The sensor network
Exposed systems that receive real attack attempts and record address, method and time. On the order of sixty sensors across around fifty countries.
All blocking in WF SecurityCloud rests on one question: do we know that this address attacks? The answer does not come from guesswork but from attack attempts that have actually happened.
Automated attacks are cheap to repeat and expensive to vary. The same infrastructure is used against a great many targets before it is abandoned: the same servers, the same domains, the same tools.
That repetition is what WF SecurityCloud exploits. Once an address has been seen attacking one system, there is good reason not to let it into the next. The more places that see the same address, the safer the conclusion.
The sensor network is the foundation, but not the whole picture. Several independent levels feed the same assessment, which makes it harder to fool.
Exposed systems that receive real attack attempts and record address, method and time. On the order of sixty sensors across around fifty countries.
Clients and websites report what they have blocked. An address stopped in many places confirms that it is still active.
Systems we have built to reach threat data that is not visible in the open. We do not describe publicly how they work — that would make them easier to avoid.
Attackers do not stick to one service. The sensors therefore receive attempts against the protocols that are actually targeted, and distinguish between what each attempt is after.
We also analyse several other kinds of data to improve the assessment. The more independent observations point the same way, the safer the conclusion that an address really is dangerous.
Which address connects, against which port and at what time.
What the attempt is after: a login, a scan, a known vulnerability or some other pattern.
How often the same address returns, and whether it changes method between attempts.
Whether the same address appears across several independent sensors, or only in one place.
A single hit is not enough. One failed login attempt can be a misconfigured server or a user who mistyped. Only when the pattern persists, or shows up in several places, does the address gain weight.
Working in the other direction matters just as much. Addresses get reused — a server compromised last week may be cleaned up today, and a cloud address can change customer. So addresses drop out of the lists when they stop appearing.
Your devices fetch updated lists from us continuously. The direction matters: the device asks for protection, we do not ask the device for anything.
What goes back are events about what was blocked — an address, a type and a time. That is what lets you see in the panel what has been stopped, and it is also all of it.
A sensor on your network gives you a picture of what is aimed at you, and makes the threat data better for everyone.