Methodology

View as markdown

As part of our documentation we wanted to spend some time discussing our methodology and approach to building Synthient. This includes our data sources, data processing techniques, and how we ensure the quality and accuracy of our data.

Data Sources

Synthient aggregates data from a variety of proxy providers to achieve comprehensive IP intelligence. The proxy ecosystem is fundamentally one of resellers, with many providers sourcing their data from a handful of large upstream providers. We track these providers internally to filter down to a core list of sources which are used to build our database.

Diagram of the proxy reseller ecosystem showing downstream providers sourcing from a few large upstream providers

Handling IPv6 Coverage

As many are aware, the IPv6 address space is vastly larger than IPv4, making it challenging to cover comprehensively. Our approach to tackling this issue is using a combination of behavioral data associated on networks to pinpoint high risk ASNs that are abused by bad actors. We also aggressively attempt to map IPv6 proxies.

Dealing with Gaps

Given the dynamic nature of IP addresses and the constant evolution of proxy services, there will inevitably be gaps in coverage. We address this by continuously monitoring the market for new providers and updating our data sources accordingly. We are continually monitoring the top providers to ensure that we can get as close to 100% coverage as possible.

Applying observations in your application

Treat a lookup as evidence to interpret alongside your own traffic. An address may be shared or reassigned, and a lack of observations does not prove that a request is safe. Keep observation times with your records and choose an expiry policy appropriate to your use case.

The IP API reference separates network information from intelligence fields. Use service tags to understand provider identifiers and the risk scoring guide to evaluate the signals behind a score. If a result appears inconsistent, send support a redacted example and the time of the lookup so it can be investigated in context.