Router and network security for ISPs and router vendors using CHERI/Morello memory-safe hardware

Hardening the internet's front door: memory-safe, self-healing router security down to the silicon.

The Challenge

Routers account for over 75% of infected devices — an infected router is more dangerous than infected IoT devices, phones or PCs. The router is both the intermediary for almost all network traffic and the first line of defence from external attack; a compromised router can open the floodgates to new attacks, act as a jump-off point for secondary attacks, and mount man-in-the-middle attacks on entire portfolios of devices. A review of disclosed vulnerabilities shows an enormous list of current and historical memory-related vulnerabilities in routing components — and the most dangerous vulnerability is always the one not yet disclosed. For ISPs and router vendors, this “hyper-scaling” threat is a direct commercial and national-security problem.

The Solution

The Secure Networking by Design (SNbD) project — NquiringMinds with the University of Oxford and TechWorks (driven by its IoT Security Foundation community) — directly addressed this threat by combining NQM’s advances in cognitive router security from ManySecured with the memory protection and secure compartmentalisation features of the CHERI/Morello secure computing hardware platform (the ARM Morello programme targets the memory-safety weaknesses that account for ~70% of operating-system vulnerabilities). By leveraging AI concepts, the NQM components not only detect and prevent attacks but aim to self-heal against emerging security threats and vulnerabilities.

Outcomes

The project took a modular approach, making individual, upgradeable, open-source software modules available across common operating systems, so ISPs and router vendors can adopt protections incrementally. From the outset SNbD was designed as a self-sustaining, collaborative, open-source initiative accepting third-party contributions, with a long-lasting legacy. Funded under the Industrial Strategy Challenge Fund as part of the Digital Security by Design (DSbD) challenge, it served to enrich and expand DSbD ahead of the availability of commercial CHERI hardware, testing — in Prof. Andrew Martin’s words — the translation of Digital Security by Design “from research to practice at scale”.

In Detail

Memory-safe, self-healing cognitive router security — hardened down to the silicon.

Cognitive security

Secure Networking by Design (SNbD) hardens the cognitive router — the intelligent, self-defending gateway developed in the ManySecured programme — onto the CHERI/Morello memory-safe hardware platform, eliminating whole classes of memory vulnerability at the network’s most critical chokepoint. Two elements are central to the SNbD cognitive router:

Cognitive security

Reasoning under uncertainty; practical Zero Trust; controllable false positives. The router acts as an intelligent agent — consuming events, making inferences and enforcing constraints — rather than a static appliance, and by leveraging AI concepts it not only detects and prevents attacks but aims to self-heal against emerging threats and vulnerabilities.

Destination-based anomaly detection

The model detects and characterises deviations in device behaviour that might indicate emerging security threats. Because variability between device types (laptops to smart bulbs) and between instances of a type normally produces large numbers of false alarms, the models were developed with strong false-alarm-rate control, requiring no tuning and deployable without an explicit training period — turning a device’s observed destination requests into an enforceable network policy at the router.

Router and network security for ISPs and router vendors using CHERI/Morello memory-safe hardware featured image

Features

Hardened router and networking protections combining icon
Hardened router and networking protections combining

Hardened router and networking protections combining ManySecured secure-router elements with CHERI/Morello memory protection and secure compartmentalisation.

AI-leveraging "cognitive router" components icon
AI-leveraging "cognitive router" components

AI-leveraging "cognitive router" components that detect, prevent and aim to self-heal from attacks.

Modular, individually upgradeable open-source software modules icon
Modular, individually upgradeable open-source software modules

Modular, individually upgradeable open-source software modules available across common operating systems.

Open-source icon
Open-source

Open-source, self-sustaining project operation accepting third-party contributions.

Unique: first application of DSbD memory-safe hardware to the router icon
Unique: first application of DSbD memory-safe hardware to the router

The single most infected device class on the internet — rather than to endpoints.

Benefits

Substantially improved security offered by router technology icon
Substantially improved security offered by router technology

Substantially improved security offered by router technology, addressing the device class responsible for over 75% of infections (project evidence base: Broadcom/Symantec ISTR industry report).

Eliminates whole classes icon
Eliminates whole classes

Eliminates whole classes of memory-safety vulnerabilities (~70% of OS vulnerabilities per the ARM Morello programme) at the network's most critical chokepoint (projection grounded in CHERI/Morello research).

Enriched and expanded icon
Enriched and expanded

Enriched and expanded the UK's Digital Security by Design ecosystem ahead of commercial CHERI hardware availability, translating DSbD research toward practice at scale.

Open-source modular outputs available icon
Open-source modular outputs available

Open-source modular outputs available to ISPs and router vendors; designed for a self-sustaining collaborative legacy.

Continuation of the ManySecured programme icon
Continuation of the ManySecured programme

Continuation of the ManySecured programme, whose lineage includes contribution to NIST SP 1800-36 and the TechWorks ManySecured working group.

Volt features used




News


Related Sectors

Volt4 — the verifiable trust fabric. Secure · Sovereign · AI-native.

100% UK founder-owned. No foreign parent, no foreign capital, no US platform dependency — and cryptographically provable.

Copyright 2026 NquiringMinds. All Rights Reserved