Skip to main content Skip to page footer

ASTRAOS - Security Out-of-the-Box

Aims & Objectives

The project develops a high-performance Network Detection and Response (NDR) solution for small and medium-sized enterprises (SMEs) as well as private households. Offered as a true out-of-the-box solution, it requires no specialized cybersecurity expertise. As a "Made in Europe" product, ASTRAOS strengthens Europe's digital sovereignty, enhances the competitiveness of SMEs, and contributes to the resilience of the European economy.

The project's objective is to make the level of protection traditionally provided by enterprise firewalls—previously associated with high costs and significant operational expertise—accessible and affordable for these target groups. This is achieved through the use of AI-based detection methods and zero-touch onboarding, enabling a low-maintenance, scalable, and user-friendly security solution.

Particular emphasis has been placed on sustainability during the development of the security appliance. This is reflected in its exceptionally energy-efficient operation.

 

Research Topics

Creating Network Intrusion Classifiers
Intrusion Detection Systems (IDSs) aim to detect attacks targeting networks and hosts. One promising approach is the use of machine learning (ML) classifiers to identify malicious activity. Network Detection and Response (NDR) solutions analyze incoming network traffic by monitoring critical network chokepoints, enabling them to protect downstream network segments.

To achieve this, NDR systems require highly capable classifiers that can reliably detect a wide range of attacks, including, but not limited to, injection attacks, flooding attacks, DNS-based attacks, covert channel communication, and Denial-of-Service (DoS) attacks.

Real-Time Monitoring of Large Volumes of Streaming Data
One of the primary challenges for NDR systems is providing real-time insights into observed network traffic. While many existing solutions simply log events to files, only a few provide integrated dashboards or other visualization mechanisms that allow network administrators to effectively monitor ongoing activity.

These insights must be delivered reliably and with minimal latency, as delayed or missing information can result in attacks going unnoticed. Furthermore, as the number of monitored network interfaces and chokepoints increases, so does the volume of generated data. Consequently, NDR solutions must be highly scalable and capable of processing large amounts of streaming data in real time.

Performance Optimization of Distributed Systems'
After network traffic has been captured at a chokepoint, NDR solutions must process the collected data as efficiently as possible. Since attack detection is time-critical, analysis has to be performed in real time to ensure that threats are identified before they can cause significant damage.

Therefore, modern NDR systems must be highly scalable and carefully optimized for performance, particularly when integrating computationally intensive components such as machine learning classifiers. Efficient distributed processing, resource management, and low-latency communication are essential to maintaining high detection accuracy while sustaining throughput in large-scale enterprise networks.

 

Funding

In 2026, we received funding via the EFRE program of the EU.

 

People from the EMCL

 

Partners

-

 

Contact

 

Links

 

Publications

  • Machmeier, S., Ludwig, M., Fuchs, M. and Heuveline, V., "heiDGAF: A Novel Open-Source CIDS Solution for DGA Detection", in 2025 15th SPRING graduate workshop, pp. 42, Nuremberg, Germany, 2025