Hello tech experts, we are auditing our cloud infrastructure security and noticed that while our web app firewall covers HTTP/HTTPS requests, our underlying transport-layer protocols are still exposed. We are worried about direct IP attacks hitting our non-HTTP services and causing infrastructure failure. What is the recommended strategy to shield transport-layer protocols effectively against large-scale malicious traffic?