SlideShare una empresa de Scribd logo
1 de 30
Descargar para leer sin conexión
Mobile Display Fraud
is Rampant Beyond Belief
June 2018
Augustine Fou, PhD.
acfou [at] mktsci.com
212. 203 .7239
June 2018 / Page 1marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Mobile is 57% of digital spend
Source: IAB Full-year 2017 Digital Advertising Report
June 2018 / Page 2marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
"Fraud in mobile advertising is more tricky than just fake
impressions, clicks, or installs. App advertisers can check
when a user actually takes an action with their app after
install to check legitimacy. The issue becomes which ad-
network supplier gets credit for delivering that install. So
attribution fraud is the major concern: where advertisers
pay ad-networks, based on attribution vendor reporting, for
installs that happened organically or by different marketing
methods." -- Shailin Dhar, Method Media Intelligence
June 2018 / Page 3marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Main forms of mobile fraud
Install FraudImpression Fraud
“fake devices installing legit
apps, get paid on CPI”
“fake or fraud apps load
display ads, get paid CPM”
Mobile display spend $25B (2017)
Source: eMarketer, April 2017
App install spend $6B (2017E)
Source: BusinessInsider, June 2016
This deck focuses on
mobile display fraud
June 2018 / Page 5marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Which is easiest for bad guys?
Fake Apps on
Fake Devices
Adware SDK in
Real Apps
Malware On
Real Devices
Limitation
Wait until unsuspecting
humans accidentally
downloads malware on
real mobile devices
Limitation
Wait until app developers
install SDK into their real
apps and humans to
download and use apps.
Limitation
No limits - apps are easily
cloned, and mobile
emulators are easily
“spun up” in data centers
June 2018 / Page 6marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Half of humans download 0 apps/mo
June 2018 / Page 7marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Apps’ primary revenue is ads
In-App
Advertising
App Store
Source: SensorTower
June 2018 / Page 8marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
75% mobile revenue from games
Source: SensorTower
June 2018 / Page 9marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Top mobile apps by ad revenue
Top mobile apps
by ad revenue
Are entirely
different than
ones humans
spend the most
time with
June 2018 / Page 10marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Massive, scalable display fraud
“Judy Malware”
• 40 bad apps to load ads
• 36 million fake devices to load
bad apps that load display ads
• e.g. 30 ads per device /minute
• 30 ads per minute = 1 billion
fraud impressions per minute
“Fireball Malware”
• 250 million infected computers
• primary use = traffic for ad fraud
• 4 ads /pageview (2s load time)
• fraudulent impressions at the
rate of 30 billion per minute
Source: Forbes, May 2017 Source: Checkpoint
June 2018 / Page 11marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
(2015) Apps doing ad fraud
Source: BusinessInsider, July 2015
“A user downloads an app
from the official app store
— which may look
legitimate and have
hundreds of positive reviews
— which then runs in the
background, serving
hundreds of ads at a rate as
high as 20 ads per minute”
Known and documented
for years – now mobile is
majority of digital spend
June 2018 / Page 12marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
(2017) Handful of bad apps
1 (52% of impressions) 2 (48% of impr)
66% avg fraud
18% avg fraud
1. 9% of the apps caused 52% of impressions; 66% outright fraud
2. Remaining 91% of apps caused 48% of impressions, 18% outright fraud
• 1 billion mobile display impressions
• Nearly 1,000 apps cross referenced with SDK
Source: https://www.slideshare.net/augustinefou/mobile-display-fraud-case-study
June 2018 / Page 13marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Fraud apps load impressions
Source: ImpScore.io - https://www.youtube.com/watch?v=w-i-ue8fPCc
“fake apps or fraud apps (real apps that misbehave) continuously
load display ad impressions in the background, inflate revenue”
June 2018 / Page 14marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
App cloning, free adware SDKs
Apps are cloned
thousands of times;
some didn’t even
bother to change
the colors or cover
graphics.
Bad guys accidentally
cloned apps that
already had detection
SDK in it – from 312, to
750, to 1,330 copies.
Source: CNBC, Aug 2017
June 2018 / Page 15marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Fake apps from real campaigns
com.obpmirzste.ldsjpv
com.zmm.shmxvjxnsagndui
com.nqzwr.leusrmpmsq
com.rced.zcdsglptpdlwpu
com.kerms.ehlsgnc
com.cmia.iabhheltm
com.skggynmtx.tyyjnwpefvqtll
com.kgdtltnuv.hayvfhob
com.ztzsiqg.dyojlxdscxws
com.xlwuqe.ddrdhsuosbn
com.rkrhmzee.wjcoznxu
com.ebhzb.hbzvomzpcctovj
com.dxnxbgj.mkridqxviiqaogw
com.obugniljhe.fptvznqwhmcjm
com.bpo.ksuhpsdkgvbtlsw
com.rlcznwgouw.vvtexstbfttngc
com.kasbgf.sbzwtgpcbjexi
com.bprlgbl.vbze
com.zka.lzhsoueilo
com.alxsavx.mizzucnlb
com.jxknvk.lrwfdfirdzpsw
com.tvwvqbt.wbshaguqy
com.iwnxtpahcu.leyuehdwdbb
com.okf.rhvemtykfibzpxj
June 2018 / Page 16marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
“Naked Ad Calls” (load ad, not page)
Why load the entire webpage when you can just
load the ad (save bandwidth) and get paid?
Pass fake data
via query strings
June 2018 / Page 17marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Apps load webpages
“fraud apps sell traffic; use hidden webview browser to load pages”
June 2018 / Page 18marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Fake app traffic – real dataRepeatedly load webpages (e.g. galleries) in sequence or random
June 2018 / Page 19marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Apps load webpages, disguise
“fraud sites’ traffic from apps that also pass fake HTTP headers”
Source: SimilarWeb
June 2018 / Page 20marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Fake devices (mobile simulators)
Download and Install Apps
Launch and Interact
June 2018 / Page 21marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Fake mobile devices – real data
Repeated hits by same device/browser, same ip address
June 2018 / Page 22marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Fake devices pass fake location
Houston, TX Bozeman, MT
Fake devices declare fake locations to absorb higher ad spend
June 2018 / Page 23marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
90-99% of geolocation bad or faked
Source: Placed, Sept 2017
Source: SafeGraph
June 2018 / Page 24marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Bad guys trick measurement
SDK Spoofing— code in an app that sends simulated ad
clicks and engagement signals to the attribution provider
… [to] fool an advertiser into paying for fraudulent
impressions/views.
Attribution Fraud— code that executes clicks (click
spamming, click injection) so fraudster can claim credit
for downstream conversions.
Detection Tag Blocking— fake or fraudulent apps can
selectively block fraud detection tags or manipulate
analytics data.
June 2018 / Page 25marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Mobile fraud is not caught
Source:
https://mumbrella.com.au/iabs-
first-australian-figures-claim-just-4-
of-digital-ads-fraudulent-429776
IAB: mobile fraud is
“almost non-existent”
“it’s NOT
non-existent”
June 2018 / Page 26marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Any device with chip/connectivity
Traffic cameras
turned into
botnet (Engadget,
Oct 2015)
mobile devices
webcams
connected
traffic lights
connected cars
thermostat
connected fridge
Security cams
used as 400
Gbps DDoS
botnet (Engadget,
Jun 2016)
…can be used as a bot
June 2018 / Page 27marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Economics of botnets explained
Source: MIT Tech Review, May 2018
“distributed denial-of-service
attacks using a network of 30,000
bots can generate around
$26,000 a month. Spam
advertising with 10,000 bots
generates around $300,000 a
month, and bank fraud with
30,000 bots can generate over
$18 million per month. But the
most profitable undertaking is
click fraud, which generates well
over $20 million a month of
profit.”
Botnets can be used
for a variety of things
June 2018 / Page 28marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
About the Author
Augustine Fou, PhD.
acfou [@] mktsci.com
212. 203 .7239
June 2018 / Page 29marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Dr. Augustine Fou – Independent Ad Fraud Researcher
2013
2014
Published slide decks and posts:
http://www.slideshare.net/augustinefou/presentations
https://www.linkedin.com/today/author/augustinefou
2016
2015
2017

Más contenido relacionado

Similar a Mobile display fraud is rampant beyond belief

Similar a Mobile display fraud is rampant beyond belief (20)

How Brands are Solving Ad Fraud Themselves
How Brands are Solving Ad Fraud ThemselvesHow Brands are Solving Ad Fraud Themselves
How Brands are Solving Ad Fraud Themselves
 
Mobile Ad Fraud - Betcha Didn't Know
Mobile Ad Fraud - Betcha Didn't KnowMobile Ad Fraud - Betcha Didn't Know
Mobile Ad Fraud - Betcha Didn't Know
 
Low-Cost, No-Tech Ways to Fight Fraud vMiMA
Low-Cost, No-Tech Ways to Fight Fraud vMiMALow-Cost, No-Tech Ways to Fight Fraud vMiMA
Low-Cost, No-Tech Ways to Fight Fraud vMiMA
 
State of Digital Ad Fraud Q2 2017 by Augustine Fou
State of Digital Ad Fraud Q2 2017 by Augustine FouState of Digital Ad Fraud Q2 2017 by Augustine Fou
State of Digital Ad Fraud Q2 2017 by Augustine Fou
 
State of digital ad fraud 2017 by augustine fou
State of digital ad fraud 2017 by augustine fouState of digital ad fraud 2017 by augustine fou
State of digital ad fraud 2017 by augustine fou
 
DMA_PPT_Analytics FINAL Sept 2017
DMA_PPT_Analytics FINAL Sept 2017DMA_PPT_Analytics FINAL Sept 2017
DMA_PPT_Analytics FINAL Sept 2017
 
Hidden Costs in Digital Media Supply Path
Hidden Costs in Digital Media Supply PathHidden Costs in Digital Media Supply Path
Hidden Costs in Digital Media Supply Path
 
Investigating digital ad fraud spi virtual meeting
Investigating digital ad fraud   spi virtual meetingInvestigating digital ad fraud   spi virtual meeting
Investigating digital ad fraud spi virtual meeting
 
Marketers Take Control Run Experiments
Marketers Take Control Run ExperimentsMarketers Take Control Run Experiments
Marketers Take Control Run Experiments
 
Unintended Consequences for Publishers using Adtech
Unintended Consequences for Publishers using AdtechUnintended Consequences for Publishers using Adtech
Unintended Consequences for Publishers using Adtech
 
Marketers' Playbook Questions to Ask Verification Vendors
Marketers' Playbook   Questions to Ask Verification VendorsMarketers' Playbook   Questions to Ask Verification Vendors
Marketers' Playbook Questions to Ask Verification Vendors
 
Where the Wild Bots are OPSNY June 2016
Where the Wild Bots are OPSNY June 2016Where the Wild Bots are OPSNY June 2016
Where the Wild Bots are OPSNY June 2016
 
Fraud Detection is Easily Fooled
Fraud Detection is Easily FooledFraud Detection is Easily Fooled
Fraud Detection is Easily Fooled
 
Good Publishers Will Save Digital Marketing v2019
Good Publishers Will Save Digital Marketing v2019Good Publishers Will Save Digital Marketing v2019
Good Publishers Will Save Digital Marketing v2019
 
Fake Everything 2019 Update
Fake Everything 2019 UpdateFake Everything 2019 Update
Fake Everything 2019 Update
 
State of Ad Fraud Ad Blocking Q1 2016 Update Augustine Fou
State of Ad Fraud Ad Blocking Q1 2016 Update Augustine FouState of Ad Fraud Ad Blocking Q1 2016 Update Augustine Fou
State of Ad Fraud Ad Blocking Q1 2016 Update Augustine Fou
 
Digital Ad Fraud Is Not Illegal Yet
Digital Ad Fraud Is Not Illegal YetDigital Ad Fraud Is Not Illegal Yet
Digital Ad Fraud Is Not Illegal Yet
 
Still nothing but ad fraud 2021 dr augustine fou
Still nothing but ad fraud 2021 dr augustine fouStill nothing but ad fraud 2021 dr augustine fou
Still nothing but ad fraud 2021 dr augustine fou
 
Ad fraud update for publishers Feb 2020
Ad fraud update for publishers Feb 2020Ad fraud update for publishers Feb 2020
Ad fraud update for publishers Feb 2020
 
History and Impact of Digital Ad Fraud
History and Impact of Digital Ad FraudHistory and Impact of Digital Ad Fraud
History and Impact of Digital Ad Fraud
 

Más de Dr. Augustine Fou - Independent Ad Fraud Researcher

Más de Dr. Augustine Fou - Independent Ad Fraud Researcher (20)

Forensic Auditing of Digital Media.pdf
Forensic Auditing of Digital Media.pdfForensic Auditing of Digital Media.pdf
Forensic Auditing of Digital Media.pdf
 
Q1 2022 Update on ad fraud for AMM
Q1 2022 Update on ad fraud for AMMQ1 2022 Update on ad fraud for AMM
Q1 2022 Update on ad fraud for AMM
 
Ad blocking benchmarks q4 2021
Ad blocking benchmarks q4 2021Ad blocking benchmarks q4 2021
Ad blocking benchmarks q4 2021
 
Digital ad dollars trickle down chart
Digital ad dollars trickle down chartDigital ad dollars trickle down chart
Digital ad dollars trickle down chart
 
Bad guys optimize ad fraud efficiency
Bad guys optimize ad fraud efficiencyBad guys optimize ad fraud efficiency
Bad guys optimize ad fraud efficiency
 
Alternative to ANA's end to end supply chain transparency study v final
Alternative to ANA's end to end supply chain transparency study v finalAlternative to ANA's end to end supply chain transparency study v final
Alternative to ANA's end to end supply chain transparency study v final
 
Impact of Loss of 3P Cookies on Publishers' Ad Revenue
Impact of Loss of 3P Cookies on Publishers' Ad RevenueImpact of Loss of 3P Cookies on Publishers' Ad Revenue
Impact of Loss of 3P Cookies on Publishers' Ad Revenue
 
Entire ecosystem supporting ad fraud 2018
Entire ecosystem supporting ad fraud 2018Entire ecosystem supporting ad fraud 2018
Entire ecosystem supporting ad fraud 2018
 
Digital Media Trust Collaborative
Digital Media Trust CollaborativeDigital Media Trust Collaborative
Digital Media Trust Collaborative
 
Programmatic reach analysis 2021
Programmatic reach analysis 2021Programmatic reach analysis 2021
Programmatic reach analysis 2021
 
2021 update on ad fraud brand safety privacy
2021 update on ad fraud brand safety privacy2021 update on ad fraud brand safety privacy
2021 update on ad fraud brand safety privacy
 
Browser and OS Share Jan 2021
Browser and OS Share Jan 2021Browser and OS Share Jan 2021
Browser and OS Share Jan 2021
 
Checking abnormal referrer traffic in google analytics
Checking abnormal referrer traffic in google analyticsChecking abnormal referrer traffic in google analytics
Checking abnormal referrer traffic in google analytics
 
Digital Fraud Viewability Benchmarks Q4 2020
Digital Fraud Viewability Benchmarks Q4 2020Digital Fraud Viewability Benchmarks Q4 2020
Digital Fraud Viewability Benchmarks Q4 2020
 
Four types of digital ad spend updated august 2020
Four types of digital ad spend updated august 2020Four types of digital ad spend updated august 2020
Four types of digital ad spend updated august 2020
 
How to Use FouAnalytics For Marketers
How to Use FouAnalytics   For MarketersHow to Use FouAnalytics   For Marketers
How to Use FouAnalytics For Marketers
 
FouAnalytics DIY site media analytics fraud detection baked in
FouAnalytics DIY site media analytics fraud detection baked inFouAnalytics DIY site media analytics fraud detection baked in
FouAnalytics DIY site media analytics fraud detection baked in
 
Fraud by Browser Study
Fraud by Browser StudyFraud by Browser Study
Fraud by Browser Study
 
Digital Ad Fraud FAQ Question 1
Digital Ad Fraud FAQ Question 1Digital Ad Fraud FAQ Question 1
Digital Ad Fraud FAQ Question 1
 
Digital ad dollars trickle down chart
Digital ad dollars trickle down chartDigital ad dollars trickle down chart
Digital ad dollars trickle down chart
 

Último

Android Application Components with Implementation & Examples
Android Application Components with Implementation & ExamplesAndroid Application Components with Implementation & Examples
Android Application Components with Implementation & ExamplesChandrakantDivate1
 
Leading Mobile App Development Companies in India (2).pdf
Leading Mobile App Development Companies in India (2).pdfLeading Mobile App Development Companies in India (2).pdf
Leading Mobile App Development Companies in India (2).pdfCWS Technology
 
Mobile Application Development-Components and Layouts
Mobile Application Development-Components and LayoutsMobile Application Development-Components and Layouts
Mobile Application Development-Components and LayoutsChandrakantDivate1
 
Mobile Application Development-Android and It’s Tools
Mobile Application Development-Android and It’s ToolsMobile Application Development-Android and It’s Tools
Mobile Application Development-Android and It’s ToolsChandrakantDivate1
 
FULL ENJOY - 9999218229 Call Girls in {Mahipalpur}| Delhi NCR
FULL ENJOY - 9999218229 Call Girls in {Mahipalpur}| Delhi NCRFULL ENJOY - 9999218229 Call Girls in {Mahipalpur}| Delhi NCR
FULL ENJOY - 9999218229 Call Girls in {Mahipalpur}| Delhi NCRnishacall1
 
9999266834 Call Girls In Noida Sector 52 (Delhi) Call Girl Service
9999266834 Call Girls In Noida Sector 52 (Delhi) Call Girl Service9999266834 Call Girls In Noida Sector 52 (Delhi) Call Girl Service
9999266834 Call Girls In Noida Sector 52 (Delhi) Call Girl Servicenishacall1
 
Thane 💋 Call Girls 7738631006 💋 Call Girls in Thane Escort service book now. ...
Thane 💋 Call Girls 7738631006 💋 Call Girls in Thane Escort service book now. ...Thane 💋 Call Girls 7738631006 💋 Call Girls in Thane Escort service book now. ...
Thane 💋 Call Girls 7738631006 💋 Call Girls in Thane Escort service book now. ...Pooja Nehwal
 

Último (8)

Android Application Components with Implementation & Examples
Android Application Components with Implementation & ExamplesAndroid Application Components with Implementation & Examples
Android Application Components with Implementation & Examples
 
Leading Mobile App Development Companies in India (2).pdf
Leading Mobile App Development Companies in India (2).pdfLeading Mobile App Development Companies in India (2).pdf
Leading Mobile App Development Companies in India (2).pdf
 
Mobile Application Development-Components and Layouts
Mobile Application Development-Components and LayoutsMobile Application Development-Components and Layouts
Mobile Application Development-Components and Layouts
 
Mobile Application Development-Android and It’s Tools
Mobile Application Development-Android and It’s ToolsMobile Application Development-Android and It’s Tools
Mobile Application Development-Android and It’s Tools
 
FULL ENJOY - 9999218229 Call Girls in {Mahipalpur}| Delhi NCR
FULL ENJOY - 9999218229 Call Girls in {Mahipalpur}| Delhi NCRFULL ENJOY - 9999218229 Call Girls in {Mahipalpur}| Delhi NCR
FULL ENJOY - 9999218229 Call Girls in {Mahipalpur}| Delhi NCR
 
9999266834 Call Girls In Noida Sector 52 (Delhi) Call Girl Service
9999266834 Call Girls In Noida Sector 52 (Delhi) Call Girl Service9999266834 Call Girls In Noida Sector 52 (Delhi) Call Girl Service
9999266834 Call Girls In Noida Sector 52 (Delhi) Call Girl Service
 
Thane 💋 Call Girls 7738631006 💋 Call Girls in Thane Escort service book now. ...
Thane 💋 Call Girls 7738631006 💋 Call Girls in Thane Escort service book now. ...Thane 💋 Call Girls 7738631006 💋 Call Girls in Thane Escort service book now. ...
Thane 💋 Call Girls 7738631006 💋 Call Girls in Thane Escort service book now. ...
 
Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)
Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)
Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)
 

Mobile display fraud is rampant beyond belief

  • 1. Mobile Display Fraud is Rampant Beyond Belief June 2018 Augustine Fou, PhD. acfou [at] mktsci.com 212. 203 .7239
  • 2. June 2018 / Page 1marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Mobile is 57% of digital spend Source: IAB Full-year 2017 Digital Advertising Report
  • 3. June 2018 / Page 2marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou "Fraud in mobile advertising is more tricky than just fake impressions, clicks, or installs. App advertisers can check when a user actually takes an action with their app after install to check legitimacy. The issue becomes which ad- network supplier gets credit for delivering that install. So attribution fraud is the major concern: where advertisers pay ad-networks, based on attribution vendor reporting, for installs that happened organically or by different marketing methods." -- Shailin Dhar, Method Media Intelligence
  • 4. June 2018 / Page 3marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Main forms of mobile fraud Install FraudImpression Fraud “fake devices installing legit apps, get paid on CPI” “fake or fraud apps load display ads, get paid CPM” Mobile display spend $25B (2017) Source: eMarketer, April 2017 App install spend $6B (2017E) Source: BusinessInsider, June 2016
  • 5. This deck focuses on mobile display fraud
  • 6. June 2018 / Page 5marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Which is easiest for bad guys? Fake Apps on Fake Devices Adware SDK in Real Apps Malware On Real Devices Limitation Wait until unsuspecting humans accidentally downloads malware on real mobile devices Limitation Wait until app developers install SDK into their real apps and humans to download and use apps. Limitation No limits - apps are easily cloned, and mobile emulators are easily “spun up” in data centers
  • 7. June 2018 / Page 6marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Half of humans download 0 apps/mo
  • 8. June 2018 / Page 7marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Apps’ primary revenue is ads In-App Advertising App Store Source: SensorTower
  • 9. June 2018 / Page 8marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou 75% mobile revenue from games Source: SensorTower
  • 10. June 2018 / Page 9marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Top mobile apps by ad revenue Top mobile apps by ad revenue Are entirely different than ones humans spend the most time with
  • 11. June 2018 / Page 10marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Massive, scalable display fraud “Judy Malware” • 40 bad apps to load ads • 36 million fake devices to load bad apps that load display ads • e.g. 30 ads per device /minute • 30 ads per minute = 1 billion fraud impressions per minute “Fireball Malware” • 250 million infected computers • primary use = traffic for ad fraud • 4 ads /pageview (2s load time) • fraudulent impressions at the rate of 30 billion per minute Source: Forbes, May 2017 Source: Checkpoint
  • 12. June 2018 / Page 11marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou (2015) Apps doing ad fraud Source: BusinessInsider, July 2015 “A user downloads an app from the official app store — which may look legitimate and have hundreds of positive reviews — which then runs in the background, serving hundreds of ads at a rate as high as 20 ads per minute” Known and documented for years – now mobile is majority of digital spend
  • 13. June 2018 / Page 12marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou (2017) Handful of bad apps 1 (52% of impressions) 2 (48% of impr) 66% avg fraud 18% avg fraud 1. 9% of the apps caused 52% of impressions; 66% outright fraud 2. Remaining 91% of apps caused 48% of impressions, 18% outright fraud • 1 billion mobile display impressions • Nearly 1,000 apps cross referenced with SDK Source: https://www.slideshare.net/augustinefou/mobile-display-fraud-case-study
  • 14. June 2018 / Page 13marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Fraud apps load impressions Source: ImpScore.io - https://www.youtube.com/watch?v=w-i-ue8fPCc “fake apps or fraud apps (real apps that misbehave) continuously load display ad impressions in the background, inflate revenue”
  • 15. June 2018 / Page 14marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou App cloning, free adware SDKs Apps are cloned thousands of times; some didn’t even bother to change the colors or cover graphics. Bad guys accidentally cloned apps that already had detection SDK in it – from 312, to 750, to 1,330 copies. Source: CNBC, Aug 2017
  • 16. June 2018 / Page 15marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Fake apps from real campaigns com.obpmirzste.ldsjpv com.zmm.shmxvjxnsagndui com.nqzwr.leusrmpmsq com.rced.zcdsglptpdlwpu com.kerms.ehlsgnc com.cmia.iabhheltm com.skggynmtx.tyyjnwpefvqtll com.kgdtltnuv.hayvfhob com.ztzsiqg.dyojlxdscxws com.xlwuqe.ddrdhsuosbn com.rkrhmzee.wjcoznxu com.ebhzb.hbzvomzpcctovj com.dxnxbgj.mkridqxviiqaogw com.obugniljhe.fptvznqwhmcjm com.bpo.ksuhpsdkgvbtlsw com.rlcznwgouw.vvtexstbfttngc com.kasbgf.sbzwtgpcbjexi com.bprlgbl.vbze com.zka.lzhsoueilo com.alxsavx.mizzucnlb com.jxknvk.lrwfdfirdzpsw com.tvwvqbt.wbshaguqy com.iwnxtpahcu.leyuehdwdbb com.okf.rhvemtykfibzpxj
  • 17. June 2018 / Page 16marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou “Naked Ad Calls” (load ad, not page) Why load the entire webpage when you can just load the ad (save bandwidth) and get paid? Pass fake data via query strings
  • 18. June 2018 / Page 17marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Apps load webpages “fraud apps sell traffic; use hidden webview browser to load pages”
  • 19. June 2018 / Page 18marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Fake app traffic – real dataRepeatedly load webpages (e.g. galleries) in sequence or random
  • 20. June 2018 / Page 19marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Apps load webpages, disguise “fraud sites’ traffic from apps that also pass fake HTTP headers” Source: SimilarWeb
  • 21. June 2018 / Page 20marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Fake devices (mobile simulators) Download and Install Apps Launch and Interact
  • 22. June 2018 / Page 21marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Fake mobile devices – real data Repeated hits by same device/browser, same ip address
  • 23. June 2018 / Page 22marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Fake devices pass fake location Houston, TX Bozeman, MT Fake devices declare fake locations to absorb higher ad spend
  • 24. June 2018 / Page 23marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou 90-99% of geolocation bad or faked Source: Placed, Sept 2017 Source: SafeGraph
  • 25. June 2018 / Page 24marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Bad guys trick measurement SDK Spoofing— code in an app that sends simulated ad clicks and engagement signals to the attribution provider … [to] fool an advertiser into paying for fraudulent impressions/views. Attribution Fraud— code that executes clicks (click spamming, click injection) so fraudster can claim credit for downstream conversions. Detection Tag Blocking— fake or fraudulent apps can selectively block fraud detection tags or manipulate analytics data.
  • 26. June 2018 / Page 25marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Mobile fraud is not caught Source: https://mumbrella.com.au/iabs- first-australian-figures-claim-just-4- of-digital-ads-fraudulent-429776 IAB: mobile fraud is “almost non-existent” “it’s NOT non-existent”
  • 27. June 2018 / Page 26marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Any device with chip/connectivity Traffic cameras turned into botnet (Engadget, Oct 2015) mobile devices webcams connected traffic lights connected cars thermostat connected fridge Security cams used as 400 Gbps DDoS botnet (Engadget, Jun 2016) …can be used as a bot
  • 28. June 2018 / Page 27marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Economics of botnets explained Source: MIT Tech Review, May 2018 “distributed denial-of-service attacks using a network of 30,000 bots can generate around $26,000 a month. Spam advertising with 10,000 bots generates around $300,000 a month, and bank fraud with 30,000 bots can generate over $18 million per month. But the most profitable undertaking is click fraud, which generates well over $20 million a month of profit.” Botnets can be used for a variety of things
  • 29. June 2018 / Page 28marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou About the Author Augustine Fou, PhD. acfou [@] mktsci.com 212. 203 .7239
  • 30. June 2018 / Page 29marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Dr. Augustine Fou – Independent Ad Fraud Researcher 2013 2014 Published slide decks and posts: http://www.slideshare.net/augustinefou/presentations https://www.linkedin.com/today/author/augustinefou 2016 2015 2017