Automatic mitigation

The attack hits at 3 a.m. The shield is awake.

Auto Shield detects attack sources and bans them every 30 seconds, using thresholds you set. A trust zone keeps your real players and customers out of the line of fire while you sleep.

3
modes per agent
30 s
scan cycle
0
manual intervention
app.pakkt.io/protection · Auto Shield ● LIVE
You stay in control

Three modes. Calibrate before you arm.

Automation should never be a black box. Start in observation, check the decisions against your real traffic, then arm.

Step 01

Off

At rest

No automatic action. You handle everything by hand via rules and the blacklist. The neutral starting point.

Step 02 · recommended

Observation

Detects, never blocks

The shield logs everything it would have banned, without blocking a thing. You see which IPs would be hit and tune the thresholds, with no connection ever cut.

Step 03 · armed

Auto

Detects and bans

The shield bans the IPs that cross the thresholds, adds the ban to the XDP + nftables blacklist, then releases it on expiry. Everything is logged.

Logic you can read

Simple scoring, not an oracle.

No opaque "machine learning". Auto Shield runs a handful of rules you can read and audit yourself: two thresholds, a trust zone, a ban cap.

  • Drop threshold: past X blocked packets/s, an IP becomes a candidate.
  • Volume threshold: guards against false positives on heavy but legitimate traffic.
  • Trust zone: an IP from a trusted country has to cross both thresholds.
  • Per-cycle cap: a hard limit on how many bans a single scan can issue.
  • Temporary ban: the duration is adjustable, and release is automatic.
Decision on an IP
drop/s > drop_threshold ?
↓ yes
trusted country ?also requires volume > threshold
TEMPORARY BAN + XDP/nft blacklist
in observation mode: logged, never applied
FAQ

Frequently asked questions

Straight answers, no marketing fog.

How does Auto Shield decide to ban an IP? expand_more
On every cycle (every 30 seconds), Auto Shield evaluates the most active source IPs against two thresholds: a drop threshold (blocked packets per second) and a volume threshold. An IP that exceeds the drop threshold becomes a ban candidate. The ban is temporary and configurable (60 minutes by default), and the number of bans per cycle is capped to prevent any runaway behavior.
What is the difference between off, observation and auto modes? expand_more
In "off" mode, Auto Shield does nothing. In "observation" mode (shadow), it detects and logs everything it would have banned, without blocking: ideal for calibrating thresholds risk-free. In "auto" mode, it actually bans the IPs that cross the thresholds. Each agent has its own mode, so you can arm the shield server by server.
Could Auto Shield ban my legitimate players or customers? expand_more
That is exactly what the trust zone and the dual threshold prevent. An IP from a trusted country must exceed both the drop threshold AND a volume threshold before it is banned: a legitimate customer with normal traffic is never touched. Observation mode also lets you verify the decisions before arming the shield.
What is the trust zone? expand_more
The trust zone is a list of countries (for example your country and those of your players) that benefit from an extra margin. A trusted IP is banned only if it exceeds both the drop threshold and a high volume threshold, which protects real users while keeping a firm hand on attack sources.
Are bans permanent? expand_more
No, they are temporary by default (60 minutes, adjustable). A banned IP is added to the dual-layer blacklist (XDP + nftables) for the duration of the ban, then automatically released. You of course retain the ability to blacklist an IP permanently by hand.

Arm the shield, reclaim your nights.

From 3 € / server / month. Observation mode first, auto next. Free 7-day trial, no credit card required.