Summary
BeeTcore detects and blocks intrusion attempts at every layer of a platform: at the edge with Cloudflare, inside WordPress platforms with Wordfence and MalCare, within custom applications, and at the server itself. Known attack patterns are blocked automatically, unusual behaviour is flagged for investigation, and every event is logged. Detection rules are kept current, and confirmed intrusions are handled under a defined response process.
1. Detection and prevention
An intrusion detection system spots signs of an attack and raises an alert. An intrusion prevention system goes further and blocks the attack automatically. BeeTcore uses both, in layers, so an attempt that gets past one layer meets the next. This document sits within the Cloud Security Framework.
2. Edge
Cloudflare’s web application firewall inspects every request before it reaches the platform. Managed rules detect and block known attack patterns, such as injection attempts, cross-site scripting, and exploits of published vulnerabilities. Custom rules add protection specific to each platform. Volume-based attacks are covered in the Denial of Service Detection and Mitigation Controls.
3. Application (WordPress platforms)
Wordfence and MalCare protect WordPress platforms from inside the application:
- Application firewall: filters malicious requests that reach the platform.
- Automatic blocking: attacking addresses and malicious patterns are blocked as soon as they are identified.
- Malware scanning: the platform is scanned for malicious code, and infections are removed.
- File change detection: unexpected changes to core, plugin, and theme files are flagged.
- Login security: brute-force protection, login rate limiting, and multi-factor authentication for administrators.
4. Application (custom builds)
- Every request is validated and access-checked, as set out in the Secure Web Development Framework.
- Failed logins, access denials, and other unusual activity are logged.
- Repeated failures trigger automatic lockouts and rate limits.
- Vulnerable dependencies are flagged as soon as vulnerabilities are published.
5. Server
- Self-managed servers: a host firewall allows only the connections a platform needs, remote access uses key-based authentication, and repeated failed access attempts are blocked automatically.
- Managed hosting and major cloud platforms: the provider’s network and host protections apply, alongside BeeTcore’s controls, as set out in the shared responsibility model in the Cloud Security Framework.
6. How attacks are detected
- Signature-based detection: requests and files are matched against known attack patterns, which are updated continuously as new threats are identified.
- Behavioural detection: activity that departs from normal behaviour, such as unusual login patterns, sudden traffic changes, or unexpected file changes, is flagged even when it matches no known signature.
7. Keeping protection current
Detection signatures and firewall rules are updated automatically by each tool’s provider as new threats emerge. The tools themselves are kept up to date as part of routine patching. Rules are tuned over time to block real threats without disrupting legitimate users.
8. Alerts and response
Every blocked or suspicious event is logged, and alerts reach the responsible technical owner through Security Continuous Monitoring. Confirmed intrusions are handled under the Incident Management Response Strategy, and the lessons feed into Continuous Service Improvement. This document is reviewed annually and after any significant intrusion attempt.
Frequently asked questions
Does BeeTcore use an intrusion detection or prevention system?
Yes, both, at every layer: Cloudflare at the edge, Wordfence and MalCare on WordPress platforms, built-in controls in custom applications, and server-level protection.
What is the difference between intrusion detection and prevention?
Detection spots signs of an attack and raises an alert. Prevention blocks the attack automatically. BeeTcore uses both, so known attacks are stopped immediately and unusual activity is investigated.
How are new threats handled?
Detection signatures and firewall rules are updated automatically as new threats emerge, and behavioural detection flags unusual activity even before a known signature exists.