IoT network protection for routers and gateways using AI anomaly detection
An open ecosystem that lets routers protect whole networks against IoT attacks.
The Challenge
Home and small-business networks are full of insecure IoT devices that cannot defend themselves; the router is the one place the whole network can be protected, but routers lack the shared knowledge to recognise devices, know their legitimate behaviour, and act. Endpoint-security initiatives don’t solve this — the gateway needs an open, industry-wide data ecosystem (ManySecured: what is it?).
The Solution
NQM led the CyberStone consortium (with the University of Oxford Cyber Security Centre, Cisco and TechWorks) building ManySecured: a secure router/IoT-gateway platform using AI-driven anomaly detection and cyber-resilient networking, built on open-source software. Central to it are the D3 (Distributed Device Descriptors) specifications — a signed, shareable language for device types, behaviours and claims that lets distributed parties share fine-grained device security data in a controlled fashion, with the router as the intelligent agent consuming events, making inferences and enforcing constraints (D3 specs).
Outcomes
Outputs include the open D3 specification suite and D3DB database, the ManySecured working group under TechWorks/IoT Security Foundation, a series of published whitepapers, and contribution to NIST SP 1800-36 on trusted IoT network-layer onboarding — with the successor SNbD project carrying the router work onto CHERI/Morello hardware.
In Detail
IoT full lifecycle management platform to detect and protect security threats at scale.
ManySecured is an open ecosystem that helps routers and gateways better protect the network against IoT attacks, complementing initiatives that enhance IoT endpoint security. Many insecure IoT devices are already in the market, and they are not going away any time soon — and even the best IoT endpoint security can and will be compromised. Enhancing the role the gateway plays in detecting and protecting against IoT attacks is, and always will be, a valuable addition to a comprehensive security strategy. Developer documentation is published at manysecured.net.
Core benefits
- Dynamic Risk — multi-factor, 360-degree risk assessment using type and instance data.
- Lifecycle Management — full integration with procurement and servicing on a fully distributed basis.
- Cyber Data Sources — integrates with well-known and novel cyber data sources using standard interfaces (D3).
- Cognitive Security — reason under uncertainty; practical Zero Trust; controllable false positives.
- Collaborative — share data between instances and organisations to better detect and respond.
- Integration — API-first design using distributed security makes it easy to integrate with legacy and partner systems.

Distributed Device Descriptors (D3)
The D3 workstream addresses two problems: how a community makes statements about device types reliably and securely, and how the community can reason about devices reliably — whether that reasoning is human-centric or machine-centric. D3 provides structured data of known provenance, which can be used to assert claims about how IoT devices should behave.
Destination-based anomaly detection
The destination-based anomaly detection model allows detection and characterisation of deviations in behaviour that might indicate emerging security threats. The broad spectrum of variability between device types — from laptops to smart bulbs — and between instances of specific types makes this difficult in practice and results in large numbers of false alarms. The ManySecured models therefore provide strong false-alarm-rate control, require no tuning, and can be deployed without an explicit training period — turning a device’s observed destination requests on the network into an enforceable policy.
Lifecycle management and trusted onboarding

Network-layer onboarding for an IoT device means provisioning network credentials to that device. The current lack of trusted IoT device onboarding processes leaves many networks vulnerable to having unauthorised devices connect to them, and leaves devices vulnerable to being taken over by networks that are not authorised to onboard them. To be strongly authenticated, the device asserts a specific identity that is cryptographically bound to the device; where a device asserts only a device type or a manufacturer, it cannot be fully authenticated, though its device type may still be verified.

Features
Secure home/SME router and IoT gateway platform (open source).
Open language for device types, recognition, behaviours and claims.
Inference of device behaviour from network traffic.
Least-privilege enforcement at the router (static behaviour constraints from authoritative sources).
Industry-wide open database of IoT device network characteristics (D3DB on GitHub).
The router becomes a collaborative defence point, not an isolated appliance.
Benefits
Contribution to NIST SP 1800-36 ("Trusted IoT Device Network-Layer Onboarding and Lifecycle Management"); NQM implementations presented at the NCCoE IoT Open House; interest from NIST and US CISA.
Sponsored by DSIT/NCSC; improved resilience of customer and national networks via router/gateway deployment.
Open D3 specifications, whitepapers and D3DB published; ManySecured working group established under TechWorks (IoTSF involvement, BT in the wider programme).
SNbD (Secure Network by Design) combining ManySecured router elements with CHERI/Morello.
Volt features used
ML anomaly detection, pattern recognition and threat identification
distributed design on open identity standards
distributed policy definition & enforcement — NQM's core innovation
configurable and dynamic policy
wrap third-party / legacy systems that lack a mature API
open standards and open source, by commitment
advanced NIST compliant security
data-centric security
interoperable core
confidence scoring and continuous assurance — trust as a graded, computed measure

