35,000Daily attacks eliminated
28%Latency reduction
24hTime to full resolution
12,000+Daily feeds contributed back
Before OneFirewall
  • 22% of all traffic was malicious
  • 35,000 attacks per day
  • No SSH brute-force protection
After OneFirewall
  • 0 daily attacks reaching the perimeter
  • 28% latency reduction
  • All SSH attacks mitigated automatically
Live From the Platform

The alliance context behind the attack

Every indicator hitting Member X's perimeter arrived with context already attached — how many alliance members had reported it, how long it had been active, and when it last struck. That's the difference between a raw IP and actionable intelligence.

Relationship graph showing one malicious IP corroborated by 21 alliance members and flagged across multiple countries and sectors, from automotive to financial services
The Challenge

What the client was facing

A B2B SaaS platform operating globally across three cloud providers (Azure, DigitalOcean, and GCP), with infrastructure distributed across Europe (two instances) and the US. Despite their scale, they lacked effective perimeter security — resulting in runaway attack volume threatening service availability and performance.

  • 22% malicious traffic — nearly a quarter of all incoming requests were unauthorised operations: bots, scanners, and attack toolkits.
  • 35,000 attacks per day targeting web services and management consoles, overwhelming operations teams.
  • Cloudflare free plan only — no advanced DDoS protection, no intelligent threat blocking.
  • Direct, unprotected console access — SSH brute-force attempts reaching management interfaces.
  • 24-hour deadline — the board required a full resolution within one business day.
The OneFirewall Response

Three phases, one business day

PHASE 1

Threat Analysis

OneFirewall mapped all active attack patterns — automated bot traffic, SSH brute-force campaigns, and application-layer attacks — across all three cloud environments. Full threat picture established in hours.

PHASE 2

Intelligence Integration

Deployed OneFirewall Alliance threat intelligence using Crime Score-based blocking — all sources scoring above 120 were immediately blocked at the edge. Real-time cross-member intelligence covered attack IPs the platform had never seen before.

PHASE 3

Preventive Controls

Deployed ACLs to block high-risk IPs, whitelisted approved remote access ranges, optimised CDN routing, and hardened all web ingress points across Azure, DigitalOcean, and GCP simultaneously.

The full attack picture mapped in Phase 1: traffic from dozens of external sources, arriving across both Check Point and Fortinet devices, converging on a single Allow decision before reaching internal hosts.

Flow diagram showing multiple external IP addresses passing through Check Point and Fortinet gateways to an Allow decision, then out to internal destination hosts

Phase 2 in practice: one indicator, traced device by device. The same source IP is allowed on one port and denied on three others — the kind of split decision a Crime Score threshold makes automatically, at the edge.

Flow diagram showing a single source IP routed through firewall devices, splitting into an Allow decision on one port and a Deny decision across HTTPS, HTTP and FTP ports to multiple internal destinations
The Results

From 35,000 daily attacks to zero — in 24 hours

While contributing intelligence back to the alliance that now protects every other member.

35,000

Daily attacks eliminated through alliance IP blocking — no manual intervention required.

28%

Latency reduction — blocking malicious traffic at the edge freed bandwidth and processing for legitimate users.

0

SSH and web application attacks left unmitigated, with no manual firewall rule updates.

12,000+

Daily threat feeds contributed to the alliance — intelligence that now protects 290+ other members.

0.49%

Unique threats identified — indicators not previously seen by any other alliance member, expanding coverage for everyone.

≥120

Crime Score threshold used — a conservative starting point for a first deployment.

“Perimeter security is critical for blocking malicious traffic at network edges. Real-time intelligence enabled accurate threat blocking without impacting legitimate users.”

OneFirewall Alliance · Post-deployment assessment

Want to see what this looks like in your environment?

Run a free Proof of Value against your own traffic — no data leaves your perimeter.

Start a Proof of Value