Since its first inception, since version 1.0, Syncplify Server!’s most important security subsystem has been the so-called “Protector”: a system capable of identifying attacks, prevent them, and auto-ban the attackers’ IP addresses, all in real-time.
Now, after nearly 13 years of honorable service, we’re retiring Protector in favor of a completely new design. The change is so radical that we felt it appropriate to use a different name for it. We now call it Shield.
But… why?
Shield was developed as part of the SFTP.cloud project, and within 2 hours of its release it had already proven itself on-field, against a distributed botnet attack.
Of course we were pleased with the result, but that got us thinking: how would have Protector fared against the same attack? Luckily we had a few dozen megabytes of very detailed logs that allowed us to re-simulate the entire attack shape and run it against both Protector and Shield to measure the results.
First and foremost, it is important to say that both Protector and Shield handled it with a 100% success rate. But then, why is Shield such a big deal? If both technolgies prevented 100% of these attacks, why is Shield so far superior?
It all comes down to four aspects:
Resource usage: while the attack was underway, Protector used up ~8% of the host machine’s CPU to prevent it, Shield did the same while using only ~0.1% (that’s 80 times fewer CPU cycles)
Long-term memory: Protector didn’t have any, so every attack was a new event from its perspective, which means that “slow and patient” attacks are dealt with but never prevented. Shield has memory. It remembers the behavior of each attacker for a certain (configurable) amount of time, and is capable of preventing re-attacks from known sources far more effectively using such knowledge.
Shield is fully deterministic: Protector was partly deterministic and partly probabilistic, leading it to raise the occasional false positive here and there. Shield is fully deterministic, leading to far fewer (in the vast majority of cases absolutely zero) false positives.
Flexibility: Shield can be fine-tuned much more granularly than Protector, which increases its flexibility by a huge margin.
So, what does it look like?
Well, first and foremost its UI is far more informative than the old Protector. Shield gives you a lot more information about each ban and what caused it.
It also provides a real-time view of its current status, including a list of IP addresses that are currently under review (have strikes) and why.
And, like we said, it’s highly configurable/tunable, but it comes with built-in sensible defaults, so most operators won’t ever have to “mess” with it.
How can you get it?
Simply update or upgrade to Syncplify Server! v8.3.0 (or newer) and Shield is built-in, your old Protector is gone, and your old banned IP list and safe-list are automatically converted to the new format.




