A device for the autonomous detection of cyber threats, consisting of: a housing that encloses a multitude of interconnected hardware components; a
network interface unit configured to receive and send data packets from one or more communication networks; a
data acquisition unit that is operationally connected to the
network interface unit and configured to capture packet-
level data,
metadata, and
system event logs; a preprocessing processor configured to analyze captured data, decodecode protocols, reconstruct communication flows, and generate structured data representations; a
feature extraction processor that is operationally coupled with the preprocessing processor and is configured to calculate statistical, temporal and entropy-based features from the structured data representations; a storage unit consisting of
volatile memory for real-
time processing and non-
volatile memory for storing historical data and learned patterns; an
inference processor that is operationally coupled with the
feature extraction processor and the storage unit, wherein the
inference processor is configured to execute a variety of trained models to identify
anomalous behavior based on deviations from stored patterns; a classification unit that is operationally coupled with the
inference processor and configured to assign detected anomalies to one or more
threat categories based on calculated confidence values; a
response control unit configured to generate and transmit remedial actions, including blocking network traffic, isolating network segments, and terminating suspicious processes; and a control processor configured to coordinate the data flow between the
network interface unit, the
data acquisition unit, the preprocessing processor, the
feature extraction processor, the inference processor, the classification unit, the
response control unit, and the storage unit, with the device operating autonomously to detect and respond to cyber threats in real time.