OEM and Embedded
Security that fits inside the device you already ship
Conventional security agents assume a server. They cannot run on a cellular router, an industrial gateway, or an ARM-class controller — which is precisely where a growing share of exposed infrastructure now lives.
AST’s prevention and deception technology runs in roughly 100 MB, with a machine learning model under 2 MB, requiring no rules, no signatures, and no administration. It has been embedded and field-validated inside third-party network hardware in production.
The engineering constraints it was built for
| Characteristic | Specification |
|---|---|
| Total footprint | Approximately 100 MB |
| ML model size | Under 2 MB |
| Target hardware | IoT devices, embedded systems, routers, and ARM-class field equipment |
| Model update time | Under 5 seconds, incremental |
| Rules and signatures | None required — self-learning |
| Administration | Zero-touch after deployment |
Already validated in production hardware
This is not a reference design or a laboratory demonstration. AST’s patented clone-trap technology has been embedded and field-validated directly within these platforms:
| Platform | Class |
|---|---|
| Teltonika | Industrial cellular routers |
| Cisco IR series | Industrial routers |
| MikroTik | Routers |
| Quectel SC200 | 4G IoT module |
Four ways to integrate
| Model | Application |
|---|---|
| Embedded in device firmware | Integrated by the manufacturer directly into router, gateway, or controller firmware — security becomes a product feature rather than a customer add-on |
| Router or edge gateway module | Deployed as a native module within routers and edge gateways, with no firmware change required |
| Standalone agent | Deployed as a standalone process on any embedded Linux device, for broad compatibility across a mixed fleet |
| Docker container | Deployed on any gateway or industrial PC supporting container execution, for the fastest rollout |
How it stays small without going stale
Dual AI engines
The detection core runs two independent machine learning modules in parallel. An incremental real-time learner updates its behavioural model within five seconds of detecting a new threat class, while a periodic deep retraining engine performs independent full retraining several times a week for stability and drift resistance.
The two cross-verify each other: an attack that evades the first must still pass the second’s independent evaluation. That makes adversarial manipulation — a growing risk for single-model security products — computationally impractical in operational conditions.
Moving target defence and obfuscation
Rather than matching known bad patterns, the control continuously shifts the protected device’s behavioural attack surface, denying attackers a reliable, repeatable foothold. Its adaptive camouflage simultaneously denies reconnaissance tooling a stable picture of the asset it is scanning.
For an OEM this matters commercially as well as technically: there is no signature distribution channel to operate, and no customer-side tuning burden to support.
The intellectual property behind it
The incremental-learning approach underlying the real-time module is peer-reviewed and published in Applied Intelligence (Springer), DOI 10.1007/s10489-021-03077-9. The clone-trap deception methodology is protected under US Patent 12,284,211 B2.
The specific engineering used to compress the model below 2 MB — small enough to embed within routers, IoT gateways, and web server plugins — is not disclosed in the paper. It is maintained as AST’s confidential intellectual property.
Who this is for
- Hardware manufacturers differentiating a router, gateway, or controller line with security built into the firmware
- Telecommunications operators securing large deployed fleets of customer-premises equipment without a truck roll
- Industrial and IoT integrators who need protection on equipment that cannot host a conventional agent
- National programmes embedding deception at firmware level across critical infrastructure
Integration is scoped per platform. Tell us what hardware you ship and we will tell you which of the four models fits, and what the integration actually involves.