← Back to Docs

Threat Model

What Compuon defends against, what it doesn't, and why that's the right tradeoff.

Primary Threat: Cheat Tool Commoditization

Most game cheating isn't done by reverse engineers. It's done by players downloading commercial cheat tools — programs like CheatEngine, ArtMoney, or paid subscription cheats that offer point-and-click memory editing.

These tools rely on universal techniques: scan for a value, find its address, write a new value. This is the class of problem behind infinite ammo, frozen health, and forked currency values in live games. Compuon makes that approach economically painful by turning unauthorized edits into mismatches the integrity server can check.

What Compuon Defends Against

+
Memory scanners — CheatEngine-style tools that find and modify runtime values. Unauthorized edits are caught by the server-side comparison.
+
Value freezing — Tools that lock a value such as health, ammo, or durability. The integrity server catches the inconsistency on the next spot-check.
+
Universal cheat tools — Each build is re-seeded, so a cheat located against one build has to be re-located against the next. How much that re-location costs an attacker has not been measured.
+
Replay attacks — Key rotation limits how long captured responses stay useful; it raises the cost of replay rather than preventing it.

What Compuon Does NOT Defend Against

Compuon is not a silver bullet. These are explicitly out of scope:

!
Dedicated reverse engineering — A skilled attacker working on YOUR specific build can bypass protection; the one black-box expert estimate we have on our own challenge build is on the order of hours, and a controlled time-to-defeat study has not been run. Compuon raises the cost, not the ceiling.
!
Nation-state actors — If a state-level adversary targets your game, no client-side protection is sufficient.
!
Server-side cheats — Compuon protects client-side variables. Server logic bugs or database manipulation are separate concerns.
!
Aimbots / ESP — Compuon protects data integrity, not rendering or input. Visual cheats that read (but don't modify) game state are a different problem.

Per-Build Uniqueness

Each build is re-seeded automatically, so a cheat has to be re-located per build. Re-location cost has not been measured.

Server-Side Check

Compuon doesn't try to make cheating impossible on the client. Instead, it makes runtime tampering provable from the server side:

// Integrity server perspective
reported_value = 999999 // what client claims
expected_value = 47 // what the integrity state reveals
// MISMATCH — suspicion increased

The server accumulates suspicion scores over time. Occasional mismatches (network issues, bugs) don't trigger action. Persistent, high-magnitude mismatches indicate intentional tampering. See Suspicion Scoring for details.