Skip to content
Conference

Cognitive Security Framework for APIs in Cloud-Native Microservices

Jul 2026 · International Conference Computing Methodologies and Communication · pp. 1206-1213 · 0 citations · 12 references

Abstract

APIs Become the Primary Communication, Orchestration and Business Operations Channel in Cloud-Native Microservices. While this architecture offers better scalability, flexibility and agility of deployment, it also increases the security risk by introducing the distributed trust boundary issue (east-west traffic), short-lived workloads and highly-permeable service-to-service communication. Traditional API security methods like perimeter filtering, signature-based detection and isolated identity checks have become insufficient for these highly dynamic environments. To overcome this challenge, and propose a Cognitive Security Framework for Cloud-Native Microservices APIs (CSF-API). The framework integrates zero-trust, workload identity, policy-as-code, service mesh attestation and enforcement, Kubernetes-native security controls and telemetry-driven intelligence into a singular model. It keeps an eye on API activity, analyzes request context through identity and runtime signals, and enforces appropriate responses (allow, audit, rate-limit, challenge, isolate or deny). The suggested architecture includes API gateways, external authorization with Envoy, Open Policy Agent and SPIFFE/SPIRE identities along with Istio authorization features, Kubernetes admission control/pod security features and observability by OpenTelemetry. Traditional reactive API protection is no longer viable due to stricter global cloud infrastructures and massive cloud-native microservice applications.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.