Case study · Perimeter

Perimeter monitoring at a manufacturing company

A manufacturing company — a single inconspicuous firewall change opened the door to spammers. Today it learns of every perimeter change within 24 hours.

48 hfrom exposure to abuse
24 hperimeter change detection
10 daysdeployment and active protection
IP · ports · signaturestemplate of the expected state

Initial state

The client's external perimeter was protected by a hardware firewall and an F5 reverse proxy. SMTP relay servers with public IP addresses were located in the DMZ. The firewall made them accessible only to the company's internal ranges.

What happened

  • after a firewall update, the rules changed unintentionally and the SMTP relay servers became reachable from the entire internet,
  • nobody noticed the change — the perimeter was not being checked continuously,
  • within 48 hours, spammers discovered the servers and abused them for a mass malicious mail campaign.

The solution

  • in agreement with the client, we deployed a continuous scan of the external perimeter over a defined range of public IP addresses,
  • we set up a template of the expected perimeter state — which IP addresses, open ports and service signatures are expected,
  • the scan, comparison with the template and reporting run every 24 hours, and every deviation is reported immediately,
  • deployment, testing and the transition to active protection were completed within 10 days.

Benefits

  • the system detects internal services exposed to the internet within 24 hours — not only after they have been abused,
  • perimeter changes after updates, migrations or vendor interventions are under control,
  • no impact on production — the scan runs from the outside, just as an attacker sees it,
  • the client has a regular overview of the state and evolution of its perimeter.

Facing a similar challenge?

Get in touch — we will be happy to go through your situation and propose concrete next steps in a no-obligation consultation.