How To Detect Ad Fraud
Free IP lookup API to uncover fraud, bots, and high risk users.
Detecting fraudulent online activity is much like being a digital detective. Every action – whether from legitimate users, automated bots, click-farms, or random scammers – leaves behind traces of evidence. Your job is to collect the evidence/data and analyze it to determine if it’s consistent with fraudulent behavior.
This analysis works on two levels: examining broad trends across large user populations and zooming in on individual user behaviors within your network. To effectively spot potential fraud you’ll need to gather evidence from three data sources:
- Traffic analytics
- Device fingerprinting
- User behavior analysis
Traffic Analytics
Before you can detect fraud through traffic analytics, you need a solid foundation of baseline data. This baseline helps you distinguish between normal activity and suspicious patterns. For example, if you know your website typically receives 1,000 daily visitors with a 2% conversion rate, a sudden spike to 10,000 visitors with a 0.1% conversion rate would stand out as potentially fraudulent.
Before a digital ad campaign begins, identify your key performance metrics and understand their typical ranges and the factors influencing them. Only then can you effectively spot unusual behavior signaling bot activity or fraud. Basic metrics to evaluate include:
- Unexplained traffic spikes: Large or atypical swings in traffic could be a successful campaign or an influx of bot or click farm traffic
- Higher bounce rates: Bots will click on a link to register engagement but immediately leave the site after it loads so a sign of fraud would be a bounce rate is higher than a typical campaign
- Visit duration: Similar to higher bounce rates, a drop in visit duration could mean bots are visiting the site staying a short time and leaving, providing no benefit to the campaign
- Conversion rates: Abnormally high conversion rates in sales, leads or installs while weirdly low conversion rates could happen because of bot visitors, both should be investigated.
- Visitor locations: Spikes in users with IP addresses from parts of the world outside your target market are a clear indicator of fraud.
Setting up automated reports with good baseline data is an important first step in detecting ad fraud before you begin your ad campaigns.
Device Fingerprinting
Device data a network collects when handling user requests can be used to create a device profile and compare it against typical, non-fraudulent devices. Similar to IP blocklists but instead of evaluating IP addresses for their riskiness and blocking them, you’re doing so for individual devices. The data points to pay attention to include:
- User-agent: Browsers and operating systems have unique identifiers, if one device has several of each or has incongruent software it may be fraudulent
- Number of users & IP addresses: One device with an inordinate number of users or IP addresses associated with it could be a public device or a device used for fraud
- Device data: Information like battery usage, device orientation and screen resolution can be compared to legitimate devices
- IP masking & VPNs: Not all devices using IP masking commit fraud, but all devices who commit fraud use IP masking
Fraud detection software can recognize these patterns and identify individual devices involved in fraud. This data is used to assess the likelihood of a device harming the network and the device can be blocked or flagged for investigation.
User Behavior Analytics
Zooming in on individual user behavior offers insights when investigating potential fraud. By analyzing patterns at the user level, you can uncover suspicious activities that might get lost in aggregate data. Here’s what to watch for when examining a potentially fraudulent user:
- Click patterns: Bots will be too regular, or erratic compared to human users with clicks, scrolls, typing and mouse movements
- Browsing behavior: An abnormal number of pages visited, and amount of time spent on a page can reveal bot behavior
- Engagement: Odd engagement like filling out multiple forms or entering weird search queries demonstrates bot or click farm engagement
- Login attempts: Scammers trying to hack someone’s account will use several login attempts or logins from multiple locations and devices
\As part of your larger investigation, tracking individual users provides invaluable intel on the legitimacy of website traffic.
Detecting Fraud at Scale
Ad fraud can be a huge headache for you and your team and can leave you scrambling to make up for lost time and money. Protecting against ad fraud is crucial to the success of your marketing campaigns.
Working with fraud detection experts can help prevent bots and malicious actors from hijacking your marketing campaigns. Fraudlogix, for example, uses the world’s largest fraud sensor detection network in the world and applies a robust analysis of every user on the network in real-time by connecting their fraud prevention API data to your site.
Our fraud-fighting solutions will allow you to know if your ads are— being seen by actual humans, appearing on brand-safe sites, within view, are running on the correct sites, all while getting a detailed analysis of transactions on your ads with the ability to block and identify fraud as it happens.
At Fraudlogix, we fight ad fraud in all its forms. We develop custom fraud prevention solutions for the unique needs of each of our clients. Sign up now for a free test or contact us to let us know how we can help you detect ad fraud. Keep ad fraud from hurting your marketing campaigns with ad fraud detection solutions from Fraudlogix.