NanoFirewall
Prevention that runs where security agents cannot
NanoFirewall is a self-learning security control built to run directly on IoT devices, embedded systems, routers, and ARM-class field equipment — the infrastructure conventional agents are simply too large to protect.
It needs no rules, no signatures, and no manual tuning. It continuously shifts the protected device’s behavioural attack surface, denying attackers a reliable, repeatable foothold, while its adaptive camouflage denies reconnaissance tooling a stable picture of the asset it is scanning. Those are two of the five capability areas that define preemptive cybersecurity: moving target defence and advanced obfuscation.
Engineered to fit
| Characteristic | Specification |
|---|---|
| Total footprint | Approximately 100 MB |
| ML model size | Under 2 MB |
| Model update time | Under 5 seconds, incremental |
| Rules and signatures | None required — self-learning |
| Administration | Zero-touch after deployment |
| Target hardware | IoT devices, embedded systems, routers, ARM-class field equipment |
NanoFirewall vs. a conventional firewall or IPS
| Capability | NanoFirewall | Conventional firewall / IPS |
|---|---|---|
| Rules and signatures | None required, self-learning | Manually authored and maintained |
| Model or rule update time | Under 5 seconds, incremental | Scheduled updates, often hours to days |
| Embedded and IoT deployment | Sub-2 MB model, runs on ARM-class devices | Typically requires dedicated appliance hardware |
| Administration | Zero-touch after deployment | Ongoing manual tuning and rule review |
| Adversarial ML resistance | Dual independent AI engines with mutual cross-verification | Not applicable — rule-based logic only |
Two AI engines, deliberately
NanoFirewall’s detection core runs two independent machine learning modules in parallel. This is a specific defence against adversarial ML attacks, which are increasingly viable against security products that depend on a single model.
Module 1 — Incremental real-time learner
Updates its behavioural model within five seconds of detecting a new threat class, so protection tracks the device’s live environment rather than a release schedule.
Module 2 — Periodic deep retraining engine
Performs independent full model retraining several times a week, providing stability and resistance to drift over the long term.
Mutual cross-verification
An attack that evades Module 1 must still pass Module 2’s independent evaluation. Because the two models are trained differently, manipulating both at once is computationally impractical in operational conditions.
Adaptive camouflage
Alongside prevention, NanoFirewall continuously varies how the protected asset presents itself, degrading the quality of any reconnaissance an attacker manages to perform.
Research foundation
The incremental-learning approach underlying the real-time module is peer-reviewed and published in Applied Intelligence (Springer), DOI 10.1007/s10489-021-03077-9 — “Web attack detection based on traps”. That publication establishes the algorithmic foundation for continuous, on-device model adaptation.
The engineering AST uses to compress that model below 2 MB, small enough to embed within routers, IoT gateways, and web server plugins, is not disclosed in the paper. It is maintained as AST’s confidential intellectual property rather than published or patented in a form requiring public disclosure.
Four deployment models
| Model | Application |
|---|---|
| Embedded in device firmware | Integrated by hardware manufacturers directly into router, gateway, or controller firmware |
| Router or edge gateway module | Deployed as a native module within routers and edge gateways, with no firmware change required |
| Standalone agent | Deployed as a standalone process on any embedded Linux device, for broad compatibility |
| Docker container | Deployed on any gateway or industrial PC supporting container execution, for fast rollout |
Manufacturers and telcos integrating NanoFirewall into their own hardware should start at OEM and embedded deployment, which covers the integration paths in detail.
Where NanoFirewall sits in the platform
NanoFirewall is the Deny pillar at the network and device edge. It consumes Indicators of Future Attacks generated by CATIS from live attacker behaviour on BaitHive Decoy deception infrastructure, and enforces prevention autonomously — without waiting for a human to approve a rule. Its prevention events flow back into ASPEN for correlation and investigation.
NanoFirewall also has a dedicated product site at nanofirewall.com, with release notes and technical documentation.