dorsal/arxiv
View SchemaA Protocol-Aware P4 Pipeline for MQTT Security and Anomaly Mitigation in Edge IoT Systems
| Authors | Bui Ngoc Thanh Binh, Pham Hoai Luan, Le Vu Trung Duong, Vu Tuan Hai, Yasuhiko Nakashima |
|---|---|
| Categories | |
| ArXiv ID | 2601.07536vv1 |
| URL | https://arxiv.org/abs/2601.07536 |
| License | http://creativecommons.org/licenses/by/4.0/ |
Abstract
MQTT is the dominant lightweight publish--subscribe protocol for IoT deployments, yet edge security remains inadequate. Cloud-based intrusion detection systems add latency that is unsuitable for real-time control, while CPU-bound firewalls and generic SDN controllers lack MQTT awareness to enforce session validation, topic-based authorization, and behavioral anomaly detection. We propose a P4-based data-plane enforcement scheme for protocol-aware MQTT security and anomaly detection at the network edge. The design combines parser-safe MQTT header extraction with session-order validation, byte-level topic-prefix authorization with per-client rate limiting and soft-cap enforcement, and lightweight anomaly detection based on KeepAlive and Remaining Length screening with clone-to-CPU diagnostics. The scheme leverages stateful primitives in BMv2 (registers, meters, direct counters) to enable runtime policy adaptation with minimal per-packet latency. Experiments on a Mininet/BMv2 testbed demonstrate high policy enforcement accuracy (99.8%, within 95% CI), strong anomaly detection sensitivity (98\% true-positive rate), and high delivery >99.9% for 100--5~kpps; 99.8% at 10~kpps; 99.6\% at 16~kpps) with sub-millisecond per-packet latency. These results show that protocol-aware MQTT filtering can be efficiently realized in the programmable data plane, providing a practical foundation for edge IoT security. Future work will validate the design on production P4 hardware and integrate machine learning--based threshold adaptation.
{
"annotation_id": "04b74514-74a1-4781-90d3-ae5a2464ccf3",
"date_created": "2026-02-17T05:53:12.645000Z",
"date_modified": "2026-02-17T05:53:12.645000Z",
"file_hash": "f571cc8081c47b2ea5fdede3cd48bf07b8d4a2eca19bf4c7cadf159d678fe845",
"private": false,
"record": {
"abstract": "MQTT is the dominant lightweight publish--subscribe protocol for IoT deployments, yet edge security remains inadequate. Cloud-based intrusion detection systems add latency that is unsuitable for real-time control, while CPU-bound firewalls and generic SDN controllers lack MQTT awareness to enforce session validation, topic-based authorization, and behavioral anomaly detection. We propose a P4-based data-plane enforcement scheme for protocol-aware MQTT security and anomaly detection at the network edge. The design combines parser-safe MQTT header extraction with session-order validation, byte-level topic-prefix authorization with per-client rate limiting and soft-cap enforcement, and lightweight anomaly detection based on KeepAlive and Remaining Length screening with clone-to-CPU diagnostics. The scheme leverages stateful primitives in BMv2 (registers, meters, direct counters) to enable runtime policy adaptation with minimal per-packet latency. Experiments on a Mininet/BMv2 testbed demonstrate high policy enforcement accuracy (99.8%, within 95% CI), strong anomaly detection sensitivity (98\\% true-positive rate), and high delivery \u003e99.9% for 100--5~kpps; 99.8% at 10~kpps; 99.6\\% at 16~kpps) with sub-millisecond per-packet latency. These results show that protocol-aware MQTT filtering can be efficiently realized in the programmable data plane, providing a practical foundation for edge IoT security. Future work will validate the design on production P4 hardware and integrate machine learning--based threshold adaptation.",
"arxiv_id": "2601.07536",
"authors": [
"Bui Ngoc Thanh Binh",
"Pham Hoai Luan",
"Le Vu Trung Duong",
"Vu Tuan Hai",
"Yasuhiko Nakashima"
],
"categories": [
"cs.CR",
"cs.NI"
],
"license": "http://creativecommons.org/licenses/by/4.0/",
"title": "A Protocol-Aware P4 Pipeline for MQTT Security and Anomaly Mitigation in Edge IoT Systems",
"url": "https://arxiv.org/abs/2601.07536",
"version": "v1"
},
"schema_id": "dorsal/arxiv",
"source": {
"execution_id": "d2151c49-cb41-43d2-8b18-0c44d6b3c5c7",
"id": "arXiv Dataset",
"type": "Model",
"variant": "snapshot-2026-01-17",
"version": "0.1.0"
},
"user_id": 1000002
}