As part of my work at Tempesta Technologies, I developed WebShield - a cloud-based application for real-time monitoring of traffic spikes and automated mitigation of DDoS attacks and unwanted bot activity. The system continuously analyzes access logs generated by Tempesta FW and stored in ClickHouse, detecting anomalous patterns such as sudden rises in requests per second, response times, or error rates.
Using statistical methods and adaptive thresholds, WebShield identifies aggressive clients by TLS/HTTP fingerprints or IP addresses and automatically applies blocking rules through Tempesta’s tooling. This provides lightweight, configurable protection against L7 DDoS, scrapers, and malicious bots while minimizing impact on legitimate users.