Security-Aware Orchestration for Service Placement and Migration in 6G-Enabled Cloud–Fog–Edge Systems
Keywords:
6G, Cloud–Fog–Edge computing, security-aware orchestration, service admission, Buehler bounds.Abstract
In 6G-enabled Cloud–Fog–Edge systems, services may need to run on different Edge, Fog, and Cloud nodes as system conditions change. A key challenge is to make these placement and migration decisions while also considering the security of the available nodes. To address this challenge, this paper proposes a service-aware admission framework that links node-security evidence with orchestration decisions. A frozen Random-Forest detector maps 65 packet-capture-derived features to a security-event evidence score, which is used as ranking evidence rather than interpreted as a calibrated attack probability. Service-specific frozen thresholds map this score to ADMIT, ABSTAIN, or MISSING states according to different selective-risk requirements. The resulting admission rules are evaluated prospectively on a fresh 540-episode physical campaign using simultaneous one-sided Buehler confidence limits. The corresponding selective-risk upper bounds are 0.0440, 0.1384, and 0.0941 for service risk targets of 0.05, 0.20, and 0.10, respectively. The frozen admission rules are then integrated with resource and latency constraints for service placement and migration in a paired 50-seed Cloud–Fog–Edge orchestration study. Relative to a resource-only baseline, the proposed policy reduces attack-active execution from 7.47% to 1.70%, while incurring higher latency and a small no-placement rate. Compared with a generic score-threshold baseline, attack exposure and latency are statistically indistinguishable, while no-placement is significantly lower. These results demonstrate that security evidence can be incorporated into service placement and migration while making the resulting security–availability–latency trade-off explicit.





