Operational Asset // SMA-07 · Zero-Trust Infrastructure & Edge Defense

Secure My A$$

Dynamic Host Cyber Defense & Edge Firewalling for Agency Fleet Protection

Zero-bloat edge security platform that monitors malicious brute-force swarms, synchronizes threat telemetry into MariaDB, and pushes dynamic /24 subnet blocks into Traefik v3 reverse proxy in under 50ms without downtime.

Traefik v3MariaDB TelemetryPython Host EngineLinux Kernel FirewallDocker Swarm
EDGE BAN PROPAGATION
< 50ms Dynamic
PHP CPU REDUCTION
85% Less Overhead
WHITELIST GUARANTEE
Zero Self-Bans
ARCHITECTURE
Dual-Mesh Defense

The Engineering Case Study

01 // THE BUSINESS CONTEXT & CHALLENGE

The Problem

Traditional WordPress security plugins run within the PHP application lifecycle, meaning malicious requests still consume server memory, CPU cycles, and database connections before being blocked. Under heavy attack, client servers crash even if the attacker never gets in.

02 // ARCHITECTURE & SYSTEMS LOGIC

How It Was Engineered

Secure My A$$ implements a dual-mesh defense architecture: a hyper-lightweight sensor monitors application probes and reports attacker subnets to a centralized telemetry store. A daemon on the host compiles active threats and streams dynamic YAML route rules into Traefik v3 in real time via inotify. Malicious requests are dropped at the edge proxy level before ever touching the web server or PHP.

03 // HARD HURDLES & RESILIENCE

Engineering Hurdles Solved

Preventing self-lockouts and false positives during rapid IP banning while maintaining lean Traefik memory footprint. Cynthia engineered an immutable multi-tier CIDR whitelist (protecting VPS gateways, workstation ISP blocks, and Stripe webhook endpoints) coupled with an automatic sliding-window TTL pruning system.

WHY THIS MATTERS TO THE HIRING EXECUTIVE

Demonstrates Cynthia's 20+ years of infrastructure expertise and U.S. Air Force cybersecurity background — building systems that protect client estates with military-grade rigor.

Business & Production Outcome

Reduced web worker CPU utilization by 85% during sustained bot attacks across client sites. Completely eliminated site crashes caused by brute-force resource starvation while hardening client compliance posture.

TARGET CLIENT: Agencies managing fleets of 20-100+ client websites on VPS infrastructure that face relentless bot attacks, brute-force exploits, and credential stuffing.
Test Live Tool ↗