astropema-ai — threat-defense-system v2.0
_ _ ____ _ ___
/ \ ___| |_ _ __ ___ | _ \ ___ _ __ ___ __ _ / \ |_ _|
/ _ \ / __| __| '__/ _ \| |_) / _ \ '_ ` _ \ / _` | / _ \ | |
/ ___ \\__ \ |_| | | (_) | __/ __/ | | | | | (_| |/ ___ \ | |
/_/ \_\___/\__|_| \___/|_| \___|_| |_| |_|\__,_/_/ \_\___|
[ HOST-LEVEL SECURITY ARCHITECTURE · LINUX · WAF · IDS · ML ]
Operating in production · ISO/IEC 27001 aligned
Custom Host-Level Security Architecture for Self-Managed Linux Infrastructure
AstroPema AI designs deterministic, reviewable defensive systems that operate
inside the application trust boundary — where operators require direct control,
auditable evidence, and verifiable enforcement without third-party telemetry dependencies.
Production Systems
Built and Operating in Production
The following capabilities are not aspirational — they represent systems currently
running in production across multiple domains including AstroPema.AI, AstroMap.AI,
PemaHosting.com, and OrNeiGong.org. Every component listed has been designed,
implemented, documented, and is actively maintained by AstroPema AI.
Linux Systems Administration & Server Infrastructure
Primary operating environment: Debian/Ubuntu Linux, administered at demonstrable production level across multiple servers and service domains.
- Full server provisioning, hardening, and lifecycle management on Debian/Ubuntu
- Multi-domain Apache and NGINX web server configuration, virtual host management, and performance tuning
- SSL/TLS certificate provisioning and automated renewal across all hosted domains
- DNS administration including zone management, propagation validation, and multi-domain record maintenance
- UFW firewall rule design, ipset hash-based blocking, and kernel-level network policy enforcement
- System monitoring, health checks, automated alerting, and on-call incident response — infrastructure built in-house
- Self-hosted Git version control (Gitea) for infrastructure-as-code and security system source management
Security Architecture & Intrusion Detection
Deterministic, reviewable defensive systems operating inside the application trust boundary — auditable evidence, verifiable enforcement, no external telemetry pipelines.
- Designed and implemented a production-grade Regex–CNN–GRU hybrid WAF integrating signature-based filtering with sequence-aware ML threat detection
- Built cross-service attack correlation system using PostgreSQL to detect coordinated threats across HTTP, SSH, and SMTP — revealing 73% of web attackers also probe mail and SSH endpoints
- Developed multi-layer defense architecture combining iptables/ipset, ModSecurity WAF, XDP BPF kernel-level drop, and ML detection — scaling to 1,500+ banned IPs with validated enforcement
- Implemented security data science pipeline with real-time log ingestion, normalization, and SQL analytics across Apache, SSH, and Postfix/Dovecot
- Applied statistical anomaly detection using window functions and time-series analysis on enforcement events, identifying coordinated botnet campaigns with measurable precision
- Actively porting core detection logic to Rust for sub-millisecond response times, supporting future commercially deployable WAF product
- Achieved $20K/year cost avoidance vs cloud SOC services by building ground-truth threat intelligence from operational data
AI Infrastructure & Machine Learning Deployment
Local GPU-accelerated AI inference environment — eliminating API dependency costs while maintaining full data sovereignty.
- RTX 5070 Ti GPU provisioned and optimized for parallel AI inference workloads
- Ollama inference server deployment serving production AI applications with sub-second response times
- Complete migration from OpenAI API dependency to self-hosted inference — eliminating recurring API costs while improving response latency
- AI inference pipeline integration with PHP web applications for real-time interpretation generation at AstroPema.AI and AstroMap.AI
- CNN-GRU neural network model training, validation, and production deployment for behavioral threat detection
Email Infrastructure & Messaging Security
- Postfix MTA configuration for outbound and inbound mail handling across multiple domains
- Dovecot IMAP/POP3 with mailbox management and quota enforcement
- DKIM signing, SPF record management, and DMARC policy enforcement — consistent inbox delivery and spoofing prevention
- Real-time SMTP abuse detection integrated into cross-service security correlation pipeline
Compliance, Governance & Reporting
- ISMS documentation framework developed in support of ISO 27001 certification for AstroPema AI LLC
- Structured HTML and PDF security reports generated directly from log-derived evidence, suitable for audit and executive review
- Statement of Applicability, risk register, and control mapping maintained as auditable operational records
- Change management via Git commit history providing reproducible, auditable infrastructure evolution records
Scripting, Automation & Full Stack
- Bash scripts for system automation, log rotation, health monitoring, backup execution, and security response pipelines
- Python scripting for ML pipeline management, data ingestion, log parsing, and statistical analysis
- Jupyter notebook-based Linux log forensics — applying data science methods to raw system logs
- PHP application development and deployment across multiple production domains
- PostgreSQL and MySQL database administration and backup/recovery procedures
Academic & Professional Credentials
MIT IDSS Machine Learning & Deep Learning | CMU Deep Learning — top 2% both cohorts.
BS Mathematics & Computer Science, University of Puerto Rico.
40+ years of practical experience spanning electronics, telecommunications, and enterprise Linux administration.
Operating production systems where downtime has real consequences — that discipline informs every engagement.