Features

What does GrootShield do for you?

Overview

GrootShield uses proprietary mitigation strategies to give server owners peace of mind by ensuring their networks are safeguarded from attacks. These features aim to protect your server from various denial-of-service attacks at every layer in the network stack.

Layer 4 Mitigation

In its simplest form, GrootShield protects you from network-layer TCP and UDP floods. Common attacks like SYN floods and UDP-based reflection/amplification floods are immediately blocked at our edge. GrootShield's anycast network stops attacks as close to the source as possible.

Layer 7 Mitigation

Attackers aim to consume your network resources until it grinds to a halt. Some attack vectors are embedded directly in the Minecraft protocol. Without disclosing specifics, we perform checks against incoming Minecraft clients to ensure they behave like real players, not attackers. This includes defenses against ping attacks, encryption attacks, and massive server join attempts.

Backend Protection / Hiding Your IP

The GrootShield plugin conceals your BungeeCord/Spigot server’s IP address by ensuring all incoming connections are authorized from the GrootShield network. Many devices constantly scan the internet for open ports, logging this information and potentially exposing your backend IP to direct attacks. Our plugin not only hides your IP but also protects against known protocol vulnerabilities not yet patched in many Spigot versions.

Load Balancing

As GrootShield accepts incoming connections to your server, players are evenly distributed to multiple backend servers. This allows you to run multiple BungeeCord instances without needing HAProxy, relying instead on GrootShield for load balancing. Simply provide multiple IP addresses for a single domain, and GrootShield manages the rest, making network scaling to meet demand easier than ever.

Last updated