEE Trans Emerg Topics Comput Intell. 2018;2(1):41-50.

Xu Z, Liu W. Artificial intelligence for securing IoT services in edge computing: a survey. Secur Commun Netw. 2020;2020:8872586.

Published

2020-06-01