| People based | Browser based | |
|---|---|---|
| Dependent on others | Farmed | Zombie |
| Self-sustained | Manual | Mechanical |
There are four different types of online advertising fraud, each with their own unique characteristics.
The recent coverage on the topic of advertising fraud has been very much focused on one aspect of the problem. In the above model this particular kind of activity is referred to as “Zombie” activity. This name is appropriate because the activity is related with infected computers acting on the behalf of the perpetrator. Much like a Zombie would act without its knowledge under the influence of a virus.
In the model presented above, we have four different kinds of online ad fraud, each with a corresponding level of barrier to entry, ease of detection and scalability. We will investigate these three factors later in the article and will first focus on the four different kinds of online ad fraud.
THE FOUR KINDS OF ONLINE AD FRAUD
As we have discussed, the first kind is “Zombie” activity where infected computers act on behalf of the perpetrators. This is what is commonly referred to as a “botnet”.
To understand how easy it is to setup one, see how a Chinese guy goes from nothing to botnet in less than 8-minutes right before your eyes using a cracked version of the commonly used Solar BotNet solution. Basically it’s a solution to gain control and manage the browsers of unknowing web users (and sometimes other bots too). Yes, in 8 minutes.
At least as common, if not more common type of online ad fraud is the “Mechanical” kind. We will later investigate the reasoning to why Mechanical activity may very well be the bulk of all online ad fraud activity.
In this case the entire operation is dependent on computers the perpetrator has 100% control of. Mechanical is where the perpetrator has devised a machine that does the same thing as Zombie activity would, but with an even lower barrier of entry and less changes for being exposed. Mechanical models are more self-sustained than Zombie models are.
The third type is “Farmed” activity, where a type of a crowd sourcing method is used to achieve the goal of impression, click or conversion fraud. A CAPTCHA breaking farm would be a great example of such an approach.
bypasscaptcha.com and byebyecaptcha.com are examples of services that can take care of CAPTCHA needs at scale. Such solution is used for breaking those CAPTCHAS that are not possible to break with pure software solutions. The cost for such services start from $1 per thousand CAPTCHA solved. As these services use humans where needed, the solutions are capable of solving CAPTCHAS as much as you or I am, or more.
Learn more about how to break CAPTCHA for conversion fraud at scale using CAPTCHA farms: http://bit.ly/1CbwnfP
A “mechanical” model that would potentially achieve roughly the same, as long as the CAPTCHA was not too complex, is a solution such as CAPTCHA Sniper, which lists the hundreds of CAPTCHA solutions it supports on its website:
Watch below CAPTCHA breaking in action with a publicly available $97 software you can access instantly online:
In summary, Farmed activities are where a given model is scaled using access to 3rd-party resources at scale. Think crowd sourcing platforms for black hats. These are used for solving CAPTCHA and other mechanical well structured tasks that are not possible in 100% computer-based systems. Farming would often go together with Mechanical online ad fraud models to “fill in the gaps” that the machine’s capabilities leave.
There are two types of Farming models; one where the farmers know what they are doing, and another where they don’t. There are many ways to get people to do things on your behalf without their knowledge, including buying ads.
Watch in real-time how in this incredible video ad networks are used for gaining access to unknowing web users’ resources:
The kind of Farming activity where they farmers do not know the true objective of their assignments, or the extent to which their resources are used at any given moment, also comes in two flavours.
One where they are actually doing something, but just not knowing what they are doing it for. And another where somebody is somehow “hijacking” their browser using a technique that can’t be considered as a zombie approach.
Manual is where there is actual people knowingly doing something like going through a credit card application.
REASONING
As we have discussed above, there are three factors to consider in terms of the four kinds of fraud. These are barrier of entry, ease of detection and scalability of the method
Three factors
Barrier of entry means how easy or difficult it is for the perpetrators to gain access to the said capabilities. Scalability means how easy it is to scale it up and run it efficiently at large scale. Ease of detection means how easy it is to detect what the perpetrators are doing. Each of these have the potential for aggravating or ailing the condition caused by the perpetrator’s activity.
In terms of detection, Zombie activity is easier to detect than mechanical because other parties than the programmatic advertising industry are interested in the problem as well. Mechanical activity is a programmatic advertising only problem. Manual is obviously the hardest to detect, and farming is the second hardest because it’s easier than manual (there has to be some structure in the organisation/platform providing the resource) but not as easy as with mechanical which might not resemble natural activity at all.
Everyone can do something manually, so that’s the easiest. Writing a script that looks like a person to an ad server is not a hard task, and could take as little as 4-8 hours from an experienced developer to do well. Much less to do it in a scrappy way that would still give the same result. It’s not so easy to find good farming partners from the dubious side, and it’s not easy to get the straight crowd sourcing platforms to bend in to dubious activity. So that is harder that writing scripts or doing it manually. While setting up a botnet might be easier than creating a script to mimic web users, it’s harder to have the zombies you need to make the botnet valuable. Therefore Zombie models are the hardest to start.
What pops out is mechanical with low barrier of entry and harder to detect than zombie activity (because it’s an adtech problem). Also it has better scalability than zombie activity, because you are not limited by how many people you can infect. You’re just limited by how many IPs you can get access to. Roughly you can assume that you can have access to large pools of cycling IPs (look like broadband access) at $0.10 per IP. If you are willing to take big blocks (i.e. you have the whole range of numbers), the price can be much lower than that. One IP could represent more than one people when the design of the system is right. the revenue earned from that person is much higher than the cost in any case.
For scale too, the reasoning is obvious. Manually is the least scalable, and pure machine model is the most scalable. Out of the two remaining, Farming models are less scalable than Zombie models because Zombie models have more economies of scale. You can add more zombies at a lower cost than you can more nodes to your farming network.
| Barrier to entry | Scalability | Ease of detection | |
|---|---|---|---|
| Zombie | Highest ▲ | Good | Easiest ▲ |
| Mechanical | Low | Best ▼ | Easy |
| Farmed | High | Poor | Hard |
| Manual | Lowest ▼ | Worst ▲ | Hardest ▼ |
▲ marks what is best for us, ▼ what is worst for us.
This way we can clearly establish the likely favourability of each model for the perpetrators and the severity of the threat associated with each model for the advertiser. For example, it seems fair to assume that there will be more Mechanical fraud than there will be Zombie fraud, because Zombie activity is easier to expose and has the highest barrier of entry. A single person person could operate a very successful Mechanical operation.
No better way to bring this point across than through the story of Shawn Hogan, the CEO of a somewhat notorious internet marketing firm Digital Point Solutions. In 2006 he was found running a cookie stuffing racket of US$28 million per year on eBay before being busted by the FBI. Shawn had been the #1 affiliate partner of eBay for years.
Read how to make US$100,000 per day on eBay stuffing cookie on toolbars and share-buttons: http://read.bi/1y1AFtK
CONCLUSION
In this article we’ve learn that botnet kind of ad fraud is just one kind of online ad fraud, and not necessarily the leading kind. We also know that it is not the kind that will be the hardest to deal with. Also we can clearly see that the spectrum of conversation we have about the topic of online ad fraud within the industry is nowhere near as broad as the spectrum (and perpetrators) of activities we are up against.
Were you left wondering how big the online ad fraud problem really is?
Read an analysis quoting five research sources on the size of the online ad fraud market: http://bit.ly/1GyHiF6