A firewall that earns the right to act.
Observe. Authorise. Enforce.
IBSR watches your validator's traffic and judges it. Mesh weighs that judgment across the cohort and issues bounded authority. Guard enforces in the kernel. A probe seen by one validator becomes protection for the whole cohort in 312 milliseconds.
Three layers. One earned authority.
Baselines your validator's own traffic and shows every packet it would have dropped. Never enforces.
Weighs judgments across the cohort and issues scoped, revocable authority.
Drops hostile traffic in the kernel at XDP/eBPF speed, only on authority the operator has earned.
This is not a static ruleset. IBSR observes your validator's own traffic and judges it against a behavioural baseline. Mesh weighs those judgments across the cohort and issues authority scoped to an abuse class and revocable. Guard acts on that authority in the kernel. Nothing enforces until the evidence has earned it. If any layer goes down, traffic flows.
The authority model is the Earned Autonomy framework (DOI 10.5281/zenodo.18406828), applied at the network boundary.
IBSR.
Observes, learns, judges. The judgment layer for in-kernel defence.
Watches your traffic. Reports what it would have blocked.
IBSR runs on operator infrastructure at kernel-level resolution. It builds a behavioural baseline of your traffic, identifies anomalies against it, and reports to Mesh what it would have blocked and why. It never acts. Enforcement is Guard's job, on the authority Mesh has earned.
Behavioural baselines built on your actual network, not vendor lab conditions or sample datasets.
See exactly what would have been blocked before anything is. Earn the authority on evidence, then grant it.
Inspect the code. Run it air-gapped. Audit every decision. No black-box vendor inference on your traffic.
Drop the IBSR binary onto the validator host. No sidecar daemons, no kernel module beyond what Linux already gives you.
IBSR baselines your traffic in shadow mode. No enforcement, no risk. Nothing leaves the box without operator sign-off.
Read the counterfactual record. When the evidence supports action, grant Mesh authority for specific, bounded abuse classes.
Guard.
Kernel-speed action, only when the authority has been earned.
Acts on instructions from Mesh, at kernel speed.
Guard performs XDP/eBPF packet blocking in the kernel, on operator infrastructure. It acts only on instructions from Mesh, scoped to the abuse classes the operator has authorised. Microsecond decision-to-action. Fail-open by architecture: if Guard or Mesh go down, traffic flows.
XDP/eBPF in the kernel. Microseconds, not milliseconds. Decision-to-action faster than the attack can pivot.
Guard acts only on judgments Mesh has earned the right to make. Per abuse class, revocable, audited.
Run alongside your existing firewall, or replace it. Open source: inspect, fork, deploy. No vendor lock-in.
Drop Guard onto the validator host. XDP attaches to the NIC. No reboot, no kernel patching beyond what your distribution already supports.
Connect Guard to your Mesh tenant. Authority is granted per abuse class. Start narrow, expand as evidence supports.
Mesh issues enforcement instructions. Guard executes in the kernel. Every action is logged with full context, revocable at any time.
Security software does not cause downtime.
The attacker's first move against one operator is the last free move against any of them.
IBSR on one validator judges a probe as reconnaissance. Mesh weighs that judgment against the cohort and, where the operator has authorised it, issues Guard a scoped instruction. Guard drops the traffic at kernel speed, and the same protection reaches every node at once. Authority stays bounded and revocable, and the system is fail-open, so defence never becomes the cause of downtime.
