Software-Defined Networking (SDN) has revolutionized the current networking environment, separating the control plane and the data plane and allowing network control to be centralized, networks to be programmed, and networks to be much more visible and managed. Such functionality greatly enhances the versatility, scalability and use of network resources. However, when it comes to implementing and maintaining SDN infrastructures, the distributed parts of the network need to be carefully orchestrated and a particular skill set is required. Given the concerns about scalability, reliability and fault-tolerance (FT), SDN architectures have been continuously developing from centralized to distributed and hybrid architectures. However, security still stands out as one of the top issues limiting the adoption of SDN. SDN is also centralized in its control architecture and programmable which means that there is new attack surface open to adversaries, which can affect SDN network availability, integrity, and confidentiality. This paper presents a flexible and lightweight security layer in SDN world with its main goal to provide efficient management of security restrictions, real-time detection of intrusion, and proactive defense against zero-day attacks while ensuring the performance of SDN controller/forwarder devices. Apart from that, the key security issues in SDN are analysed in depth, then there is a detailed description of the proposed framework architecture, operational workflow and finally it shows the implementation and effectiveness of the proposed security layer using experimental evaluations.