Abstract
This paper proposes an intelligent and adaptive security framework for internet of things (IoT) environments by integrating edge Honeypots, AI‐driven intrusion detection systems (IDS), and software‐defined networking (SDN). The system is designed to enhance real‐time threat detection, reduce false positives, and dynamically mitigate attacks. Edge Honeypots are deployed at the network perimeter to attract and analyze malicious traffic, which is then used to train AI‐based IDS models. The IDS employ a hybrid detection mechanism combining signature‐based and anomaly‐based techniques. SDN facilitates centralized traffic control and dynamic rule updates, enabling rapid responses to new attack vectors. The framework is implemented and evaluated in a simulated SDN‐IoT environment using Mininet, with several machine learning models benchmarked. The Decision Tree model achieves the highest detection accuracy (97%) for IoT threats. Experimental results demonstrate improved detection performance, reduced false positives, and enhanced adaptability through a continuous learning loop between the IDS and honeypots.