New: Telecom-native cyber defense for ISPs and operators  Explore OneMesh →
XSecurity One / OneMesh · Telecom-Native Network Detection & Response

Network detection built with telecom context.

Detect security behavior across flow, DNS, RADIUS, BNG, CGNAT, OLT/ONU, CPE and routing signals — then connect it to the incident that matters.

Pilot availability Pseudonymous context Rollback available
Network telemetry

Fourteen signal families. One pipeline.

OneMesh ingests the telemetry an operator network actually produces — not just what an enterprise NDR expects to see.

NetFlowflow
sFlowflow
IPFIXflow
DNSresolver
DHCPlease
Firewalllogs
Router / Switchsyslog
RADIUSaaa
BNGedge
CGNATtranslation
OLT / ONUaccess
CPE / ACSpremises
BGP / RPKIrouting
DDoScontext

Source availability depends on your release configuration — only approved sources are shown as active in the product.

Telecom detections

Detections written for operator networks.

Behavioral detections tuned to subscriber-scale baselines — where "normal" looks nothing like an office LAN.

Botnet behavior & beaconing

Periodicity and destination analysis across subscriber flows at CGNAT scale.

DNS tunnelling

Entropy, label length and resolver behavior against per-tenant baselines.

Scanning & brute force

Inbound and lateral scanning, credential-stuffing patterns against exposed services.

Exfiltration anomaly

Volume, timing and destination anomalies scored per asset and subscriber class.

CGNAT abuse correlation

Translate abuse reports and detections back through CGNAT to the right session.

CPE compromise & rogue ONU risk

Weak credentials, unexpected management traffic and access-layer anomalies.

RADIUS & authentication anomaly

Session storms, impossible geographies and privileged command anomalies.

Route leak / hijack & RPKI invalid

Routing events that put subscriber traffic somewhere it should never go.

DDoS anomaly context

Attack context correlated with the assets and subscribers actually affected.

Telecom security graph

From threat IP to incident — with privacy intact.

OneMesh models the path a threat actually takes through an operator network, and keeps subscriber identity behind an audited gate the whole way.

onemesh · telecom security graph Pseudonymous context
Threat185.x.x.24 EdgeBNG AAARADIUS session PremisesCPE AccessONU AggregationOLT SitePOP SubscriberSUB-9F42E1pseudonymous ref Identity gate · not exposed by default Correlated INCIDENT 0248 · Compromised CPE / botnet behavior
Guarded network action

Actions your network team will actually allow.

Every OneMesh action carries approval, expiry and rollback. Nothing touches the network without a signed, scoped, time-limited command — and a way back.

Approval required Auto-expiry Rollback available Signed action
Firewall block & MikroTik address list

Push scoped blocks to edge firewalls and router address lists with automatic expiry.

DNS sinkhole

Redirect known-malicious resolution for affected scopes while investigation continues.

RADIUS CoA & session suspension

Change-of-Authorization to re-scope or suspend a compromised session cleanly.

XIMS quarantine via OneBridge

Move a subscriber to a quarantine profile through the authorized XIMS bridge.

RTBH / FlowSpec request & restoration

Request blackhole or FlowSpec mitigation — and restore service on one screen when it clears.

onebridge · signed context bridge
XIMSsubscriber lifecycle · billingRADIUS ops · IPDR XSecurity Onedetection · incidentguarded response authorized security context → ← guarded action requests signed · audited
OneBridge for XIMS

A narrow signed bridge — not a giant data pipe.

XIMS keeps subscriber lifecycle, CRM, billing, provisioning and RADIUS operations. XSecurity One receives only authorized security context: pseudonymous references, active IP mappings, CPE/ONU identifiers and security-relevant events.

PURPOSE-BOUND. MINIMAL. AUDITED.

About OneBridge

Test your telecom use case.

Bring one real scenario — a compromised CPE, a beaconing subscriber, a routing anomaly — and see how OneMesh handles it end to end.