Skip to content

Protection Profiles

OpenShield-XDP ships with 70 pre-computed configurations across 10 profiles × 7 intensity levels. Instead of tuning individual thresholds, you answer "what do you host?" and the installer picks the optimal preset.

How profiles work

Each profile encodes a protection philosophy:

  • Rate limits (PPS, BPS, TCP/UDP/ICMP/SYN thresholds) — how much traffic is allowed before scoring begins
  • Scoring (violation scores, suspicion threshold, ban duration) — how aggressively traffic is metered and banned
  • Detection features (entropy, TTL anomaly, packet size anomaly, SYN/FIN ratio, connection tracking) — which behavioral checks are active
  • Escalation (auto subnet ban, panic circuit breaker) — how the system responds under sustained attack

The 7 intensity levels (Strict → Low → Medium → Balanced → High → Very High → Extreme) scale every threshold by a multiplier. Balanced is always the recommended default.

The 10 profiles

#ProfileDesigned for
1Ultra StrictPersonal websites, admin panels, internal dashboards, login portals, small APIs, low-traffic applications
2StrictBlogs, portfolio sites, WordPress, company websites, small stores
3Balanced (default)SaaS, APIs, ecommerce, communities, forums, general web hosting
4PerformanceLarge APIs, streaming, downloads, reverse proxies, large websites
5HostingDocker hosts, VPS nodes, shared hosting, Pterodactyl panels, Kubernetes
6GamingMinecraft, FiveM, Rust, CS2, Terraria, voice servers, game hosting
7EnterpriseBanks, government, large SaaS, critical infrastructure
8CDN / EdgeCDN, reverse proxies, ISPs, large hosting providers, very high bandwidth
9Database / StorageDatabase servers, file storage, backups, mail servers
10CustomMixed workloads, manual per-threshold tuning

The 7 intensity levels

LevelRate MultiplierEffect
Strict0.40×Most aggressive — fastest bans, tightest thresholds
Low0.60×Aggressive — slightly relaxed
Medium0.80×Moderately aggressive
Balanced1.00×Recommended default
High1.35×Relaxed — allows more legitimate traffic
Very High1.75×Very relaxed — minimal false positives
Extreme3.00×Most permissive — blocks only extreme abuse

Per-profile threshold examples

SYN packets per second (syn_pps_threshold)

ProfileStrict (×0.40)Balanced (×1.00)Extreme (×3.00)
Ultra Strict2870210
Strict44110330
Balanced68170510
Performance1604001,200
Hosting4001,0003,000
Gaming2005001,500
Enterprise100250750
CDN / Edge8002,0006,000
Database60150450

Packets per second (pps_threshold)

ProfileStrict (×0.40)Balanced (×1.00)Extreme (×3.00)
Ultra Strict1604001,200
Strict2005001,500
Balanced3408502,550
Performance8002,0006,000
Hosting2,0005,00015,000
Gaming8002,0006,000
Enterprise4801,2003,600
CDN / Edge3,2008,00024,000

Each of the 34 tuned thresholds follows the same pattern — base value from the profile category, scaled by the intensity level, clamped to a safe range.

Workload-based recommendation

The installer presents 27 workload types. Select what you host, and the engine recommends the best profile:

Detected workloads: Minecraft Server, Docker Host, Pterodactyl Panel
Recommended: Gaming Profile
Reason: Tolerates legitimate UDP bursts while protecting against
reflection and flood attacks. Allows modpacks, plugins, many
concurrent game servers.

See Installation for the interactive installer flow.