Skip to main content
A OneFirewall member (referred to here as Member X) runs a B2B SaaS platform serving clients globally, hosted across three cloud providers: Azure, DigitalOcean, and GCP, with two instances in Europe and one in the US.

Background

As Member X’s business grew, so did its exposure to attacks. 22% of incoming traffic was performing unauthorized operations, and an average of 35,000 attacks per day targeted web services and management consoles. The existing security setup had clear gaps: Cloudflare’s free plan handled CDN without advanced security features, management consoles were reachable directly without a VPN, and there was no capability to detect advanced threats. Member X needed a fix within 24 hours, without reworking its technology stack.

What happened

OneFirewall started by analyzing the attack traffic: high-frequency automated bot traffic, brute-force attempts against SSH, and application-layer attacks on web services. Threat sources were scored using OneFirewall’s Crime Score metric, and any source scoring above 120 was prioritized for blocking. Within 24 hours, OneFirewall deployed ACLs to block IPs scoring above 120, whitelisted remote access to approved IP ranges, adjusted traffic routing and CDN configuration to reduce the attack surface, and hardened web ingress points using the gathered threat intelligence.

Result

All traffic from IPs with a Crime Score above 120 was blocked, eliminating the 35,000 daily unauthorized requests. Latency dropped 28%, since malicious traffic was filtered at the edge before reaching the application. SSH brute-force attempts and the identified web application attacks were both stopped automatically, without manual intervention. Member X’s own traffic also fed back into the network: the integration added over 12,000 new threat feed entries per day, including 0.49% of threats not previously detected by other Alliance members.