Software-Defined Networks and 5GSecurity and Verification in ComputingIoT and Edge/Fog Computing
DOI: 10.4018/ijcac.398931

tlooto Summary

A three-layered security framework that integrates lightweight SDN controllers with runtime attestation for trusted execution in resource-constrained fog nodes, and uses an unsupervised deep learning autoencoder to detect anomalies and identify zero-day threats.

Abstract

The deployment of software-defined networking (SDN) in distributed Kubernetes environments across fog and cloud systems introduces complex security challenges. Traditional approaches often fail to ensure secure, resource-efficient control-plane operations and verifiable node coordination at scale. This study proposes a three-layered security framework: (a) flexible control plan (FCP) integrates lightweight SDN controllers with runtime attestation for trusted execution in resource-constrained fog nodes; (b) secure software-defined offloading (SSDO) enforces encrypted, policy-driven inter-node communication and signature verification to prevent unauthorized coordination; and (c) sentinel-adaptive intrusion detection (SAID) uses an unsupervised deep learning autoencoder to detect anomalies and identify zero-day threats. Combined, these layers offer scalable, adaptive, and real-time security for distributed SDN-Kubernetes environments.

Citation format

KHAN, A.; NANDA, Priyadarsi. End-to-end security for SDN controllers in distributed k8s environments for fog and cloud. International Journal of Cloud Applications and Computing, 2026, 16(1): 1–30.