Operational cyber resilience assessment of edge IoT systems using a PH MMPP framework from IDS observable attack regimes
摘要
This study developed an analytical PH/MMPP priority-clearing framework for assessing the operational cyber resilience of Edge-IoT systems. The framework complements intrusion-detection approaches by transforming IDS-observable attack-traffic regimes into quantitative indicators of service degradation, including queue accumulation, latency amplification, residual service capacity, destructive clearing risk, service survivability, and spectral proximity to overload instability. The obtained results demonstrated substantial degradation of Edge-IoT service behaviour under attack escalation: the mean ordinary-queue length increased from 0.74 to 286.91 packets, the virtual ordinary-queueing delay rose from 0.011 to 11.428 s, the operational response-time indicator increased from 0.021 to 23.706 s, and the legitimate-service survivability probability decreased from 0.983 to 0.0064. The framework was calibrated using traffic characteristics extracted from the CICIoT2023 and Edge-IIoTset datasets and subsequently applied to the analysis of generalised operational attack regimes rather than dataset-specific cases. By integrating IDS-observable attack regimes with queueing dynamics, service survivability, and spectral stability analysis within a unified stochastic framework, the proposed approach enables a transition from attack-detection assessment to the quantitative evaluation of the operational cyber resilience of Edge-IoT services.