ABATIS

The Engine Of Deterministic eXecution Integrity


Every cyber-attack, regardless of its origin or objective, depends upon one fundamental requirement: Code must execute.


Whether the event involves ransomware, malicious software, a compromised software update, an Artificial Intelligence generated payload or the misuse of legitimate administrative tools, none of these actions can produce operational consequences until code is permitted to execute.


For more than three decades, the cybersecurity industry has concentrated on determining whether that code appears malicious. Behaviour is analysed. Telemetry is collected. Threat intelligence is consulted. Machine learning models assess risk. Security teams investigate alerts and respond to suspicious activity.


Abatis was engineered around a fundamentally different question: Should that code be allowed to execute at all?

Abatis ensures that software executes only when it has been authorised by organisational policy.

THE ENGINE POWERING DXI


Abatis is the engine of Deterministic eXecution Integrity (DXI).


Where DXI defines the architectural philosophy, Abatis brings that philosophy to life within the operating system. Operating at kernel level, it deterministically controls what code is permitted to execute before the operating system transfers control to that code.

 

Only software explicitly permitted by organisational policy is allowed to execute. Everything else is prevented from becoming operational before it can produce operational consequences. 


This distinction is fundamental. Traditional cybersecurity products attempt to recognise malicious behaviour. Abatis deterministically controls what code is permitted to execute.

FROM DETECTION TO CONTROL


Modern cybersecurity is built around probability. Security products continuously attempt to determine whether software appears malicious by analysing behaviour, correlating telemetry and comparing activity against ever expanding intelligence databases.


This approach has produced remarkable advances in threat detection, but it has also created increasing operational complexity. As software ecosystems have grown and Artificial Intelligence has accelerated the creation of new attack techniques, detection platforms have been required to process ever increasing volumes of information in an attempt to recognise behaviour they have never previously encountered.


Abatis does not participate in this race. It does not ask whether code appears malicious. It simply determines whether that code is permitted to execute.


This principle applies equally to ransomware, malicious scripts, compromised software updates, insider threats, malicious automation and previously unknown attack techniques. The origin of the code becomes secondary. What matters is whether it is permitted to execute under organisational policy.

Execution is either permitted or denied according to policy. It is not based on behavioural probability.

ENGINEERED FOR RELIABILITY 


Abatis has been purpose built for simplicity, reliability and deterministic operation.


The execution engine comprises fewer than 100 KB of kernel mode code. Every line exists for a reason. Its compact architecture reduces complexity, minimises attack surface and reflects more than two decades of continuous engineering rather than continual redesign.


Throughout that period the deterministic execution engine has accumulated no published Common Vulnerabilities and Exposures (CVEs) and, to our knowledge, no publicly reported breach attributable to a failure of the deterministic execution architecture itself.


Perhaps more remarkably, the original architects of Abatis continue to lead its engineering today, preserving the design philosophy that has defined the platform since its inception whilst continually refining it to meet the demands of modern computing. This is engineering discipline rather than engineering fashion.

ENGINEERED FOR EVERY OPERATING ENVIRONMENT


One of Abatis' defining characteristics is that it is not constrained by a particular operating system or deployment model.


The principles of Deterministic eXecution Integrity are independent of hardware platform. Wherever an operating system governs the execution of software, deterministic execution control can be established.


Over more than two decades, Abatis has been engineered across successive generations of Microsoft Windows, from Windows NT through to Windows 11 and the latest Windows Server platforms. The same deterministic principles have subsequently been engineered for Linux and Android, extending execution control beyond traditional enterprise computing into Operational Technology, Industrial Control Systems and the rapidly expanding Internet of Things.


This significantly expands the environments in which DXI can be applied. Servers, workstations and laptops represent only part of today's digital estate. CCTV systems, building management systems, HVAC controllers, medical devices, industrial automation, transportation infrastructure, telecommunications platforms, edge computing and smart city deployments all depend upon operating systems capable of executing software. 

 

Every operating environment evolves throughout its operational life. Applications are installed. Security patches are applied. Firmware is updated. Third party software is deployed. Configuration changes are introduced. Increasingly, Artificial Intelligence is being used to generate software automatically. Those same mechanisms can equally deliver malicious code, compromised software updates or unauthorised changes. 

 

Whether the environment is a workstation, a server, an industrial controller, a CCTV system or a medical device, the fundamental question remains the same. Should that code be allowed to execute? Abatis answers that question deterministically.

More than twenty years of continuous engineering.

<100 KB of code.

Original architects still lead development.

BUILT FOR OPERATIONAL RESILIENCE


Abatis was developed for environments where operational continuity is essential. Its deterministic architecture has protected defence organisations, Critical National Infrastructure, financial services, transportation, healthcare, government and industrial environments for more than two decades.


Because protection is enforced through deterministic execution control rather than continual behavioural analysis, organisations benefit from consistent protection, lower administrative overhead and significantly reduced operational complexity. Protection remains effective whether systems are connected to the Internet, isolated within air gapped environments or operating across highly restricted sovereign infrastructure.


The objective is not simply to prevent compromise. It is to preserve continuity.

SUPPORTING CYBER SOVEREIGNTY


Governments and operators of Critical National Infrastructure increasingly seek greater control over the technologies responsible for protecting their most important systems.


Many modern security platforms depend upon continual communication with external cloud services for analytics, threat intelligence and operational decision making. Whilst these approaches provide valuable capabilities, they also create dependencies upon infrastructure and jurisdictions beyond the organisation's direct control.


Abatis was engineered around a different philosophy. Execution policy is enforced locally, within the organisation's own environment. Protection does not depend upon the routine export of operational telemetry or continual consultation with external services. Organisations retain control over both policy enforcement and operational decision making, supporting broader objectives relating to resilience, governance and cyber sovereignty.

Engineered across Windows, Linux and Android.

No known publicly reported breach attributable to failure of the deterministic execution engine.

No published CVEs.

THE FOUNDATION OF TRUSTED EXECUTION


Abatis does not attempt to replace every component of a modern cybersecurity architecture. It establishes the deterministic execution engine upon which that architecture can operate with greater confidence. Working alongside Aegis, which deterministically controls access to information, and Praesidium, which provides operational visibility, governance and management, Abatis forms the execution engine at the heart of the Deterministic eXecution Integrity architecture.


For decades, cybersecurity has concentrated on recognising malicious behaviour. Abatis begins with a simpler engineering principle: If unauthorised code cannot execute, it cannot compromise the operating environment. That principle lies at the heart of Deterministic eXecution Integrity.

Want to know more?

Get in touch; let's talk about Custom Security Solutions.

Browse our whitepapers!

Discover proven strategies for Cyber Protection.