Here is the Defend-O-Tron system architecture based on the protection flow. Most of the supporting components run as isolated Docker containers; the core defense components run directly in the host OS for performance and visibility into the data path.
