Secure My A$$
Dynamic Host Cyber Defense & Edge Firewalling for Agency Fleet Protection
Zero-bloat edge security platform that monitors malicious brute-force swarms, synchronizes threat telemetry into MariaDB, and pushes dynamic /24 subnet blocks into Traefik v3 reverse proxy in under 50ms without downtime.
The Engineering Case Study
The Problem
Traditional WordPress security plugins run within the PHP application lifecycle, meaning malicious requests still consume server memory, CPU cycles, and database connections before being blocked. Under heavy attack, client servers crash even if the attacker never gets in.
How It Was Engineered
Secure My A$$ implements a dual-mesh defense architecture: a hyper-lightweight sensor monitors application probes and reports attacker subnets to a centralized telemetry store. A daemon on the host compiles active threats and streams dynamic YAML route rules into Traefik v3 in real time via inotify. Malicious requests are dropped at the edge proxy level before ever touching the web server or PHP.
Engineering Hurdles Solved
Preventing self-lockouts and false positives during rapid IP banning while maintaining lean Traefik memory footprint. Cynthia engineered an immutable multi-tier CIDR whitelist (protecting VPS gateways, workstation ISP blocks, and Stripe webhook endpoints) coupled with an automatic sliding-window TTL pruning system.
Business & Production Outcome
Reduced web worker CPU utilization by 85% during sustained bot attacks across client sites. Completely eliminated site crashes caused by brute-force resource starvation while hardening client compliance posture.