> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Where Attacks Come From, Where They Land

> Correlating the geography of attack origins against the specific enforcement points absorbing the traffic

<img style={{ borderRadius: '0.5rem' }} src="https://mintcdn.com/onefirewall/mGgHxMsQTm71_QZa/images/case6.png?fit=max&auto=format&n=mGgHxMsQTm71_QZa&q=85&s=fab1f7f9a635356b543122c260aab71b" width="2690" height="684" data-path="images/case6.png" />

The map on the left shows attack volume by country of origin for the analysis window: **154** from the US, **28** from China, **16** from Brazil, with smaller counts distributed across dozens of other countries. The bar chart on the right shows blocked volume by the specific device that enforced it.

***

## Origin distribution

A long tail of single- and double-digit counts spread across nearly every region, alongside concentration in a small number of countries, is consistent with botnet and residential proxy infrastructure rather than a small number of dedicated attackers operating from fixed locations. Proxy chains route through whatever IP space is available at the time, which is why origin alone is an unreliable basis for blocking: filtering by country either misses distributed traffic or over-blocks legitimate users routed through the same regions. Blocking by validated indicator addresses the behavior independent of routing.

## Enforcement points

The bar chart names four separate devices: two Checkpoint deployments and two Fortigate deployments, each enforcing independently. Checkpoint-3472409 and Fortigate-infra1 each blocked roughly **3,400–3,600** events; Checkpoint-198365 close behind; Fortigate-infra2, covering a smaller segment of the environment, closer to **1,750**. All four are enforcing against the same underlying Crime Score feed.

## Mixed-vendor enforcement

Environments running more than one firewall vendor typically maintain separate blocklists and separate update cycles per platform, which creates a gap between what one device knows and what another enforces. In this data, both vendors applied the same intelligence at the same time, so an indicator confirmed at one edge does not need to be independently rediscovered at another.

***

Proof of Value engagements run this correlation across a client's existing mix of enforcement points. [Start a Proof of Value](https://onefirewall.com/proof-of-value).
