A secure framework for containerized IoT applications in integrated edge–cloud computing environments

Qifan Deng, Mohammad Goudarzi, Arash Shaghaghi, Majid Sarvi, Rajkumar Buyya · Future Generation Computer Systems · 2025

The integration of edge and cloud computing combines low latency with high computational power, addressing the constraints of edge resources and high access latency inherent in cloud environments. This is essential for deploying Internet of Things (IoT) applications, which are mainly developed by Containers within these heterogeneous environments. However, the open, multi-user nature of edge computing, compounded by a lack of standardized practices, introduces substantial security challenges with severe economic implications. In response, we propose SecConEC, an economically driven framework designed to secure the deployment and execution of containerized IoT applications. We conducted systematic threat modeling using the STRIDE framework, explicitly incorporating quantitative economic risk assessment to identify and prioritize security threats based on their potential economic impacts. We particularly focus on tampering and resource hijacking threats. SecConEC implements robust yet lightweight mitigation and detection mechanisms informed by the MITRE ATT&CK framework through a Security Information and Event Management (SIEM) system. Also, SecConEC introduces a dynamic, security-aware scheduling mechanism that balances performance and security considerations, proactively mitigating economic risks associated with potential security threats. Extensive performance evaluation shows that SecConEC significantly mitigates prioritized threats, effectively securing IoT application deployment and execution in edge-cloud environments, while maintaining low service latency with a minimal performance overhead of 1.7%.

Read the paper · More papers on PaperTik