Skip to main content

🛡️ SYNAPSE SHIELD

Next-Gen Open-Source Behavioral Biometrics & Bot Mitigation Engine

A privacy-first, zero-friction, self-hosted alternative to Cloudflare Turnstile.

License: MIT FastAPI Python 3.12 Inference SLA Zero-PII

FeaturesArchitectureQuickstartDeveloper GuideBenchmarks


⚡ Overview

Synapse Shield replaces intrusive legacy CAPTCHAs and proprietary cloud WAFs with sub-millisecond behavioral biomechanics & cryptographic challenges.

By evaluating natural human neuromuscular micro-tremors (Jerk: $da/dt$), cursor trajectory curvature, Fitts's Law validation (terminal deceleration profiles), and millisecond keystroke intervals, Synapse Shield autonomously classifies and mitigates bots, scrapers, and credential stuffers before they touch your backend logic.


✨ Key Features

  • 🧩 100% Invisible & Friction-Free UX: Zero annoying puzzle solving, image selecting, or audio challenges. Genuine human users pass instantly.
  • 🔑 Cryptographic Challenge-Response: Native protection against telemetry replay attacks. Clients fetch a single-use token from /api/challenge and sign their telemetry payload.
  • 📈 Fitts's Law Deceleration Profiling: Evaluates mouse deceleration as it approaches targets/clicks (terminal_decel_ratio) and checks velocity asymmetry (velocity_skewness) to detect mechanical bot paths.
  • ⚡ Ultra-Low Latency (<0.5 ms): Evaluated locally in-memory using lightweight NumPy & mathematical kinematic scoring.
  • 🔒 100% Zero-PII & Privacy-First: No keystroke characters, form inputs, or personally identifiable information are captured. Only relative millisecond delta timestamps are processed (GDPR / KVKK compliant).
  • 💸 $0 Cloud Costs (Self-Hostable): Zero third-party cloud lock-in. Run anywhere with a single packages command.
  • 📊 Poisson Flooder Detection: Catches high-frequency headless API scrapers lacking mouse telemetry using cumulative Poisson anomaly distributions.
  • 🎮 Interactive 3D Security Lab: Built-in Three.js & WebGL visual dashboard with real-time SQLite audit trails and live telemetry gauges.

🏛️ Architecture

[ CLIENT BROWSER ]
       │
       ├── (1) GET /api/challenge ──► (Generates single-use Cryptographic Token)
       │
       ├── (2) Capture 50 Hz Biometric Telemetry (Mouse, Touch, Key Timestamps)
       │
       ▼ [Signed Telemetry Payload (Telemetry + Token)]
[ FASTAPI INGRESS GATEWAY ]
       │
       ├── (3) Token verification & Replay Attack check
       │
       ├── (4) Kinematic Feature Extraction (19D Physical Vector)
       │       [Jerk: da/dt, Deceleration Ratio, Velocity Skewness, Straightness]
       ▼
[ REAL-TIME DECISION ENGINE (<0.5 ms) ]
       │
       ├────────────────────────┬────────────────────────┐
       ▼                        ▼                        ▼
[ RISK < 50% ]          [ 50% ≤ RISK < 70% ]      [ RISK ≥ 70% ]
  Clean Human             Suspicious Traffic      Automated Bot
       │                        │                        │
       ▼                        ▼                        ▼
[ ALLOW 200 ]            [ CHALLENGE / POW ]      [ BLOCK 403 ]
(Seamless Pass)           (Dynamic Challenge)     (Access Denied)

🚀 30-Second Quickstart

Installing the Command Line Tool

Since Synapse Shield is built as a pyproject.toml package, you can run CLI commands directly:

# 1. Install dependencies
pip install -r requirements.txt

# 2. Run the Synapse Shield server (with Hot-Reload dynamic auto-reload enabled)

synapse-shield run --host 0.0.0.0 --port 8000

Visit http://127.0.0.1:8000 in your browser to launch the Security Lab Cockpit dashboard.

Running the Simulation Suite

To run the automated adversarial Red Team simulation suite showing Fitts's Law violations and Replay Attack mitigations:

synapse-shield test

💻 Developer Integration

1. Backend Protection (FastAPI Decorator)

Protect any API endpoint or login route using the @shield_protect decorator:

from fastapi import FastAPI, Request
from synapse_shield.middleware import shield_protect

app = FastAPI()

@app.post("/api/login")
@shield_protect(max_risk_score=50.0)
async def login(request: Request):
    # This code only executes if Synapse Shield verifies the request as Human
    return {"status": "success", "message": "Authenticated successfully"}

2. Frontend Integration (Vanilla JS Sync)

Include the SDK (<5 KB) and wrap your sensitive form submission:

<!-- Include SDK -->
<script src="http://your-server:8000/static/synapse-sdk.js"></script>

<script>
  // Initialize biometric listener
  SynapseShield.init();

  async function handleLogin() {
    // Automatically retrieves challenge, packages telemetry, and submits to verification endpoint
    const response = await SynapseShield.submit("/api/score");
    console.log("Evaluation Result:", response);
  }
</script>

🤖 Attack Simulation Benchmarks

Synapse Shield includes an automated adversarial test suite simulating 7 distinct attack vectors:

Test Scenario Attack Signature Detection Mechanism Decision Risk Score
Natural Human Organic curves with tremors Biological Jerk & Deceleration verified ALLOW <10.0%
Linear Bot Selenium straight-line cursor $\text{Straightness} = 1.000$ & Zero Jerk BLOCK 98.5%
Replay Attacker Reuse of valid telemetry signature Cryptographic Token Reused / Stale BLOCK 100.0%
Fitts Violator Bot Direct speed click - no terminal slowdown terminal_decel_ratio > 0.85 BLOCK 80.0%
Poisson Flooder 8 rapid requests in $<500\text{ ms}$ Poisson frequency anomaly ($P > 95%$) BLOCK 85.0%
Selenium Webdriver Automated headless crawler navigator.webdriver = true BLOCK 100.0%
Robotic Auto-Typer Constant 50ms keystrokes $\text{Key Variance} < 1.0\text{ ms}^2$ BLOCK 92.0%

🧠 Kinematic & Mathematical Foundation

Synapse Shield extracts physical motion vectors derived from classical biomechanics:

1. Jerk (Acceleration Derivative): $$\text{Jerk} = \frac{da}{dt} = \frac{d^3x}{dt^3}$$ Human neuromuscular micro-tremors produce continuous high-frequency Jerk, whereas mathematical bot curves (Bézier/Linear) produce near-zero or static Jerk.

2. Fitts's Target Deceleration Profile: $$\text{Terminal Decel Ratio} = \frac{\bar{v}{\text{terminal}}}{v{\text{max}}}$$ Humans reflexively slow down when approaching a target click button ($\text{Terminal Decel Ratio} < 0.40$), whereas simple click bots maintain monotonic high speeds during clicks.

3. Poisson Request Rate Anomaly: $$P(X \ge k) = 1 - \sum_{i=0}^{k-1} \frac{\lambda^i e^{-\lambda}}{i!}$$


📁 Repository Structure

Synapse_Shield/
├── pyproject.toml              # PyPI Paket Tanımı & Yapılandırması
├── README.md                   # Proje dokümantasyonu
├── LICENSE                     # MIT Lisans dosyası
├── requirements.txt            # Gerekli kütüphaneler listesi
└── src/
    └── synapse_shield/         # Asıl Kütüphane Paketi
        ├── __init__.py         # Dışa aktarılan API (shield_protect, SynapseEngine)
        ├── engine.py           # Karar motoru
        ├── features.py         # Kinematik matematik modülü
        ├── middleware.py       # FastAPI dekoratörü
        ├── cli.py              # Terminal komutu (synapse-shield run / test)
        ├── tokens.py           # Kriptografik Challenge-Response token üretimi & doğrulaması
        ├── live_attacker.py    # Saldırı simülatörü
        └── static/             # Gömülü arayüz ve JS SDK
            ├── index.html
            └── synapse-sdk.js

📜 License

Distributed under the MIT License. Free for both commercial and personal use.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

synapse_shield-0.1.0.tar.gz (27.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

synapse_shield-0.1.0-py3-none-any.whl (27.0 kB view details)

Uploaded Python 3

File details

Details for the file synapse_shield-0.1.0.tar.gz.

File metadata

  • Download URL: synapse_shield-0.1.0.tar.gz
  • Upload date:
  • Size: 27.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.0

File hashes

Hashes for synapse_shield-0.1.0.tar.gz
Algorithm Hash digest
SHA256 4db998fca94e751a6003b7ba85c773db34dcfc946a2b6a3946f32218e21d0622
MD5 d8bc7d18f8cd1f9eba903d157a28d504
BLAKE2b-256 f6ad3f382221bcd65575c720fea4adb1a8969e171fdf2050370ddab6f5b770ca

See more details on using hashes here.

File details

Details for the file synapse_shield-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: synapse_shield-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 27.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.0

File hashes

Hashes for synapse_shield-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 e75ac94b146b39e41ca88160702ab1872a40cf92bfaa5aea512a3f2e1ffd2016
MD5 60c8fc67ad6fea7c247f739e4cdbaf06
BLAKE2b-256 31862a9ed7d1ca38c8b07f3e0c3f647014e88a43f16156a824db6cb2e7163eef

See more details on using hashes here.

Release history Release notifications | RSS feed

0.3.1

2 files

0.3.0

2 files

0.2.2

2 files

0.2.1

2 files

0.2.0

2 files

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page