PROTECT

CYTUR-SD

Ship network Defender
Maritime-Specific Intrusion Detection Solution

A maritime-specific Intrusion Detection System (IDS) that monitors all onboard networks and equipment 24/7, instantly alerting when hacking attempts or abnormal activities are detected. Its key strength is complete understanding of maritime-exclusive communication protocols such as NMEA and Modbus.

Why You Need It

Why Maritime-Specific Intrusion Detection Is Essential

🌐
Expanding Attack Surface from Digital Transformation
Vessel digitalization and accelerating shore-to-ship connectivity have exposed previously isolated operational technology (OT) systems to external threats. The attack surface exploitable by hackers has expanded to critical levels, making cyber attacks targeting vessels a tangible reality.
🛡️
Maritime-Specific Threats Beyond Conventional Security
Satellite communication latency causes conventional security solutions to malfunction on vessels. Maritime-specific threats such as GPS spoofing/jamming and marine sensor data falsification directly endanger navigation safety as critical vulnerabilities unique to the maritime environment.
No Solutions That Understand the 'Language of Ships'
Conventional shore-based IDS cannot interpret maritime protocols like NMEA and AIS, missing critical threats or generating false alarms. Only a maritime-specialized solution that deeply understands vessel control networks and operates uninterrupted in satellite environments can ensure smart ship cyber survivability.
Product Overview

The Vessel's Dedicated Cyber Guardian

A maritime-specific Intrusion Detection System (IDS) that monitors all critical onboard networks and equipment around the clock, instantly alerting upon detection of hacking attempts or abnormal activity.

📡
Real-Time Vessel Network Monitoring
Cyber incident detection — Continuously monitors vessel networks and equipment to rapidly capture anomalies such as unauthorized access or abnormal traffic.

Immediate alerts & response — Sends alarms to operators upon threat detection and integrates with CYTUR-TA to effectively execute incident response processes required by international regulations.
📋
System Event & Communication Monitoring (UR E27)
Global security standard compliance — Analyzes internal user behavior and system communication events in accordance with UR E27 requirements based on IEC 62443.

Real-time security status — Monitors individual security events at the system level in real time to maintain optimal vessel security health at all times.
🔒
Security Audit Log Generation for Objective Verification
Automated evidence recording — All detected security events are logged in detail according to international regulatory requirements, maintained in a state ready for post-incident verification.

Incident recovery support — Generated logs serve as decisive evidence for analyzing causes and establishing response and recovery plans in future cyber incidents.
Key Benefits

The Value CYTUR-SD Delivers

Operational Stability
Prevent Operational Shutdowns with Real-Time Detection
Instantly identifies unauthorized access or abnormal traffic on vessel networks, proactively preventing vessel shutdowns caused by cyber incidents.
Compliance
International Security Standard Compliance
Automates system event monitoring and audit log generation required by UR E26 and E27, supporting class certification maintenance and post-incident recovery planning.
Precision Defense
Low False Positive Rate Based on Maritime Data
Analyzes actual vessel communication data rather than generic shore-based data, providing a precision defense system that reduces false alarms and identifies only genuine threats.
Core Features

Core Capabilities

01
Maritime Protocol-Based Anomaly Detection
Ship Language Analysis
Performs real-time deep analysis of maritime-exclusive protocols including Modbus (control), NMEA (navigation), and AIS (positioning) beyond standard IT traffic. Instantly captures vessel-specific threats such as unauthorized equipment commands or GPS spoofing that conventional security equipment easily misses.
02
Latest Threat Intelligence Integration
Real-Time Threat Map Updates
Integrates in real time with CYTUR-TI™ (Maritime Threat Intelligence) containing the latest global CVE data and malicious IP blacklists. Rapidly applies detection rules to block both known attacks and newly emerging sophisticated hacking attempts.
03
Raw Packet-Based Precision Monitoring
Incident Analysis Evidence
Goes beyond simple alarms by providing raw packet data and payload information at the time of threat events. Presents objective evidence of "who attacked, when, and with what data" for root cause analysis and class submission documentation.
04
Sub-Second Ultra-Fast Real-Time Detection
Golden Time Defense
Equipped with a high-performance processing engine that maintains detection latency under one second for incident prevention. Triggers immediate alarms upon attack detection, enabling operators to take defensive action before threats spread to other critical systems.
05
High-Performance Data Processing & Resource Optimization
Stable System Operations
Reliably processes massive onboard network traffic (approx. 11.5GB+ daily) while monitoring system resource usage in real time. Maintains 365-day uninterrupted security surveillance without any side effects of slowing down or halting navigation equipment.
06
Asset-Based Customized Detection Rules
Intelligent Integration
Integrates with CYTUR-MG to automatically apply customized security rules tailored to each vessel's equipment priorities and characteristics. Performs detection optimized for current operational status and asset configuration, reducing false positives and focusing on critical threats.
Why CYTUR-SD

Key Differentiators

01
Maritime-Optimized Architecture (Edge Local AI)
Independent security operation — Applies an edge-local approach that runs independently onboard without external cloud connection, ensuring uninterrupted security even when satellite communications are unstable.

Ultra-low latency real-time detection — Through a distributed architecture that eliminates data transmission delays, instantly detects threats in under one second, providing high performance for golden-time incident response.
02
Precision Analysis That Understands 'Ship Language'
Deep protocol analysis — Fully analyzes maritime-exclusive communication standards like NMEA, AIS, and Modbus that conventional security equipment cannot interpret, capturing sophisticated attacks targeting vessel control networks.

Low false positives & precision defense — Uses algorithms trained on actual vessel operational datasets rather than generic shore-based data, reducing unnecessary alarms in maritime environments and accurately identifying only real threats.
03
International Standard Compliance (Compliance Hub)
IACS UR E26/E27 compliance — Unlike competitors that only partially support generic security standards, designed to fully comply with the latest international maritime security requirements, completely supporting class certification.

Automated security logs & history — Automates generation of system events and audit logs essential for certification audits, dramatically reducing the administrative burden on ship owners and shipyards.
Comparison

Competitive Comparison

CategoryCYTUR-SDLegacy IDSOther Products
Detection ArchitectureEdge Local AI (Onboard)Central server-basedGeneric UTM/firewall with limited detection
Detection ScopeOT+IT convergence, maritime protocols, behavioral/policy/logic detectionIT traffic (server/cloud)General IT network traffic only
Response MethodAI autonomous responseManual responseSimple rule-based blocking / post-incident
Communication SupportMaritime satellite & ship comm (ICS, AIS, NMEA, CAN, RS-422)Shore-based design, no maritime supportUnsupported (limited ICS protocols, disabled during comm loss)
DatasetProprietary maritime threat datasetShore-based datasetsGeneric IT/OT signatures (high maritime false positive risk)
Maritime StandardsIMO MSC-FAL.1/Circ.3, IEC 61162-450/460 대응No maritime standard supportPartial/limited generic industrial standards (IEC 62443)
CYTUR-SD
Detection Architecture — Edge Local AI (Onboard)
Detection Scope — OT+IT 융합, 선박 특화 프로토콜
Response Method — AI autonomous response
Communication — Full maritime satellite & ship comm
Dataset — Proprietary maritime threat dataset
Standards — IMO MSC-FAL.1/Circ.3, IEC 61162
Legacy IDS
Detection Architecture — Central server-based
Detection Scope — IT traffic (server/cloud)
Response Method — Manual response
Communication — Shore-based, no maritime support
Dataset — Shore-based datasets
Standards — No maritime standard support
Other Products
Detection Architecture — 범용 UTM/방화벽 기반
Detection Scope — General IT network traffic only
Response Method — 단순 룰 기반 차단 / 사후 대응
Communication — Limited ICS, disabled on comm loss
Dataset — 육상 범용 시그니처 (해양 오탐 높음)
Standards — Partial generic industrial standards
Dashboard

Integrated Dashboard

A comprehensive dashboard providing at-a-glance views of attack status, detection logs, and event summaries. Directly configure signature policies and graphically monitor network traffic, signature hits, and protocol detection counts.

CYTUR-SD Dashboard 1 CYTUR-SD Dashboard 2 CYTUR-SD Dashboard 3
Specifications

Product Specifications

Spec / ModelCYTUR-SD 500
(N95)
CYTUR-SD 1000
(i3-14100)
CYTUR-SD 5000
(i7-14700)
CPUIntel® Processor N95
(4C/4T, Max 3.40GHz, 6M Cache)
Intel® Core™ i3-14100
(4C/8T, Max 4.7GHz, 12M Cache)
Intel® Core™ i7-14700
(8P+12E/28T, Max 5.4GHz, 24M Cache)
RAM1 x DDR4 16GB1 x DDR5 16GB4 x DDR5 16GB
Storage1 x 500GB SSD1 x 2.5" 1TB HDD2 x 3.5" SATA3 4TB HDD
Interface2 x 1G Copper6 x 1G Copper
(By-pass 2 pair)
2 x 1G Copper,
PCI-E x4 (Module expansion)
Power35W150W ATX Power Supply300W ATX Redundant Power
Rack Type1U1U2U
Weight3 kg6 kg12.8 kg
Dimensions
(H×W×D mm)
440×227×44440×427×44438×559×88
CYTUR-SD 500 (N95)
CPU — Intel® N95 (4C/4T, 3.40GHz)
RAM — 1 x DDR4 16GB
Storage — 1 x 500GB SSD
Interface — 2 x 1G Copper
Power — 35W | Rack — 1U | Weight — 3 kg
CYTUR-SD 1000 (i3-14100)
CPU — Intel® i3-14100 (4C/8T, 4.7GHz)
RAM — 1 x DDR5 16GB
Storage — 1 x 2.5" 1TB HDD
Interface — 6 x 1G Copper (By-pass 2 pair)
Power — 150W ATX | Rack — 1U | Weight — 6 kg
CYTUR-SD 5000 (i7-14700)
CPU — Intel® i7-14700 (8P+12E/28T, 5.4GHz)
RAM — 4 x DDR5 16GB
Storage — 2 x 3.5" SATA3 4TB HDD
Interface — 2 x 1G Copper, PCI-E x4
Power — 300W Redundant | Rack — 2U | Weight — 12.8 kg

The Vessel's Dedicated Cyber Guardian을 만나보세요

Want to learn more about CYTUR-SD? Request a consultation today.