Before a Malicious Request Reaches the Website: How NNS AI Security Shield Decides

3 days ago

The Request Reaches the Node

A node may run many websites, but this request belongs to one specific hosting service.

NNS AI Security Shield first checks whether this website owns the entitlement and has protection enabled. A website without protection follows its normal path and is not inspected because another customer purchased the shield.

First Decision: Is the Source on This Website's List?

An IP on the current website allowlist passes immediately. An IP on the current website blocklist is rejected for this website.

Both lists remain isolated. An allowlist does not grant access to other websites, and a blocklist does not make decisions for another customer.

Second Decision: Is the Request Path Trusted?

Payment callbacks, open APIs, and administration uploads can behave differently from ordinary pages.

Customers can allow an exact path or directory prefix for the current website. A matched path skips per-site inspection while remaining subject to website permissions and node baseline security.

Third Decision: Does the Request Resemble an Attack?

A request that does not match a list enters NNS AI analysis.

The platform identifies malicious probes, attack patterns, and abnormal requests, producing a result that belongs only to the current website.

Intelligent Monitoring: Observe Without Blocking

In Intelligent Monitoring mode, a matched request is recorded and then continues to the website.

This mode is useful when protection is newly enabled. Customers can review today's detections and recent records before adding an allowlist entry or switching modes.

Active Protection: Record and Stop the Request

In Active Protection mode, a matched malicious request is blocked before reaching the website application.

The source, path, risk type, and result remain visible. Both modes use the same decision capability; the difference is whether a match continues or stops.

A Security Cockpit for the Current Website

The shield page displays status, mode, today's detections, today's blocks, recent records, allowlists, blocklists, and path allowlists.

Customers manage only their own website boundary. They cannot view another website's records or edit node-wide security rules.

Activation and Deactivation

Customers can view whether the current website has the Security Shield entitlement from the service page. After entitlement is granted, protection can be enabled, disabled, or switched between modes from the control panel.

Disabling protection only stops per-site inspection for the current website. It does not remove the entitlement or existing list settings, so protection can be enabled again later.

When the Website Moves, Its Defense Moves Too

The entitlement, mode, and lists belong to the hosting service.

After migration or offsite recovery, NNS applies the settings at the new location without another purchase and without treating an old node identity as the new website.

True Per-Site Protection

NNS AI Security Shield is not one unexplained switch placed over an entire node.

Every request is decided by the current website's entitlement, lists, and mode. Trusted requests continue, monitored requests leave records, and blocked requests stop before the application.

One policy, one record set, and one defense per website: that is the independence of NNS AI Security Shield.