L1-L2 Hardware-Anchored Network Defense. Demonstration Simulator PATENT FILED

Defense in depth across OSI layers. Layer 1-2 filter (in SFP) plus Layer 3-7 software (in router).
⚡ Continuous sim. Click any attack to start a loop. Click it again to stop. Hit Reset All to clear everything.

Attack Controls

50%
OSI Layer Legend
Layer 1-2
Physical + Data Link. Filter lives here (in SFP module). Sees timing.
Layer 3
Network routing. Both routers do this.
Layer 3-7
Software stack: NGFW, IPS, EDR, 802.1X. Lives in router.
⚠ Chaos Mode: multi-select

Network Topology

Internet (WAN) Path A: Baseline (SFP-A → Router-A) SFP-A AOI SFP28 copper L1 transceiver only no L1-L2 filter Router-A L3 routing + L3-7 software ▸ NGFW (Palo Alto) ▸ IPS / IDS ▸ EDR / Splunk ▸ MAC filter / 802.1X L3-7 SOFTWARE: [ACTIVE] kernel: ok Intranet A FILE-SVR file server PC-A1 PC-A2 WORKSTN admin endpoint DB-server Path B: Filter (SFP-B with L1-L2 → Router-B) SFP-B AOI SFP28 copper L1-L2 Filter independent timebase Router-B L3 routing + L3-7 software ▸ NGFW (Palo Alto) ▸ IPS / IDS ▸ EDR / Splunk ▸ MAC filter / 802.1X L3-7 SOFTWARE: [ACTIVE] kernel: ok Intranet B FILE-SVR file server PC-B1 PC-B2 WORKSTN admin endpoint DB-server idle idle Continuous simulation. Click attacks to start loops. Click again to stop.

Live Dashboard

Path A PROTECTED
SFP-A + Router-A (L3-7 software)
L1-L2 filter NOT INSTALLED
L3-7 software ACTIVE
Frames fwd 0
Attacks in 0
Status operational
Blast radius none
Path B FULL DEFENSE
SFP-B (L1-L2 filter) + Router-B (L3-7 software)
L1-L2 filter ACTIVE
L3-7 software ACTIVE
Frames fwd 0
Blocked 0
Status protected
Blast radius none

Event Log

[init] Ready. Click any attack button to start a loop. Click again to stop.

Future / Emerging Threat Landscape

Honest assessment. 16 emerging threats. Layer 3-7 software helps with some, Layer 1-2 filter helps with others. Combined: covers all.
Threat vector
L3-7 sw
L1-L2 filter
1. Covert timing channel exfiltration
NO
YES
2. MAC spoof via timing fingerprint
NO
YES
3. Slow-rate DoS evading rate limits
NO
YES
4. Month-long clock drift attack
NO
YES
5. 100-agent AI swarm (low individual rate)
PARTIAL
YES
6. AI-adversarial traffic (statistical mimicry)
NO
YES
7. Polymorphic / content-morphing attacks
PARTIAL
YES
8. Living-off-the-land (DNS, HTTPS abuse)
PARTIAL
YES
9. Coordinated low-rate distributed attack
NO
YES
10. Post-kernel-compromise persistence
NO
YES
11. Known malware / CVE signatures
YES
PARTIAL
12. SSL/TLS decryption and inspection
YES
N/A
13. Volumetric DDoS
YES
PARTIAL
14. Phishing / social engineering
YES
N/A
15. Insider threat (privileged user)
PARTIAL
YES
16. Supply-chain firmware substitution
PARTIAL
YES
Combined. Layer 3-7 software handles 7 of 16 well alone. Layer 1-2 filter handles 12 of 16 well. Combined: 16 of 16.

The Honest Story

Where each defense lives. Layer 1-2 filter lives in the SFP module. Layer 3-7 software lives in the router. Different layers, complementary protection.

Why L3-7 software cannot catch timing attacks

Any software running on the router host references the router OS clock. Microsecond resolution at best. Covert timing channels operate at sub-microsecond precision. The signal is below the software clock resolution.

Why L3-7 fails after router kernel compromise

Privileged malware on the router disables IPS, patches out EDR, manipulates the router clock. L3-7 software on that router is compromised. Reachable intranet devices enter the blast radius. The L1-L2 filter is in the SFP module, not on the router. Router kernel compromise cannot reach it.

Why AI-driven attacks make our case stronger

AI can mimic content. AI cannot change the physical timing fingerprint of the hardware producing it. The L1-L2 filter sees the residual.

Two product paths

Inline mode: filter in data path. +25 ns latency. Catches every attack frame.

Passive tap mode: filter watches in parallel. 0 ns added. For trading floors and HFT.

IP status

Patent filed. Non-provisional conversion in progress.