BEYOND BOTNETS
Clean Ads I/O | June 3, 2015
1
ADVERTISING’S ORIGINAL MISSION
2
WHAT IS A BOTNET?
3
WHAT IS A BOTNET?
4
WHAT IS A BOTNET?
Common Uses
•Impression fraud
•Click fraud
•Conversion fraud
Spam
Content scraping
Denial of service (DDOS)
Financial transactions
Advertising fraud
5
6
ADVERTISING’S OPERATING ASSUMPTIONS
7
VOLUNTEER BOTNETS
8
AD STACKING
WHY LOAD ONE AD WHEN YOU CAN LOAD MANY?
PIXEL STUFFING
9
WHY LOAD ONE SITE WHEN YOU CAN LOAD MANY?
10
ADVERTISING’S OPERATING ASSUMPTIONS
11
DOMAIN SPOOFING: MISDECLARATION OF URL
12
DOMAIN SPOOFING: CROSS-DOMAIN EMBEDDING
13
DOMAIN SPOOFING: CROSS-DOMAIN EMBEDDING
Film piracy site
Sleazy network
Fashion site
14
ADVERTISING’S OPERATING ASSUMPTIONS
15
USER AGENT SPOOFING
16
LOCATION FRAUD
17
Is it where
you were
told it was?
THREE QUESTIONS
Is it who you
were told it
was?
Is it a real opportunity to
tell your message?
18
• Operate at scale
• Attack from multiple angles
- Sophisticated data science
- Empowered white hats
- Web tech wizardry
• Industry-wide protection
THE INTEGRAL APPROACH
THANK YOU!
Jason Shaw| jshaw@integralads.com

"Ad Fraud: Beyond Botnets" - Jason Shaw, Integral Ad Science

Editor's Notes

  • #4 Bot: computer operating under the control of someone other than its owner Owner is usually unaware Botnet: collection of bots leveraged for a common purpose by one “master”
  • #5 Bot: computer operating under the control of someone other than its owner Owner is usually unaware Botnet: collection of bots leveraged for a common purpose by one “master”
  • #6 Not just being unviewable Most ads aren’t seen anyway Not because it’s malware Offensive, perhaps, but that’s not the harm You are purchasing a lie Implicit claim: If you place your ad here, you may influence a potential customer. Truth: With no human present, there is no chance of this.
  • #7 Not just being unviewable Most ads aren’t seen anyway Not because it’s malware Offensive, perhaps, but that’s not the harm You are purchasing a lie Implicit claim: If you place your ad here, you may influence a potential customer. Truth: With no human present, there is no chance of this.
  • #9 Sign up, download, and run Typically sites without significant organic traffic See also: abuse of incentive programs
  • #11 Why load one site when you can load ten?! Typicall y brand-unsafe sites looking to monetize significant organic traffic
  • #13 Declaration of bid URL other than the real one Not only fraudulent, but brand safety concern
  • #17 Sent in HTTP request header Identifies OS, browser, etc. May be modified by the user
  • #18 Mobile app impressions garner higher CPMs when accompanied by lat/long data In absence of user’s permission to obtain it, make it up! Users seeking to interfere with IP-based geolocation use proxy servers or VPN services
  • #20 Scale: 4 billion impressions in the browser daily Consumption: integrations across the buy and sell sides