GrammaTech proposes CyDir, a system for automatically detecting anomalous behavior in avionics and ISR systems. CyDir will automatically diagnose anomalous behaviors cause and immediately direct a response to maximize mission success by minimizing the effect of the anomalous behavior (and any malware which caused this behavior).CyDir is specifically designed to detect and mitigate malicious behavior, but can also provide responses to hardware malfunctions, misconfigurations, and other non-malicious faults.CyDir combines synchronous and asynchronous anomaly detection with a system reasoner and GrammaTechs efficient monitoring and instrumentation technology.If CyDir is certain of a fault, it can prevent the attempted action from occurring, preventing malicious actions from occurring.Where the cause of fault is initially uncertain, CyDir passes information to the system reasoner until it can determine the proper response to mitigate the threat and maximize the probability of mission success.When the system reasoner is uncertain, it can present all information relevant to a potential fault to knowledgeable operators along with a recommendation for action. CyDir will then learn the proper response by observing the operator, increasing its future response capabilities.Anomaly Detection,intrusion detection,Intrusion Prevention,fight-through-the-attack,Deep-Learning,insider attack,Malware