For 125 days straight, Qriton Shield has defended live production infrastructure — a city public-services portal and a regional media platform — against a constant stream of probing, abuse, and outright attack. This is what the record shows, and why every number in it can be checked.

Shield applies the same evidence-first architecture behind Qriton's models to live network behaviour: it watches traffic in real time, decides how to respond, and carries the reasoning behind every action it takes. Over those 125 days it inspected 22.2 million requests and blocked 11 million of them — roughly one in two.

The numbers

When the floods came

Quiet days look like steady background noise. The interesting days do not. On one April afternoon traffic to a single protected site jumped to 6.36 million requests in twenty-four hours. Weeks later, a concentrated flood drove 1.6 million requests from roughly 1,300 sources — and Shield blocked 98% of it, absorbing the surge without a human in the loop and without a signature list to fall back on.

Shield is built on a Modern Continuous Hopfield Network — the same family Qriton uses for its models — so it recognises coordinated activity as a pattern across IP ranges, sessions, timing, and behaviour, rather than a stream of isolated alerts. Volumetric attacks that would slip past a static rulebook show up as exactly what they are.

Where it came from — and what it wanted

The heaviest floods were volumetric and concentrated: a handful of sources drove millions of requests. Geolocating the top attackers shows the load originated mainly in Romania and Germany, with bursts from Türkiye, Italy and Switzerland — and a long tail reaching the US, the Netherlands, Russia, Hong Kong, Canada and the UK. Eleven countries among the top sources alone.

Origin of the heaviest attack traffic

Blocked requests from the top source addresses, by country.
Romania2.49M
Germany1.86M
Türkiye254K
Italy72K
Switzerland22K
United StatesNetherlandsRussiaHong KongCanadaUnited Kingdom

What they went after

Most-targeted endpoints across the protected sites — almost entirely GET floods.
Real-time “now-playing” API feeds~130K
Shield’s own detection API (/hopfield)19,002
City “sesizări” complaints API12,839
Messages API12,832
Weather / data API5,500

Traffic over five months

Requests inspected per month; April carried a multi-day flood, June a sharp two-day spike.
February2.66M req · 2.0M blocked
March2.33M req · 1.9M blocked
April12.5M req · 3.8M blocked
May2.11M req · 1.0M blocked
June (6 days)2.55M req · 2.3M blocked

A system that tunes itself — and shows its work

The defensive posture that handled June was not the one Shield started with. Over the campaign it adjusted its own parameters 68 times — tightening per-IP thresholds, raising block sensitivity for command-and-control patterns, shifting rate limits — and it logged why each time:

perIpThreshold 40 → 38  ·  reason: escalationRate 0.83 > 0.30

Across the campaign its core defenses hardened in response to live pressure — every move recorded:

Per-IP request threshold4015Tightened as coordinated sources escalated — escalationRate 0.83 > 0.30
Detection boost multiplier0.300.80Raised sensitivity to repeat offenders
High-severity rate limit1510Stricter ceiling once deterrence dropped
Attribution threshold20%10%Lowered to attribute mixed-source campaigns sooner

68 self-tuning changes in total — each with a timestamp and a reason in the calibration record.

That is the difference that matters. Plenty of systems adapt; few can tell you what they changed, when, and on what evidence. Shield's calibration history reads like an operator's notebook — every decision attributable, reviewable, and defensible after the fact.

Why accountability is the point

As autonomous, agentic threats become routine, "the system blocked it" stops being an acceptable answer — to a security lead, to an auditor, or to a regulator. Static perimeter defenses were built for a slower world. Shield is built for one where the action has to be explained later, in line with the standard Qriton applies across its work: systems operators can understand, auditors can review, and teams can run entirely under their own control.

Infrastructure teams can run Shield today — free on an individual server at shield.qriton.com, with enterprise deployment available across device-to-cloud infrastructure.

Have infrastructure that can't afford an unexplained answer? Talk to Qriton about Shield in your environment.