Our team built automation to detect repeatedly suspicious source addresses, safely add them to firewall blocking controls, and provide a governed web interface for authorized security teams.
Project challenge
Reduce manual response time for recurring suspicious traffic while preventing duplicate or unsafe blocking and avoiding the need to grant broad firewall administration access.
Delivery
- The team created log-driven automation to identify repeated suspicious addresses over a rolling time window.
- The team added safeguards for protected infrastructure addresses and duplicate checks against existing firewall objects.
- The team built a controlled web interface for authorized add/remove operations with authentication and full audit logging.
- The team separated day-to-day security response from direct firewall CLI administration.
Outcome
Routine threat-response actions were automated while preserving approval, auditability, and safeguards around critical infrastructure.
Technology and methods
Client-confidential case study. Client-identifying information, addressing, credentials, security-sensitive configuration, and other protected details are intentionally omitted.