OEM and Embedded

Security that fits inside the device you already ship

Conventional security agents assume a server. They cannot run on a cellular router, an industrial gateway, or an ARM-class controller — which is precisely where a growing share of exposed infrastructure now lives.

AST’s prevention and deception technology runs in roughly 100 MB, with a machine learning model under 2 MB, requiring no rules, no signatures, and no administration. It has been embedded and field-validated inside third-party network hardware in production.

The engineering constraints it was built for

Characteristic Specification
Total footprint Approximately 100 MB
ML model size Under 2 MB
Target hardware IoT devices, embedded systems, routers, and ARM-class field equipment
Model update time Under 5 seconds, incremental
Rules and signatures None required — self-learning
Administration Zero-touch after deployment

Already validated in production hardware

This is not a reference design or a laboratory demonstration. AST’s patented clone-trap technology has been embedded and field-validated directly within these platforms:

Platform Class
Teltonika Industrial cellular routers
Cisco IR series Industrial routers
MikroTik Routers
Quectel SC200 4G IoT module

Four ways to integrate

Model Application
Embedded in device firmware Integrated by the manufacturer directly into router, gateway, or controller firmware — security becomes a product feature rather than a customer add-on
Router or edge gateway module Deployed as a native module within routers and edge gateways, with no firmware change required
Standalone agent Deployed as a standalone process on any embedded Linux device, for broad compatibility across a mixed fleet
Docker container Deployed on any gateway or industrial PC supporting container execution, for the fastest rollout

How it stays small without going stale

Dual AI engines

The detection core runs two independent machine learning modules in parallel. An incremental real-time learner updates its behavioural model within five seconds of detecting a new threat class, while a periodic deep retraining engine performs independent full retraining several times a week for stability and drift resistance.

The two cross-verify each other: an attack that evades the first must still pass the second’s independent evaluation. That makes adversarial manipulation — a growing risk for single-model security products — computationally impractical in operational conditions.

Moving target defence and obfuscation

Rather than matching known bad patterns, the control continuously shifts the protected device’s behavioural attack surface, denying attackers a reliable, repeatable foothold. Its adaptive camouflage simultaneously denies reconnaissance tooling a stable picture of the asset it is scanning.

For an OEM this matters commercially as well as technically: there is no signature distribution channel to operate, and no customer-side tuning burden to support.

The intellectual property behind it

The incremental-learning approach underlying the real-time module is peer-reviewed and published in Applied Intelligence (Springer), DOI 10.1007/s10489-021-03077-9. The clone-trap deception methodology is protected under US Patent 12,284,211 B2.

The specific engineering used to compress the model below 2 MB — small enough to embed within routers, IoT gateways, and web server plugins — is not disclosed in the paper. It is maintained as AST’s confidential intellectual property.

Who this is for

  • Hardware manufacturers differentiating a router, gateway, or controller line with security built into the firmware
  • Telecommunications operators securing large deployed fleets of customer-premises equipment without a truck roll
  • Industrial and IoT integrators who need protection on equipment that cannot host a conventional agent
  • National programmes embedding deception at firmware level across critical infrastructure

Integration is scoped per platform. Tell us what hardware you ship and we will tell you which of the four models fits, and what the integration actually involves.