NanoFirewall

Prevention that runs where security agents cannot

NanoFirewall is a self-learning security control built to run directly on IoT devices, embedded systems, routers, and ARM-class field equipment — the infrastructure conventional agents are simply too large to protect.

It needs no rules, no signatures, and no manual tuning. It continuously shifts the protected device’s behavioural attack surface, denying attackers a reliable, repeatable foothold, while its adaptive camouflage denies reconnaissance tooling a stable picture of the asset it is scanning. Those are two of the five capability areas that define preemptive cybersecurity: moving target defence and advanced obfuscation.

Engineered to fit

Characteristic Specification
Total footprint Approximately 100 MB
ML model size Under 2 MB
Model update time Under 5 seconds, incremental
Rules and signatures None required — self-learning
Administration Zero-touch after deployment
Target hardware IoT devices, embedded systems, routers, ARM-class field equipment

NanoFirewall vs. a conventional firewall or IPS

Capability NanoFirewall Conventional firewall / IPS
Rules and signatures None required, self-learning Manually authored and maintained
Model or rule update time Under 5 seconds, incremental Scheduled updates, often hours to days
Embedded and IoT deployment Sub-2 MB model, runs on ARM-class devices Typically requires dedicated appliance hardware
Administration Zero-touch after deployment Ongoing manual tuning and rule review
Adversarial ML resistance Dual independent AI engines with mutual cross-verification Not applicable — rule-based logic only

Two AI engines, deliberately

NanoFirewall’s detection core runs two independent machine learning modules in parallel. This is a specific defence against adversarial ML attacks, which are increasingly viable against security products that depend on a single model.

Module 1 — Incremental real-time learner

Updates its behavioural model within five seconds of detecting a new threat class, so protection tracks the device’s live environment rather than a release schedule.

Module 2 — Periodic deep retraining engine

Performs independent full model retraining several times a week, providing stability and resistance to drift over the long term.

Mutual cross-verification

An attack that evades Module 1 must still pass Module 2’s independent evaluation. Because the two models are trained differently, manipulating both at once is computationally impractical in operational conditions.

Adaptive camouflage

Alongside prevention, NanoFirewall continuously varies how the protected asset presents itself, degrading the quality of any reconnaissance an attacker manages to perform.

Research foundation

The incremental-learning approach underlying the real-time module is peer-reviewed and published in Applied Intelligence (Springer), DOI 10.1007/s10489-021-03077-9 — “Web attack detection based on traps”. That publication establishes the algorithmic foundation for continuous, on-device model adaptation.

The engineering AST uses to compress that model below 2 MB, small enough to embed within routers, IoT gateways, and web server plugins, is not disclosed in the paper. It is maintained as AST’s confidential intellectual property rather than published or patented in a form requiring public disclosure.

Four deployment models

Model Application
Embedded in device firmware Integrated by hardware manufacturers directly into router, gateway, or controller firmware
Router or edge gateway module Deployed as a native module within routers and edge gateways, with no firmware change required
Standalone agent Deployed as a standalone process on any embedded Linux device, for broad compatibility
Docker container Deployed on any gateway or industrial PC supporting container execution, for fast rollout

Manufacturers and telcos integrating NanoFirewall into their own hardware should start at OEM and embedded deployment, which covers the integration paths in detail.

Where NanoFirewall sits in the platform

NanoFirewall is the Deny pillar at the network and device edge. It consumes Indicators of Future Attacks generated by CATIS from live attacker behaviour on BaitHive Decoy deception infrastructure, and enforces prevention autonomously — without waiting for a human to approve a rule. Its prevention events flow back into ASPEN for correlation and investigation.

NanoFirewall also has a dedicated product site at nanofirewall.com, with release notes and technical documentation.