ONX

Blog · Case study ·

2,480 Malicious Bot Incidents Stopped on the Origin

How ONX protected a major aquapark complex from a concentrated wave of automated traffic.

Within a single hour

ONX detected and blocked 2,480 malicious bot incidents on the origin — before they became an application workload.

The Incident

On September 8, between 05:00 and 06:00 UTC, ONX detected an unusual concentration of automated activity against the customer's public web application. During the observed window:

  • 2,480 malicious incidents were detected
  • 2,480 incidents were blocked
  • 100% of the recorded incidents were classified as blocked bots
  • Activity was recorded throughout the entire observed period
  • Individual sources were tracked using privacy-preserving IP hashes

The attack was not a single isolated event. It was a sustained stream of automated activity that ONX identified and blocked on the PHP origin.

The Attack Pattern

The traffic was highly automated and persistent. ONX recorded malicious activity during every minute of the observed attack window.

53 blocked incidents per minute (average)
70 incidents in the peak minute
60 min continuous automated activity

The activity continued throughout the observed period, demonstrating a sustained automated attack pattern rather than a single short burst.

What ONX Did

ONX identified the traffic as automated malicious activity and blocked the requests on the origin. The protection process was straightforward:

Detect → Classify → Block

The malicious requests were stopped at the ONX protection layer. They were not allowed to continue to the protected application.

Why Origin Protection Matters

A public-facing application can be exposed to unwanted automated traffic even when the application itself is functioning normally. Repeated malicious requests can create unnecessary pressure on application resources, including:

  • CPU
  • memory
  • worker processes
  • connection pools
  • application threads
  • database connections
  • network bandwidth

ONX is designed to prevent that traffic from becoming an application workload. Stop the attack before booking or ticket code runs.

The Result

2,480 malicious incidents detected
2,480 incidents blocked
100% of recorded incidents stopped

The recorded malicious traffic was handled by ONX on the origin. The application stayed available throughout the incident.

A Real-World Test of Origin Protection

For an aquapark complex, the website is more than a marketing page. It can support:

  • ticket sales
  • reservations
  • online payments
  • opening information
  • promotions
  • customer accounts
  • operational information

An attack against such infrastructure can therefore become a business problem very quickly. The objective of ONX is simple: keep the public application available while malicious traffic is stopped before it becomes a PHP workload.

This incident demonstrated that principle in practice.

ONX: Security on the Origin

The September 8 incident is a practical example of why origin protection matters for a booking site. ONX identified a sustained wave of automated malicious traffic and stopped it before ticket code ran.

The attack reached the web server. It did not become an application incident.

ONX — Stop bots before they become a reception ticket.

Back to the journal