NARI Nano CD

Router-native cyber-defense cognition.

NARI Nano CD is the compact cyber-defense track for routers and local network devices: router-only evidence, traffic reasoning, Suricata-rule proposals, policy boundaries, and operator-approved action.

Router defense Local evidence Suricata proposals CPU-class inference Operator authority

Nano CD loop

observe router logs, flows, rules, ports, services, and local policy context

separate evidence, suspicion, anomaly, policy issue, and confidence

prepare Suricata-rule proposals, inspect notes, alerts, or escalation packets

preserve no-direct-mutation, audit, rollback, and operator approval

Small cyber-defense brains should be precise, local, and cautious.

Router scope

Nano CD is built for bounded router defense, not endpoint overclaiming.

The product direction keeps the cyber domain narrow and reviewable: local router evidence, local policy, explainable proposals, and clear limits around what the system knows and can do.

Evidence

Router-only reality

Reason from router-visible logs, flows, ports, DNS, rules, and device-local configuration.

Rules

Suricata proposals

Generate reviewable rule proposals with evidence, confidence, expected impact, and rollback notes.

Edge

Local deployment

Target compact local hardware where privacy, latency, and independence from cloud inference matter.

Authority

Operator-approved action

Keep mutation, blocking, and high-impact changes behind human review and explicit approval.

Defense posture

Nano CD should know the boundary of the router.

The product should avoid endpoint claims when the evidence is router-only.

Rule proposals can carry rationale, uncertainty, expected effect, and rollback guidance.

Local reasoning can preserve privacy and reduce dependence on remote inference.

Nexus CD can later coordinate many Nano CD brains across broader infrastructure.