Evidence

Verifiable evidence, not marketing claims

Everything on this page can be checked independently. The patent is public record, the research is peer-reviewed and indexed, the interdiction dates are ours and are stated precisely, and the performance figures are the ones we hold ourselves to.

It is written to be forwarded — send it to your architects, your SOC lead, or your procurement team and let them verify it without talking to us first. The reasoning these figures support is set out in full on why preemptive cybersecurity.

Issued patent

Reference Detail
Patent number US 12,284,211 B2
Title Cyber clone of a computing entity
Granted 22 April 2025
Assignee Advanced Security Technologies Asia Pte Ltd
Covers The core cyber-clone deception methodology used by both BaitHive Decoy and TCP Mirage. The distinguishing claim is that the clone traps are engineered to be indistinguishable from genuine production assets to automated scanning tools and AI-driven reconnaissance — not only to legacy honeypot-detection heuristics.

Peer-reviewed research

Reference Detail
DOI 10.1007/s10489-021-03077-9
Title Web attack detection based on traps
Journal Applied Intelligence (Springer), volume 52, 2022
Relevance Establishes the peer-reviewed algorithmic foundation for trap-based detection and for the incremental, real-time learning approach underlying NanoFirewall’s detection core, including continuous on-device model adaptation.

On proprietary implementation. The publication establishes the algorithmic core. It does not disclose the engineering AST uses to compress that model below 2 MB so it runs embedded inside routers, IoT gateways, and web server plugins. That work is deliberately retained as confidential intellectual property rather than published or patented in a form requiring public disclosure.

Zero-day interdiction timeline

Each case below states when AST observed the activity, when it became public, and the interval between the two. Intervals are calculated from those dates and nothing else.

Case AST observed Public disclosure Interval
Microsoft SharePoint zero-day 5 June 2025 20 July 2025 45 days ahead
Oracle zero-day 6 October 2025 10 November 2025 35 days ahead
React Server Components
(CVE-2025-55182)
1 December 2025 3 December 2025 2 days ahead
Log4Shell 9 December 2021 9 December 2021 Same day — see note below

On the React Server Components case

CVE-2025-55182 was rated CVSS 10.0 — unauthenticated remote code execution in the React Server Components protocol — and it was patched on the same day it was publicly disclosed. Being ahead of disclosure therefore meant being ahead of the fix.

AST observed exploitation activity against its deception infrastructure on 1 December 2025, during the coordinated-disclosure embargo and two days before both the advisory and the npm patch. Public vulnerability trackers reported no in-the-wild exploitation as of 3 December.

This is the gap deception telemetry closes. Our decoys are attacked directly, so a technique becomes visible to us while it is in use — not when someone else reports it. Two days is a shorter margin than the SharePoint and Oracle cases, and we publish it as it is: on a CVSS 10.0 flaw affecting a large share of the modern web, two days of advance prevention is the difference between patching and responding.

Log4Shell is a different kind of case, and we label it as such. We detected exploitation activity on the day of public disclosure, at the very start of global mass exploitation — not ahead of it. We include it because day-zero telemetry on the largest internet-wide exploitation event in recent memory is meaningful evidence of sensor coverage. It is not evidence of pre-disclosure interdiction, and we do not present it as such. The SharePoint, Oracle, and React Server Components cases are.

Published performance specifications

Component Specification
ASPEN correlation latency Sub-10ms on live event streams
ASPEN sustained throughput 50,000 events per second without performance degradation
NanoFirewall total footprint Approximately 100 MB
NanoFirewall ML model size Under 2 MB, runs on ARM-class devices
NanoFirewall model update time Under 5 seconds, incremental
NanoFirewall administration Zero-touch after deployment; no rules or signatures required
BaitHive Decoy deployment Pre-built clone packs within 1 business day; custom clones within 3–7 business days
CATIS detection window Typically 1–2 days ahead of vulnerability confirmation; documented cases 30–45 days ahead

Field-validated embedded platforms

AST’s patented clone-trap technology has been embedded and field-validated directly inside third-party network hardware. This is OEM-verified deployment on real devices, not a laboratory demonstration — and it is where competing agents generally cannot run at all.

  • Teltonika industrial cellular routers
  • Cisco IR series industrial routers
  • MikroTik routers
  • Quectel SC200 4G IoT module

Standards, integration, and compliance alignment

Area Detail
Threat intelligence exchange STIX/TAXII-compatible export for existing SIEM platforms and information-sharing hubs
Programmatic access REST API feeds for real-time consumption by third-party monitoring and enforcement layers
Log ingestion syslog, CEF, JSON, and custom format connectors
Perimeter integration NGFW threat feed integration — CATIS-derived feeds delivered to incumbent firewalls
Deployment models On-premises, hybrid, SaaS, and fully air-gapped; multi-instance architecture for classified and multi-tenant environments
Compliance-aligned reporting Structured audit evidence suitable for frameworks such as ISO 27001, SOC 2, and the NIST Cybersecurity Framework, with sector-specific reporting such as NERC CIP for energy operators available on request

Read the last row precisely. It describes the reporting and audit evidence the platform produces, so that it maps onto these frameworks during your own audits. It is not a claim that AST holds certification against them. If you need certification status for a procurement questionnaire, ask us and we will answer it directly.

Verify it, then talk to us

The patent and the research are linked above and need no introduction from us. If your team wants the interdiction cases walked through in technical detail, or a specification confirmed against your own environment, get in touch.