Fraud goes all the way from simple operations where actual people in countries like India or Bangladesh are physically clicking on ads to sophisticated operations where bots generate human like traffic which is mixed with genuine traffic to avoid detection.
Did you have any experience dealing with residential proxy networks? If so, can you give some examples of any mitigations to inbound requests from those connections?
Also, we refrained from calling it fraud, the term was invalid traffic. This also accounted for things like someone double tapping on an ad instead of once, and so on. There is a good report by Alexander Tuzhilin [1] commissioned by Google when they were sued for charging for invalid traffic that might give you some more ideas.
I was curious, when you say block traffic, would you send 400s or silently just not record the crucial events? It seems like maybe tipping off automation would cause them to readjust. Perhaps they are not that determined?
Things such as a single device ID sending hundreds of requests in a minute or blacklisted IPs would be just dropped silently, no point in even wasting bandwidth to show an ad. For cuts of traffic where the clicks etc were outside of predetermined ranges, it would again be blocked and dropped. In other cases, where fraud happened before we could block it, there was a flag called 'billable' which was set to False so the advertiser wasn't charged for it.
Who were the fraud operators affiliated with / what was their incentive? Isn’t it the publishers that would see value, or perhaps a competitor trying to disrupt marketing efforts?
Do you see opportunity for innovation in traffic validation? Have you seen much in the way of training ML for this purpose?
At least Android provides a public API to measure trustworthiness, but if you are in the business of selling clicks you may also be in the business of turning a blind eye to fraudulent activity that makes you money.
At first I assumed it was conservative enough to fly under the radar. However, now that this network is so big, the pattern of this fraudulent behavior must be unmistakable. It is so simple.
The only conclusion I can draw is that the network is well aware of these bots, and so long as they don't draw negative attention, they are actually boosting "engagement" as the likes / follows do cause events that trigger people into revisiting the product--and ultimately reaching goals.
A 4 core i7 CPU + 32GB of RAM will run 4-8 Android machines, maybe a couple more. You can get 10 Android phones for ~$700.
Especially since you can acquire "barely working" phones. Broken camera? Not a problem. Broken audio jack? No worries. Cracked screen? Meh. No battery life? Doesn't matter one bit.
I imagine it's pretty easy to acquire hundreds of barely working phone for cheap if you don't care about using them as a traditional mobile device.
Can buy a used MacBook Air, sell the lcd assembly and keyboard/trackpad and already recover a big chunk of the cost. (If you needed an Apple device).
What year do you live in? These days even i3s come with 4 cores.
Just ignore the "i7" part if it confuses you. I've not had a desktop in over a decade, so I'm talking about mobile chips 90% of the time.
Check out Correlium https://corellium.com/
They operate in a sort of legal grey-area since you're not 'supposed' to emulate iOS so if you decide to use it, keep in mind it could all be shut down at a moments notice.
https://www.washingtonpost.com/technology/2020/12/29/apple-c...