Detect and protect
CDPGuard filters packets, recognises abuse while it happens and blocks it on the server. That is operational defence.
On the systemCTIAD · CDPGuard
CDPGuard detects and protects the attached systems. CTIAD is the central threat-intelligence and abuse database: collect, correlate, score, report. They are connected, and they do different work.
Roles
CDPGuard filters packets, recognises abuse while it happens and blocks it on the server. That is operational defence.
On the systemCTIAD stores security events and abuse signals, relates them, scores them and makes the result available for protection and for review.
Central databaseScored threat intelligence is there so CDPGuard and operators can act on a case, not on a single unexplained line.
CTIAD → CDPGuardWhat CDPGuard sees — abuse and threat events — is the material CTIAD is built to correlate. Protection observes. The database keeps the record.
CDPGuard → CTIADBlacklist
The blacklist publishes evaluated indicators. It does not replace CTIAD. A list is one output after collection, correlation and scoring. Public catalogues such as AbuseIPDB are a comparison, not the CTPF data basis and not this design.