Repository navigation
Expand file tree
/
Copy pathappendix.html
More file actions
163 lines (159 loc) · 6.79 KB
/
Copy pathappendix.html
File metadata and controls
163 lines (159 loc) · 6.79 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
{% block body_content %}
<div class="row" >
<p>{{ trafficType }} which score in the high-risk range are associated with non-human traffic through inconsistencies
seen in the visitors behavior and device characteristics. For increased insight into scoring methodologies
Forensiq provides five Reason Codes, defined below:</p>
</div>
<div class="row" >
<table>
<thead class="fqheader">
<tr>
<th>Reason Code</th>
<th>Definition</th>
</tr>
</thead>
<tbody>
<tr>
<td>Spoofed</td>
<td>The user’s device and browser were manipulated to resemble a different
device or browser. This technique is commonly used to produce a real-life
distribution of traffic and simulate traffic from multiple visitors.</td>
</tr>
<tr>
<td>IP Reputation</td>
<td>The IP address was historically associated with high-risk characteristics like
spoofing and other patterns that correspond to proxy and botnet activity.
</td>
</tr>
<tr>
<td>Hosting Provider</td>
<td>An IP belongs to a hosting provider’s range. Unlike regular Internet Service
Providers (e.g. T-Mobile, Verizon), when a visit is generated from a hosting
provider’s IP, it is most often associated with automated, non-human traffic.
</td>
</tr>
<tr>
<td>Proxy</td>
<td>The IP address is a known proxy.</td>
</tr>
<tr>
<td>Automated Traffic</td>
<td>Identifies malicious botnet activity flagged on the user level through real-time
traffic pattern analysis.</td>
</tr>
</tbody>
</table>
</div>
<div class="row" >
<p>Campaign optimization can be done at the Source, Sub Source, and Domain levels. The below table
provides groups the Total Risk Ratio into seven distinct Risk Levels and can be used to build blacklists.</p>
</div>
<div class="row" >
<table>
<thead class="fqheader">
<tr>
<th>Risk Ratio</th>
<th>Risk Level</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>< 2%</td>
<td class="premium">Premium</td>
<td>High quality impression traffic. Fraudulent activity may be
due to false positives, which is less than 1% in organic traffic
sources.</td>
</tr>
<tr>
<td>2% - 5%</td>
<td class="low">Low</td>
<td>Fraudulent activity is not likely. Some fraudulent activity
may occur at the impression level.</td>
</tr>
<tr>
<td>6% - 10%</td>
<td class="moderate">Moderate</td>
<td>Some fraudulent activity is likely, concentrated at the impres-
sion level. Traffic mixing between human and non-human
traffic sources is likely.</td>
</tr>
<tr>
<td>11% - 15%</td>
<td class="elevated">Elevated</td>
<td>Fraudulent activity is likely, some concentrated at the impres-
sion level. Traffic mixing between human and non-human
traffic sources is highly likely.</td>
</tr>
<tr>
<td>16% - 20%</td>
<td class="el-high" style="white-space:nowrap">Elevated-High</td>
<td>Fraudulent activity is likely to affect the entire source. Traffic
mixing between human and non-human traffic sources is highly
likely.</td>
</tr>
<tr>
<td>20% - 26%</td>
<td class="high">High</td>
<td>Fraudulent activity is likely to affect the entire source. Traffic
mixing between human and non-human traffic sources is highly
likely.</td>
</tr>
<tr>
<td>26% - 100%</td>
<td class="critical">Critical</td>
<td>It is not recommended to buy from sources with fraud levels
within this threshold.</td>
</tr>
</tbody>
</table>
<p>This guide should be considered in combination with the following to create custom blacklists for each
Campaign:</p>
<ul>
<li><span class="fqred">Risk Tolerance for Fraud:</span> How much fraud the client is potentially willing to accept
have no tolerance while others may have less stringent requirements.</li>
<li><span class="fqred">Price Points:</span> The CPMs the client wants to remain within.</li>
<li><span class="fqred">Volume:</span> The volume of traffic that the client wishes to buy.</li>
</ul>
</div>
<div class="row" >
<h4>Methodology</h4>
<p>Our methodology for scoring is based on two factors:</p>
<ol>
<li>The high-risk patterns we identify by analyzing various device metrics and for each conversion when the Forensiq tag fires or API is called.</li>
<li>The visitor's IP address, which we evalate against our Fraud Intelligence Database for high-risk patterns and past fraudulent activity.</li>
</ol>
<h4>Fraud Evaluation Criteria: Conversion Score</h4>
<table>
<thead class="fqheader">
<tr>
<th>Risk Ratio</th>
<th>Risk Level</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>0-64</td>
<td class="low">Low</td>
<td>High quality impression traffic. Fraudulent activity may be
due to false positives, which is less than 1% in organic traffic
sources.</td>
</tr>
<tr>
<td>65-79</td>
<td class="elevated">Suspect</td>
<td>Fraudulent activity is not likely. Some fraudulent activity
may occur at the impression level.</td>
</tr>
<tr>
<td>80-100</td>
<td class="high">High-Risk</td>
<td>Some fraudulent activity is likely, concentrated at the impres-
sion level. Traffic mixing between human and non-human
traffic sources is likely.</td>
</tr>
</tbody>
</table>
</div>
{% endblock %}