35,000 attacks eliminated. 28% faster. 24 hours.
A global B2B SaaS platform operating across Azure, DigitalOcean, and GCP deployed OneFirewall Alliance and eliminated all unauthorised traffic — including 35,000 daily attacks — while reducing latency by 28%.
- 22% of all traffic was malicious
- 35,000 attacks per day
- No SSH brute-force protection
- 0 daily attacks reaching the perimeter
- 28% latency reduction
- All SSH attacks mitigated automatically
The alliance context behind the attack
Every indicator hitting Member X's perimeter arrived with context already attached — how many alliance members had reported it, how long it had been active, and when it last struck. That's the difference between a raw IP and actionable intelligence.
What the client was facing
A B2B SaaS platform operating globally across three cloud providers (Azure, DigitalOcean, and GCP), with infrastructure distributed across Europe (two instances) and the US. Despite their scale, they lacked effective perimeter security — resulting in runaway attack volume threatening service availability and performance.
- 22% malicious traffic — nearly a quarter of all incoming requests were unauthorised operations: bots, scanners, and attack toolkits.
- 35,000 attacks per day targeting web services and management consoles, overwhelming operations teams.
- Cloudflare free plan only — no advanced DDoS protection, no intelligent threat blocking.
- Direct, unprotected console access — SSH brute-force attempts reaching management interfaces.
- 24-hour deadline — the board required a full resolution within one business day.
Three phases, one business day
Threat Analysis
OneFirewall mapped all active attack patterns — automated bot traffic, SSH brute-force campaigns, and application-layer attacks — across all three cloud environments. Full threat picture established in hours.
Intelligence Integration
Deployed OneFirewall Alliance threat intelligence using Crime Score-based blocking — all sources scoring above 120 were immediately blocked at the edge. Real-time cross-member intelligence covered attack IPs the platform had never seen before.
Preventive Controls
Deployed ACLs to block high-risk IPs, whitelisted approved remote access ranges, optimised CDN routing, and hardened all web ingress points across Azure, DigitalOcean, and GCP simultaneously.
The full attack picture mapped in Phase 1: traffic from dozens of external sources, arriving across both Check Point and Fortinet devices, converging on a single Allow decision before reaching internal hosts.
Phase 2 in practice: one indicator, traced device by device. The same source IP is allowed on one port and denied on three others — the kind of split decision a Crime Score threshold makes automatically, at the edge.
From 35,000 daily attacks to zero — in 24 hours
While contributing intelligence back to the alliance that now protects every other member.
35,000
Daily attacks eliminated through alliance IP blocking — no manual intervention required.
28%
Latency reduction — blocking malicious traffic at the edge freed bandwidth and processing for legitimate users.
0
SSH and web application attacks left unmitigated, with no manual firewall rule updates.
12,000+
Daily threat feeds contributed to the alliance — intelligence that now protects 290+ other members.
0.49%
Unique threats identified — indicators not previously seen by any other alliance member, expanding coverage for everyone.
≥120
Crime Score threshold used — a conservative starting point for a first deployment.
“Perimeter security is critical for blocking malicious traffic at network edges. Real-time intelligence enabled accurate threat blocking without impacting legitimate users.”
