IoT network protection for routers and gateways using AI anomaly detection

An open ecosystem that lets routers protect whole networks against IoT attacks.

The Challenge

Home and small-business networks are full of insecure IoT devices that cannot defend themselves; the router is the one place the whole network can be protected, but routers lack the shared knowledge to recognise devices, know their legitimate behaviour, and act. Endpoint-security initiatives don’t solve this — the gateway needs an open, industry-wide data ecosystem (ManySecured: what is it?).

The Solution

NQM led the CyberStone consortium (with the University of Oxford Cyber Security Centre, Cisco and TechWorks) building ManySecured: a secure router/IoT-gateway platform using AI-driven anomaly detection and cyber-resilient networking, built on open-source software. Central to it are the D3 (Distributed Device Descriptors) specifications — a signed, shareable language for device types, behaviours and claims that lets distributed parties share fine-grained device security data in a controlled fashion, with the router as the intelligent agent consuming events, making inferences and enforcing constraints (D3 specs).

Outcomes

Outputs include the open D3 specification suite and D3DB database, the ManySecured working group under TechWorks/IoT Security Foundation, a series of published whitepapers, and contribution to NIST SP 1800-36 on trusted IoT network-layer onboarding — with the successor SNbD project carrying the router work onto CHERI/Morello hardware.

In Detail

IoT full lifecycle management platform to detect and protect security threats at scale.

ManySecured is an open ecosystem that helps routers and gateways better protect the network against IoT attacks, complementing initiatives that enhance IoT endpoint security. Many insecure IoT devices are already in the market, and they are not going away any time soon — and even the best IoT endpoint security can and will be compromised. Enhancing the role the gateway plays in detecting and protecting against IoT attacks is, and always will be, a valuable addition to a comprehensive security strategy. Developer documentation is published at manysecured.net.

Core benefits

  • Dynamic Risk — multi-factor, 360-degree risk assessment using type and instance data.
  • Lifecycle Management — full integration with procurement and servicing on a fully distributed basis.
  • Cyber Data Sources — integrates with well-known and novel cyber data sources using standard interfaces (D3).
  • Cognitive Security — reason under uncertainty; practical Zero Trust; controllable false positives.
  • Collaborative — share data between instances and organisations to better detect and respond.
  • Integration — API-first design using distributed security makes it easy to integrate with legacy and partner systems.

Cyber data sources API-first integration

Distributed Device Descriptors (D3)

D3 — Distributed Device Descriptors

The D3 workstream addresses two problems: how a community makes statements about device types reliably and securely, and how the community can reason about devices reliably — whether that reasoning is human-centric or machine-centric. D3 provides structured data of known provenance, which can be used to assert claims about how IoT devices should behave.

Destination-based anomaly detection

Destination-based anomaly detection model

The destination-based anomaly detection model allows detection and characterisation of deviations in behaviour that might indicate emerging security threats. The broad spectrum of variability between device types — from laptops to smart bulbs — and between instances of specific types makes this difficult in practice and results in large numbers of false alarms. The ManySecured models therefore provide strong false-alarm-rate control, require no tuning, and can be deployed without an explicit training period — turning a device’s observed destination requests on the network into an enforceable policy.

Lifecycle management and trusted onboarding

Trusted network-layer onboarding

Network-layer onboarding for an IoT device means provisioning network credentials to that device. The current lack of trusted IoT device onboarding processes leaves many networks vulnerable to having unauthorised devices connect to them, and leaves devices vulnerable to being taken over by networks that are not authorised to onboard them. To be strongly authenticated, the device asserts a specific identity that is cryptographically bound to the device; where a device asserts only a device type or a manufacturer, it cannot be fully authenticated, though its device type may still be verified.

IoT network protection for routers and gateways using AI anomaly detection featured image

Features

Secure home/SME router and IoT gateway platform (open source) icon
Secure home/SME router and IoT gateway platform (open source)

Secure home/SME router and IoT gateway platform (open source).

D3 (Distributed Device Descriptors) icon
D3 (Distributed Device Descriptors)

Open language for device types, recognition, behaviours and claims.

AI-driven anomaly detection icon
AI-driven anomaly detection

Inference of device behaviour from network traffic.

Least-privilege enforcement at icon
Least-privilege enforcement at

Least-privilege enforcement at the router (static behaviour constraints from authoritative sources).

Industry-wide open database icon
Industry-wide open database

Industry-wide open database of IoT device network characteristics (D3DB on GitHub).

Unique: security intelligence shared as signed, distributed data icon
Unique: security intelligence shared as signed, distributed data

The router becomes a collaborative defence point, not an isolated appliance.

Benefits

Contribution to NIST SP 1800-36 icon
Contribution to NIST SP 1800-36

Contribution to NIST SP 1800-36 ("Trusted IoT Device Network-Layer Onboarding and Lifecycle Management"); NQM implementations presented at the NCCoE IoT Open House; interest from NIST and US CISA.

Sponsored by DSIT/NCSC icon
Sponsored by DSIT/NCSC

Sponsored by DSIT/NCSC; improved resilience of customer and national networks via router/gateway deployment.

Open D3 specifications icon
Open D3 specifications

Open D3 specifications, whitepapers and D3DB published; ManySecured working group established under TechWorks (IoTSF involvement, BT in the wider programme).

Follow-on icon
Follow-on

SNbD (Secure Network by Design) combining ManySecured router elements with CHERI/Morello.

Volt features used


Working with



News


Related Sectors

Volt4 — the verifiable trust fabric. Secure · Sovereign · AI-native.

100% UK founder-owned. No foreign parent, no foreign capital, no US platform dependency — and cryptographically provable.

Copyright 2026 NquiringMinds. All Rights Reserved