Кіріспе
Интернеттегі жарнамадағы алаяқтық түрі. Кликке байланысты алаяқтық – төлемақы моделінде (PPC) онлайн жарнамада кездесетін алаяқтық түрі. Бұл жарнама түрінде жарнама орналастырған веб-сайт иелеріне сайтқа кірген пайдаланушылардың жарнаманы басу санына қарай төленеді. Алаяқтық орын алатын жағдайларда, адам, автоматтандырылған скрипт, компьютерлік бағдарлама немесе автоматты басу құрылғысы веб-браузердің нағыз қолданушысын имитациялап, жарнаманың мазмұнына қызығушылық танытпай, жарнамаға түйеді, осылайша кірісті арттыруға тырысады. Кликке байланысты алаяқтық – жарнама желілерінің осы алаяқтықтан пайда табуына байланысты пікірталас пен сот процестерінің көбеюіне себеп болып отыр. Медиа кәсіпкері және журналист Джон Баттелл кликке байланысты алаяқтықты жарнама берушілердің платалы іздеу жарнамасын бұрмалаудың қасақана зиянды, "қара әдіс" тәсілі деп сипаттайды. Олар роботтарды немесе аз жалақы алатын жұмысшыларды өз сайттарындағы жарнамаларды қайта-қайта басу үшін пайдаланады, соның нәтижесінде жарнама беруші жарнама берушіге және оның қызметін пайдаланатын агенттіктерге төленетін қаражатты көбейтеді.
Click fraud is a type of fraud that occurs on the Internet in pay per click (PPC) online advertising. In this type of advertising, the owners of websites that post the ads are paid based on how many site visitors click on the ads. Fraud occurs when a person, automated script, computer program or an auto clicker imitates a legitimate user of a web browser, clicking on such an ad without having an actual interest in the target of the ad's link in order to increase revenue. Click fraud is the subject of some controversy and increasing litigation due to the advertising networks being a key beneficiary of the fraud. Media entrepreneur and journalist John Battelle describes click fraud as the intentionally malicious, "decidedly black hat" practice of publishers gaming paid search advertising by employing robots or low wage workers to click on ads on their sites repeatedly, thereby generating money to be paid by the advertiser to the publisher and to any agent the advertiser may be using.
Қалтаға бір шерту үшін жарнамалау
PPC жарнамасы – веб-мастерлердің (веб-сайт операторларының) жарнама берушілерден алынған кликке арналған сілтемелерді, кликке төленетін ақы үшін көрсетуге келісуі. Осы сала дамыған сайын, жариялаушылар мен жарнама берушілер арасында делдалдық қызмет атқаратын бірнеше жарнама желілері пайда болды. Кез келген пайдаланушы жарнаманы басса, жарнама беруші жарнама желісіне ақы төлейді, ал жарнама желісі жариялаушыға осы ақшаның бір бөлігін қайтарады. Бұл кіріс бөлісу жүйесі кликтер арқылы жасалатын алаяқтыққа ынталандыру ретінде қарастырылады. Ірі жарнама желілеріне Google-дің AdWords/AdSense және Yahoo! Search Marketing жатады, олар екі қызметті де атқарады, өйткені олар өздері де жариялаушылар (өздерінің іздеу жүйелерінде). Сорбонна Бизнес мектебінің профессоры Жан Луп Рише айтқандай, кликтер арқылы жасалатын алаяқтық көбінесе жарнамалық алаяқтықтың үлкен тізбегінің бір бөлігі болып табылады және оны ірі жеке бастылық алаяқтық пен/немесе атрибуция алаяқтығының құралы ретінде пайдалануға болады. Ірі көлемдегі алаяқтықпен айналысатындар веб-беттердегі жарнамаларды басуды имитациялайтын скрипттерді жиі қолданады. Дегенмен, бір немесе аздаған компьютерлерден немесе бір географиялық аймақтан келетін көптеген кликтер жарнама желісі мен жарнама берушілерге күдіс тудырады. Сондай-ақ, жариялаушының компьютерінен жасалған кликтер кликтерді бұрмалауды қадағалайтындарға күдіс келтіреді. Бір компьютерден ірі көлемде алаяқтық жасауға тырысқан адамның ұсталу ықтималдығы жоғары. IP-адрестерді анықтауға негізделген алаяқтықтың бір түрі – қолданушының трафигін пайдаланып, оны кликтерге немесе көрсетулерге айналдыру. Мұндай шабуылды пайдаланушыларға JavaScript арқылы бағдарламалық түрде алынған жарнамаларды көрсету үшін 0 өлшемді iframe-дерді пайдалану арқылы жасыруға болады. Сондай-ақ, оны жарнама берушілер мен порталдардан жасырып, «кері жәндіктер» деп аталатын заңды бетпен көрсетуге болады, ал қарапайым келушілерге кликтер арқылы алаяқтық жасалатын бет көрсетіледі. 0 өлшемді iframe-дерді және адам келушілерін қатыстыратын басқа да әдістер ынталандырылған трафикті пайдаланумен біріктірілуі мүмкін, онда «Оқуға ақы төленген» (PTR) сайттарының мүшелеріне веб-сайтқа кіру және/немесе кілт сөздер мен іздеу нәтижелерін басу үшін аз сомада ақша төленеді, кейде күніне жүздеген немесе мыңдаған рет. PTR сайттарының кейбір иелері PPC қозғалтқыштарының мүшелері болып табылады және іздеуді жүзеге асыратын пайдаланушыларға көптеген электрондық пошта жарнамаларын жібере алады, ал іздемейтіндерге аз жарнамалар жібереді. Олар мұны негізінен іздеу нәтижелеріндегі бір клик үшін төленетін ақы ғана сайтқа түсетін табыс көзі болғандықтан жасайды. Бұл мәжбүрлі іздеу деп аталады, бұл «Ақы төлеу» индустриясындағы қабылданбас практика. Ұйымдасқан қылмыскерлер әртүрлі географиялық жерлердегі дербес интернет-қосылымдары бар көптеген компьютерлерді пайдаланып бұл мәселені шеше алады. Көбінесе скрипттер нағыз адамның әрекеттерін имитациялай алмайды, сондықтан ұйымдасқан қылмыс желілері трояндық кодты пайдаланады, ол қарапайым адамның компьютерін зомби-компьютерге айналдырады және кездейсоқ қайта бағыттауларды немесе DNS кэшін улауды пайдаланады, бұл пайдаланушының әрекеттерін алаяқтықпен табыс көретін әрекеттерге айналдырады. Жарнама берушілерге, жарнама желілеріне және билік органдарына бірнеше елге тараған адамдар желілеріне қарсы іс жүргізу қиынға соғады. Көрсету алаяқтығы – жарнаманың жалған түрде жасалған көрсетулері жарнама берушінің есебіне әсер ететін жағдай. Кликтер арқылы бағаға негізделген аукциондық модельдерде жарнама берушіге белгілі бір кілт сөз үшін қабылдауға болмайтын төмен кликтер саны үшін айыппұл салынуы мүмкін. Бұл кілт сөзді жарнаманы баспай-ақ бірнеше рет іздеуді білдіреді. Мұндай жарнамалар автоматты түрде өшіріледі, сол кілт сөз үшін бәсекелес жарнаманың төмен бағасы жалғасады, ал бірнеше жоғары баға берушілер (іздеу нәтижелерінің бірінші бетінде) жойылады.
Инфляциялық шабуылға ұшырау
Инфляциялық шабуыл – кейбір жарнама жариялаушылардың жарнама берушілердің веб-сайттарына жоналған трафик арқылы негізсіз табыс табу үшін қолданатын алаяқтық әдіс. Бұл қарапайым инфляциялық шабуылға қарағанда күрделірек және анықтау қиынырақ. Бұл процеске екі тараптың – адал емес жариялаушы P және адал емес веб-сайт S-тің қатысуы кіреді. S веб-сайтындағы веб-беттерде клиентті P веб-сайтына қайта бағыттайтын скрипт болады, бұл процесс клиенттен жасырылады. Демек, пайдаланушы U S-тегі бір бетті қараса, ол P сайтындағы бетке басу немесе сұрау салу сияқты әрекетті имитациялайды. P сайтында екі түрлі веб-бет бар: өңделген нұсқа және түпнұсқа нұсқа. Өңделген нұсқа жарнамаға басу немесе сұрау салуды имитациялайды, соның нәтижесінде P басу санатына есептеледі. P, пайдаланушы U-дың браузеріне өңделген (демек, алаяқтық) скриптті жүктеуді S-тен келген сұрау екенін тексеру арқылы таңдап жүзеге асырады. Бұл сілтеме P-ге сілтеме алынған сайтты көрсететін Referrer өрісі арқылы іске асырылуы мүмкін. S-тен келетін барлық сұраулар өңделген скриптпен жүктеледі, осылайша автоматты және жасырылған сұрау жіберіледі. Бұл шабуыл S-ке келген әрбір қарапайым келуді P бетіндегі жарнамаға басуға айналдырады. Жағдай одан да нашар, P бірнеше адал емес веб-сайттармен ынтымақтаса алады, олардың әрқайсысы бірнеше адал емес жариялаушылармен ынтымақтаса алады. Егер жарнама комиссары P веб-сайтына кірсе, алаяқтық емес бет көрсетіледі, сондықтан P-ді алаяқтық жасады деп айыптау мүмкін емес. Мұндай ынтымақтастық бар деген күдік тумаса, жарнама комиссары осындай шабуылдарды анықтау үшін барлық интернет-сайттарды тексеруі керек, бұл мүмкін емес.
Web pages on S contain a script that redirects the customer to P's Web site, and this process is hidden from the customer. So, when user U retrieves a page on S, it would simulate a click or request to a page on P's site. P's site has two kinds of webpages: a manipulated version, and an original version. The manipulated version simulates a click or request to the advertisement, causing P to be credited for the click through. P selectively determines whether to load the manipulated (and thus fraudulent) script to U's browser by checking if it was from S. This can be done through the Referrer field, which specifies the site from which the link to P was obtained. All requests from S will be loaded with the manipulated script, and thus the automatic and hidden request will be sent. This attack will silently convert every innocent visit to S to a click on the advertisement on P's page. Even worse, P can be in collaboration with several dishonest Web sites, each of which can be in collaboration with several dishonest publishers. If the advertisement commissioner visits the Web site of P, the non fraudulent page will be displayed, and thus P cannot be accused of being fraudulent. Without a reason for suspecting that such collaboration exists, the advertisement commissioner has to inspect all the Internet sites to detect such attacks, which is infeasible.
Органикалық іздеу нәтижелерін манипуляциялау
Веб-сайттардың іздеу жүйесіндегі табиғи нәтижелердегі орнын анықтаудағы маңызды факторлардың бірі – CTR (Click Through Rate), яғни кликтер мен көрсетулер арақатынасы. Бұл іздеу нәтижесіне қанша рет басқан, оның іздеу нәтижелерінде қанша рет пайда болғанымен салыстырылғандығын көрсетеді. PPC алаяқтығынан айырмасы, онда бәсекелес бот желісінің көмегімен немесе төмен құнмен жұмыс істейтін адамдарды пайдаланып, жалған кликтер жасаса, бұл жағдайда мақсат – бәсекелестерге қарсы «өзіңнің есесінен пайда табу» саясатын қолдану, олардың CTR көрсеткішін мүмкіндігінше төмендетіп, іздеу нәтижелеріндегі орнын нашарлату. Зардап келтірушілер өздеріне қажетті табиғи іздеу нәтижелеріне жалған кликтер жасап, ал қажет емес нәтижелерді төмендетуге тырысады. Бұл тәсіл бір адамның басқаруындағы бизнес-қызметтердің картелін құруға немесе белгілі бір саяси көзқарасты таратуға және т.б. қолданылуы мүмкін. Мұндай мәселенің масштабы белгісіз, бірақ веб-мастерлер құралдарындағы статистиканы мұқият қадағалайтын көптеген веб-сайтты дамытушылар үшін бұл айқын.
Сот іс-әрекеттері
Бұл мәселеге байланысты даулар бірнеше сот ісіне әкеп соқты. Бір жағдайда, Google (жарнама беруші де, жарнама желісі де ретінде әрекет ете отырып) Техас штатының Auction Experts (жариялаушы ретінде әрекет ете отырып) компаниясына қарсы сот ісінде жеңіске жетті. Google бұл компанияны Auction Experts сайтында пайда болған жарнамаларды басу үшін адамдарға ақы төлеуге айыптады, бұл жарнама берушілерге 50 000 доллар шығын келтірді. Желілер бұған тоқтамаққа тырысқанымен, жарнама желілерінің ниеттеріне жариялаушылар күмәнданады, себебі жарнама желісі әрбір басылған жарнама үшін ақша алады, тіпті ол алаяқтық болса да. 2005 жылдың шілдесінде Yahoo компаниясы оған қарсы арыз шағысу бойынша келісімге келді, онда талапкерлер оның кликтерді алаяқтықтан қорғау үшін жеткілікті шаралар қабылдамағанын айыптады. Yahoo талапкерлердің заңдық шығындары үшін 4,5 миллион доллар төледі және 2004 жылға дейінгі жарнама берушілердің талаптарын өтеуге келісті. 2006 жылдың шілдесінде Google ұқсас істі 90 миллион долларға шешті. 2006 жылдың 8 наурызында Google Lane's Gifts & Collectibles компаниясы ұсынған арыз шағысу бойынша 90 миллион доллар төлеуге келісті. Арыз шағысу ісі Миллер округіне, Арканзас штатына, Даллас адвокаттары Стив Малуф, Джоэл Файнберг және Дин Грэшем тарапынан берілді. Іс бойынша талапкерлердің сарапшы куәсі 2001 жылы PPC алаяқтығының алғашқы мысалдарына тоқтаған интернет іздеу сарапшысы Джесси Стричиола болды.
Майкл Энтони Брэдли
2004 жылы Калифорния штатының тұрғыны Майкл Энтони Брэдли Google Clique бағдарламасын жасады, ол спамдерге Google-ді жалған кликтер арқылы миллиондаған долларға алдауға мүмкіндік береді деп мәлімдеді, бұл оның қамауға алынуына және айыпталуына әкелді. Брэдли алаяқтықтың мүмкін екенін және Google-дың оны анықтауға шамасы келмейтінін көрсетті. Әділет министрлігі оның Google-ға хабарласып, егер олар технология құқықтары үшін 100 000 доллар төлемесе, оны спамдерге сататынын, соның салдарынан Google миллиондаған доллар шығынға ұшырайтынын айтқанын мәлімдеді. Осыдан кейін Брэдли 2006 жылы қорқыту және пошта арқылы алаяқтық жасағаны үшін қамауға алынды. 2006 жылғы 22 қарашада айыптаулар түсіндірілмей алынып тасталды; АҚШ прокурорының кеңсесі де, Google да ешқандай түсіндірме беруден бас тартты. Business Week журналы Google-дың сот процесімен ынтымақтасуға құлшынбағанын, себебі олар кликтерді анықтау әдістерін жария етуге мәжбүр болар еді деп болжайды.
Шешімдер
Кликті алдап алуды дәлелдеу өте қиын, өйткені компьютердің артында кім тұрғанын және олардың ниеті қандай екенін білу қиын. Мобильді жарнама алаяқтығын анықтауда деректерді талдау сенімді көрсеткіштер бере алады. Аномальды көрсеткіштер түрлі алаяқтық түрлерінің болуын көрсетеді. Жарнамалық кампаниядағы кликтерді анықтау үшін жарнама берушілер келесі атрибуция нүктелеріне назар аударуы керек:
IP Address: As bots run similar scripts from the same server, any click fraud on mobile ads will indicate a high density of clicks coming from the same IP address or a range of similar IP addresses. Advertisers can also run check on IP addresses to verify their history with another fraud. Click Timestamp: Click timestamp maintains the time at which the click is made on the ad. The bot based click fraud runs repeatedly to attempt clicking on the ads, which increases click frequency for that duration. A high range of clicks with almost similar timestamp points at the possibility of click fraud. A low duration and high frequency mean a high probability of fraud. Action Timestamp: Action timestamp is the time at which the user takes action on (or engages with) the app or website. With a bot based click attack, there can be a similarity with action timestamp. As bot clicks on the advertisement and then performs the action on app or website without any delay, the advertiser can notice a low or almost no action timestamp. Often the best an advertising network can do is to identify which clicks are most likely fraudulent and not charge the account of the advertiser. Even more sophisticated means of detection are used, but none are foolproof. The Tuzhilin Report produced by Alexander Tuzhilin as part of a click fraud lawsuit settlement, has a detailed and comprehensive discussion of these issues. In particular, it defines "the Fundamental Problem of invalid (fraudulent) clicks":
"There is no conceptual definition of invalid clicks that can be operationalized [except for certain obviously clear cases]." "An operational definition cannot be fully disclosed to the general public because of the concerns that unethical users will take advantage of it, which may lead to a massive click fraud. However, if it is not disclosed, advertisers cannot verify or even dispute why they have been charged for certain clicks." The PPC industry is lobbying for tighter laws on the issue. Many hope to have laws that will cover those not bound by contracts. A number of companies are developing viable solutions for click fraud identification and are developing intermediary relationships with advertising networks. Such solutions fall into two categories:
Forensic analysis of advertisers' web server log files. This analysis of the advertiser's web server data requires an in depth look at the source and behavior of the traffic. As industry standard log files are used for the analysis, the data is verifiable by advertising networks. The problem with this approach is that it relies on the honesty of the middlemen in identifying fraud. Third party corroboration. Third parties offer web based solutions that might involve placement of single pixel images or Javascript on the advertiser's web pages and suitable tagging of the ads. The visitor may be presented with a cookie. Visitor information is then collected in a third party data store and made available for download. The better offerings make it easy to highlight suspicious clicks, and they show the reasons for such a conclusion. Since an advertiser's log files can be tampered with, their accompaniment with corroborating data from a third party forms a more convincing body of evidence to present to the advertising network. However, the problem with third party solutions is that such solutions see only part of the traffic of the entire network. Hence, they can be less likely to identify patterns that span several advertisers. In addition, due to the limited amount of traffic they receive when compared to middlemen, they can be overly or less aggressive when judging traffic to be fraud. In a 2007 interview in Forbes, Google click fraud prevention expert Shuman Ghosemajumder said that one of the key challenges in click fraud detection by third parties was access to data beyond clicks, notably, ad impression data. Click fraud is less likely in cost per action models.
IP мекенжайы: Боттар бір серверден ұқсас скрипттерді іске қосатындықтан, мобильді жарнамалардағы кликтерді ашу бір IP мекенжайынан немесе ұқсас IP мекенжайлар диапазонынан келетін кликтердің жоғары тығыздығын көрсетеді. Жарнама берушілер басқа алаяқтықтармен байланысын тексеру үшін IP мекенжайларын да тексеруі мүмкін.
IP Address: As bots run similar scripts from the same server, any click fraud on mobile ads will indicate a high density of clicks coming from the same IP address or a range of similar IP addresses. Advertisers can also run check on IP addresses to verify their history with another fraud. Click Timestamp: Click timestamp maintains the time at which the click is made on the ad. The bot based click fraud runs repeatedly to attempt clicking on the ads, which increases click frequency for that duration. A high range of clicks with almost similar timestamp points at the possibility of click fraud. A low duration and high frequency mean a high probability of fraud. Action Timestamp: Action timestamp is the time at which the user takes action on (or engages with) the app or website. With a bot based click attack, there can be a similarity with action timestamp. As bot clicks on the advertisement and then performs the action on app or website without any delay, the advertiser can notice a low or almost no action timestamp. Often the best an advertising network can do is to identify which clicks are most likely fraudulent and not charge the account of the advertiser. Even more sophisticated means of detection are used, but none are foolproof. The Tuzhilin Report produced by Alexander Tuzhilin as part of a click fraud lawsuit settlement, has a detailed and comprehensive discussion of these issues. In particular, it defines "the Fundamental Problem of invalid (fraudulent) clicks":
"There is no conceptual definition of invalid clicks that can be operationalized [except for certain obviously clear cases]." "An operational definition cannot be fully disclosed to the general public because of the concerns that unethical users will take advantage of it, which may lead to a massive click fraud. However, if it is not disclosed, advertisers cannot verify or even dispute why they have been charged for certain clicks." The PPC industry is lobbying for tighter laws on the issue. Many hope to have laws that will cover those not bound by contracts. A number of companies are developing viable solutions for click fraud identification and are developing intermediary relationships with advertising networks. Such solutions fall into two categories:
Forensic analysis of advertisers' web server log files. This analysis of the advertiser's web server data requires an in depth look at the source and behavior of the traffic. As industry standard log files are used for the analysis, the data is verifiable by advertising networks. The problem with this approach is that it relies on the honesty of the middlemen in identifying fraud. Third party corroboration. Third parties offer web based solutions that might involve placement of single pixel images or Javascript on the advertiser's web pages and suitable tagging of the ads. The visitor may be presented with a cookie. Visitor information is then collected in a third party data store and made available for download. The better offerings make it easy to highlight suspicious clicks, and they show the reasons for such a conclusion. Since an advertiser's log files can be tampered with, their accompaniment with corroborating data from a third party forms a more convincing body of evidence to present to the advertising network. However, the problem with third party solutions is that such solutions see only part of the traffic of the entire network. Hence, they can be less likely to identify patterns that span several advertisers. In addition, due to the limited amount of traffic they receive when compared to middlemen, they can be overly or less aggressive when judging traffic to be fraud. In a 2007 interview in Forbes, Google click fraud prevention expert Shuman Ghosemajumder said that one of the key challenges in click fraud detection by third parties was access to data beyond clicks, notably, ad impression data. Click fraud is less likely in cost per action models.
Кликтің уақыт белгісі: Кликтің уақыт белгісі жарнамаға жасалған кликтің уақытын тіркеп сақтайды. Боттарға негізделген клик алаяқтығы жарнамаларды кликтеп көруге тырысу үшін қайталап орындалады, бұл сол уақыт ішінде кликтердің жиілігін арттырады. Уақыт белгілері шамалы ерекшесетін көптеген кликтер клик алаяқтығының мүмкіндігін көрсетеді. Ұзақ емес уақыт және жоғары жиілік – алаяқтық ықтималдығының жоғары деңгейі.
IP Address: As bots run similar scripts from the same server, any click fraud on mobile ads will indicate a high density of clicks coming from the same IP address or a range of similar IP addresses. Advertisers can also run check on IP addresses to verify their history with another fraud. Click Timestamp: Click timestamp maintains the time at which the click is made on the ad. The bot based click fraud runs repeatedly to attempt clicking on the ads, which increases click frequency for that duration. A high range of clicks with almost similar timestamp points at the possibility of click fraud. A low duration and high frequency mean a high probability of fraud. Action Timestamp: Action timestamp is the time at which the user takes action on (or engages with) the app or website. With a bot based click attack, there can be a similarity with action timestamp. As bot clicks on the advertisement and then performs the action on app or website without any delay, the advertiser can notice a low or almost no action timestamp. Often the best an advertising network can do is to identify which clicks are most likely fraudulent and not charge the account of the advertiser. Even more sophisticated means of detection are used, but none are foolproof. The Tuzhilin Report produced by Alexander Tuzhilin as part of a click fraud lawsuit settlement, has a detailed and comprehensive discussion of these issues. In particular, it defines "the Fundamental Problem of invalid (fraudulent) clicks":
"There is no conceptual definition of invalid clicks that can be operationalized [except for certain obviously clear cases]." "An operational definition cannot be fully disclosed to the general public because of the concerns that unethical users will take advantage of it, which may lead to a massive click fraud. However, if it is not disclosed, advertisers cannot verify or even dispute why they have been charged for certain clicks." The PPC industry is lobbying for tighter laws on the issue. Many hope to have laws that will cover those not bound by contracts. A number of companies are developing viable solutions for click fraud identification and are developing intermediary relationships with advertising networks. Such solutions fall into two categories:
Forensic analysis of advertisers' web server log files. This analysis of the advertiser's web server data requires an in depth look at the source and behavior of the traffic. As industry standard log files are used for the analysis, the data is verifiable by advertising networks. The problem with this approach is that it relies on the honesty of the middlemen in identifying fraud. Third party corroboration. Third parties offer web based solutions that might involve placement of single pixel images or Javascript on the advertiser's web pages and suitable tagging of the ads. The visitor may be presented with a cookie. Visitor information is then collected in a third party data store and made available for download. The better offerings make it easy to highlight suspicious clicks, and they show the reasons for such a conclusion. Since an advertiser's log files can be tampered with, their accompaniment with corroborating data from a third party forms a more convincing body of evidence to present to the advertising network. However, the problem with third party solutions is that such solutions see only part of the traffic of the entire network. Hence, they can be less likely to identify patterns that span several advertisers. In addition, due to the limited amount of traffic they receive when compared to middlemen, they can be overly or less aggressive when judging traffic to be fraud. In a 2007 interview in Forbes, Google click fraud prevention expert Shuman Ghosemajumder said that one of the key challenges in click fraud detection by third parties was access to data beyond clicks, notably, ad impression data. Click fraud is less likely in cost per action models.
Әрекеттің уақыт белгісі: Әрекеттің уақыт белгісі – пайдаланушының қолданба немесе веб-сайтта әрекет жасаған (немесе онымен байланысқан) уақыты. Боттарға негізделген шабуыл кезінде әрекеттің уақыт белгісінде ұқсастық болуы мүмкін. Бот жарнаманы кликтеп, кейіннен қолданбада немесе веб-сайтта кез келген кешіктірусіз әрекет жасаса, жарнама беруші аз немесе мүлдем әрекет уақыт белгісін байқауы мүмкін.
IP Address: As bots run similar scripts from the same server, any click fraud on mobile ads will indicate a high density of clicks coming from the same IP address or a range of similar IP addresses. Advertisers can also run check on IP addresses to verify their history with another fraud. Click Timestamp: Click timestamp maintains the time at which the click is made on the ad. The bot based click fraud runs repeatedly to attempt clicking on the ads, which increases click frequency for that duration. A high range of clicks with almost similar timestamp points at the possibility of click fraud. A low duration and high frequency mean a high probability of fraud. Action Timestamp: Action timestamp is the time at which the user takes action on (or engages with) the app or website. With a bot based click attack, there can be a similarity with action timestamp. As bot clicks on the advertisement and then performs the action on app or website without any delay, the advertiser can notice a low or almost no action timestamp. Often the best an advertising network can do is to identify which clicks are most likely fraudulent and not charge the account of the advertiser. Even more sophisticated means of detection are used, but none are foolproof. The Tuzhilin Report produced by Alexander Tuzhilin as part of a click fraud lawsuit settlement, has a detailed and comprehensive discussion of these issues. In particular, it defines "the Fundamental Problem of invalid (fraudulent) clicks":
"There is no conceptual definition of invalid clicks that can be operationalized [except for certain obviously clear cases]." "An operational definition cannot be fully disclosed to the general public because of the concerns that unethical users will take advantage of it, which may lead to a massive click fraud. However, if it is not disclosed, advertisers cannot verify or even dispute why they have been charged for certain clicks." The PPC industry is lobbying for tighter laws on the issue. Many hope to have laws that will cover those not bound by contracts. A number of companies are developing viable solutions for click fraud identification and are developing intermediary relationships with advertising networks. Such solutions fall into two categories:
Forensic analysis of advertisers' web server log files. This analysis of the advertiser's web server data requires an in depth look at the source and behavior of the traffic. As industry standard log files are used for the analysis, the data is verifiable by advertising networks. The problem with this approach is that it relies on the honesty of the middlemen in identifying fraud. Third party corroboration. Third parties offer web based solutions that might involve placement of single pixel images or Javascript on the advertiser's web pages and suitable tagging of the ads. The visitor may be presented with a cookie. Visitor information is then collected in a third party data store and made available for download. The better offerings make it easy to highlight suspicious clicks, and they show the reasons for such a conclusion. Since an advertiser's log files can be tampered with, their accompaniment with corroborating data from a third party forms a more convincing body of evidence to present to the advertising network. However, the problem with third party solutions is that such solutions see only part of the traffic of the entire network. Hence, they can be less likely to identify patterns that span several advertisers. In addition, due to the limited amount of traffic they receive when compared to middlemen, they can be overly or less aggressive when judging traffic to be fraud. In a 2007 interview in Forbes, Google click fraud prevention expert Shuman Ghosemajumder said that one of the key challenges in click fraud detection by third parties was access to data beyond clicks, notably, ad impression data. Click fraud is less likely in cost per action models.
Жарнама желісі көбінесе қай кликтердің алаяқтық екенін анықтап, жарнама берушінің шотын есептен шығармайды. Одан да күрделі әдістер қолданылады, бірақ олардың ешқайсысы да қателіксіз емес. Александр Тужилиннің клик алаяқтығына қатысты сот ісі аясында жасаған "Тузгилин есебінде" осы мәселелерге қатысты егжей-тегжейлі және жан-жақты талқылау бар. Атап айтқанда, ол "жарамсыз (алдамшы) кликтердің негізгі мәселесін" анықтайды: "Жарамсыз кликтердің тұжырымдамалық анықтамасы жоқ, оны іске асыруға болады [айқын белгілі бір жағдайларды қоспағанда]". "Операциялық анықтама этикалық емес пайдаланушылар оны пайдаланып, үлкен клик алаяқтығына әкелуі мүмкін болғандықтан, жалпы жұртшылыққа толық ашыла алмайды. Алайда, егер бұл ақпарат жарияланбаса, жарнама берушілер белгілі бір кликтер үшін неге ақы төленгенін тексеріп, тіпті даулай алмайды". PPC индустриясы бұл мәселе бойынша қатаң заңдарды қабылдауға үгіт-насихат жүргізеді. Көптеген адамдар келісімшартпен байланысты емес адамдарды қамтитын заңдар болады деп үміттенеді. Бірқатар компаниялар клик алаяқтығын анықтау үшін тиімді шешімдерді әзірлеп, жарнама желілерімен де аралық қатынастар құруда. Мұндай шешімдер екі топқа бөлінеді:
IP Address: As bots run similar scripts from the same server, any click fraud on mobile ads will indicate a high density of clicks coming from the same IP address or a range of similar IP addresses. Advertisers can also run check on IP addresses to verify their history with another fraud. Click Timestamp: Click timestamp maintains the time at which the click is made on the ad. The bot based click fraud runs repeatedly to attempt clicking on the ads, which increases click frequency for that duration. A high range of clicks with almost similar timestamp points at the possibility of click fraud. A low duration and high frequency mean a high probability of fraud. Action Timestamp: Action timestamp is the time at which the user takes action on (or engages with) the app or website. With a bot based click attack, there can be a similarity with action timestamp. As bot clicks on the advertisement and then performs the action on app or website without any delay, the advertiser can notice a low or almost no action timestamp. Often the best an advertising network can do is to identify which clicks are most likely fraudulent and not charge the account of the advertiser. Even more sophisticated means of detection are used, but none are foolproof. The Tuzhilin Report produced by Alexander Tuzhilin as part of a click fraud lawsuit settlement, has a detailed and comprehensive discussion of these issues. In particular, it defines "the Fundamental Problem of invalid (fraudulent) clicks":
"There is no conceptual definition of invalid clicks that can be operationalized [except for certain obviously clear cases]." "An operational definition cannot be fully disclosed to the general public because of the concerns that unethical users will take advantage of it, which may lead to a massive click fraud. However, if it is not disclosed, advertisers cannot verify or even dispute why they have been charged for certain clicks." The PPC industry is lobbying for tighter laws on the issue. Many hope to have laws that will cover those not bound by contracts. A number of companies are developing viable solutions for click fraud identification and are developing intermediary relationships with advertising networks. Such solutions fall into two categories:
Forensic analysis of advertisers' web server log files. This analysis of the advertiser's web server data requires an in depth look at the source and behavior of the traffic. As industry standard log files are used for the analysis, the data is verifiable by advertising networks. The problem with this approach is that it relies on the honesty of the middlemen in identifying fraud. Third party corroboration. Third parties offer web based solutions that might involve placement of single pixel images or Javascript on the advertiser's web pages and suitable tagging of the ads. The visitor may be presented with a cookie. Visitor information is then collected in a third party data store and made available for download. The better offerings make it easy to highlight suspicious clicks, and they show the reasons for such a conclusion. Since an advertiser's log files can be tampered with, their accompaniment with corroborating data from a third party forms a more convincing body of evidence to present to the advertising network. However, the problem with third party solutions is that such solutions see only part of the traffic of the entire network. Hence, they can be less likely to identify patterns that span several advertisers. In addition, due to the limited amount of traffic they receive when compared to middlemen, they can be overly or less aggressive when judging traffic to be fraud. In a 2007 interview in Forbes, Google click fraud prevention expert Shuman Ghosemajumder said that one of the key challenges in click fraud detection by third parties was access to data beyond clicks, notably, ad impression data. Click fraud is less likely in cost per action models.
Жарнама берушілердің веб-сервер журналдарын криминалистік талдау. Жарнама берушінің веб-сервер деректерін талдау трафиктің көзі мен мінез-құлқын терең зерттеуді қажет етеді. Тәжірибеде қолданылатын стандартты журнал файлдары талдау үшін пайдаланылғандықтан, деректерді жарнама желілері тексеруге болады. Бұл тәсілдің қиындығы – ол алаяқтықты анықтау үшін делдалдардың адал болуына тәуелді.
IP Address: As bots run similar scripts from the same server, any click fraud on mobile ads will indicate a high density of clicks coming from the same IP address or a range of similar IP addresses. Advertisers can also run check on IP addresses to verify their history with another fraud. Click Timestamp: Click timestamp maintains the time at which the click is made on the ad. The bot based click fraud runs repeatedly to attempt clicking on the ads, which increases click frequency for that duration. A high range of clicks with almost similar timestamp points at the possibility of click fraud. A low duration and high frequency mean a high probability of fraud. Action Timestamp: Action timestamp is the time at which the user takes action on (or engages with) the app or website. With a bot based click attack, there can be a similarity with action timestamp. As bot clicks on the advertisement and then performs the action on app or website without any delay, the advertiser can notice a low or almost no action timestamp. Often the best an advertising network can do is to identify which clicks are most likely fraudulent and not charge the account of the advertiser. Even more sophisticated means of detection are used, but none are foolproof. The Tuzhilin Report produced by Alexander Tuzhilin as part of a click fraud lawsuit settlement, has a detailed and comprehensive discussion of these issues. In particular, it defines "the Fundamental Problem of invalid (fraudulent) clicks":
"There is no conceptual definition of invalid clicks that can be operationalized [except for certain obviously clear cases]." "An operational definition cannot be fully disclosed to the general public because of the concerns that unethical users will take advantage of it, which may lead to a massive click fraud. However, if it is not disclosed, advertisers cannot verify or even dispute why they have been charged for certain clicks." The PPC industry is lobbying for tighter laws on the issue. Many hope to have laws that will cover those not bound by contracts. A number of companies are developing viable solutions for click fraud identification and are developing intermediary relationships with advertising networks. Such solutions fall into two categories:
Forensic analysis of advertisers' web server log files. This analysis of the advertiser's web server data requires an in depth look at the source and behavior of the traffic. As industry standard log files are used for the analysis, the data is verifiable by advertising networks. The problem with this approach is that it relies on the honesty of the middlemen in identifying fraud. Third party corroboration. Third parties offer web based solutions that might involve placement of single pixel images or Javascript on the advertiser's web pages and suitable tagging of the ads. The visitor may be presented with a cookie. Visitor information is then collected in a third party data store and made available for download. The better offerings make it easy to highlight suspicious clicks, and they show the reasons for such a conclusion. Since an advertiser's log files can be tampered with, their accompaniment with corroborating data from a third party forms a more convincing body of evidence to present to the advertising network. However, the problem with third party solutions is that such solutions see only part of the traffic of the entire network. Hence, they can be less likely to identify patterns that span several advertisers. In addition, due to the limited amount of traffic they receive when compared to middlemen, they can be overly or less aggressive when judging traffic to be fraud. In a 2007 interview in Forbes, Google click fraud prevention expert Shuman Ghosemajumder said that one of the key challenges in click fraud detection by third parties was access to data beyond clicks, notably, ad impression data. Click fraud is less likely in cost per action models.
Үшінші тараптың растауы. Үшінші тараптар веб-базалық шешімдер ұсынады, олар жарнама беруші веб-беттерінде бір пикселдік суреттерді немесе Javascript орналастыруды және жарнамаларды тиісті тегтеуді қамтуы мүмкін. Келушіге cookie ұсынылуы мүмкін. Келушілер туралы ақпарат үшінші тараптың деректер қоймасында жиналады және жүктеуге қолжетімді болады. Жақсырақ ұсыныстар күдікті кликтерді анықтауға мүмкіндік береді және осындай қорытындының себептерін көрсетеді. Жарнама берушінің журналдарына қол сұғылуы мүмкін болғандықтан, оларды үшінші тараптан алынған растау деректерімен қоса беру жарнама желісіне ұсынуға арналған дәлелдемелерді сенімді етеді. Алайда үшінші тарап шешімдерімен проблемасы – мұндай шешімдер бүкіл желідегі трафиктің бір бөлігін ғана көреді. Сондықтан олар бірнеше жарнама берушілердің арасындағы үлгілерді анықтай алмайды. Сонымен қатар, олардың трафигі араласпен салыстырғанда аз болғандықтан, трафикті алаяқтық деп бағалай отырып, олар тым агрессивті немесе аз агрессивті болуы мүмкін. 2007 жылы Forbes журналына берген сұхбатында Google-дың клик алаяқтығын болдырмау жөніндегі сарапшысы Шуман Госемажумдер үшінші тараптардың клик алаяқтығын анықтаудағы басты қиындықтардың бірі – клик деректерінен басқа деректерге қол жеткізу екенін айтты, атап айтқанда, жарнама көрсету деректеріне.
IP Address: As bots run similar scripts from the same server, any click fraud on mobile ads will indicate a high density of clicks coming from the same IP address or a range of similar IP addresses. Advertisers can also run check on IP addresses to verify their history with another fraud. Click Timestamp: Click timestamp maintains the time at which the click is made on the ad. The bot based click fraud runs repeatedly to attempt clicking on the ads, which increases click frequency for that duration. A high range of clicks with almost similar timestamp points at the possibility of click fraud. A low duration and high frequency mean a high probability of fraud. Action Timestamp: Action timestamp is the time at which the user takes action on (or engages with) the app or website. With a bot based click attack, there can be a similarity with action timestamp. As bot clicks on the advertisement and then performs the action on app or website without any delay, the advertiser can notice a low or almost no action timestamp. Often the best an advertising network can do is to identify which clicks are most likely fraudulent and not charge the account of the advertiser. Even more sophisticated means of detection are used, but none are foolproof. The Tuzhilin Report produced by Alexander Tuzhilin as part of a click fraud lawsuit settlement, has a detailed and comprehensive discussion of these issues. In particular, it defines "the Fundamental Problem of invalid (fraudulent) clicks":
"There is no conceptual definition of invalid clicks that can be operationalized [except for certain obviously clear cases]." "An operational definition cannot be fully disclosed to the general public because of the concerns that unethical users will take advantage of it, which may lead to a massive click fraud. However, if it is not disclosed, advertisers cannot verify or even dispute why they have been charged for certain clicks." The PPC industry is lobbying for tighter laws on the issue. Many hope to have laws that will cover those not bound by contracts. A number of companies are developing viable solutions for click fraud identification and are developing intermediary relationships with advertising networks. Such solutions fall into two categories:
Forensic analysis of advertisers' web server log files. This analysis of the advertiser's web server data requires an in depth look at the source and behavior of the traffic. As industry standard log files are used for the analysis, the data is verifiable by advertising networks. The problem with this approach is that it relies on the honesty of the middlemen in identifying fraud. Third party corroboration. Third parties offer web based solutions that might involve placement of single pixel images or Javascript on the advertiser's web pages and suitable tagging of the ads. The visitor may be presented with a cookie. Visitor information is then collected in a third party data store and made available for download. The better offerings make it easy to highlight suspicious clicks, and they show the reasons for such a conclusion. Since an advertiser's log files can be tampered with, their accompaniment with corroborating data from a third party forms a more convincing body of evidence to present to the advertising network. However, the problem with third party solutions is that such solutions see only part of the traffic of the entire network. Hence, they can be less likely to identify patterns that span several advertisers. In addition, due to the limited amount of traffic they receive when compared to middlemen, they can be overly or less aggressive when judging traffic to be fraud. In a 2007 interview in Forbes, Google click fraud prevention expert Shuman Ghosemajumder said that one of the key challenges in click fraud detection by third parties was access to data beyond clicks, notably, ad impression data. Click fraud is less likely in cost per action models.
Құн төленген әрекеттер моделінде клик алаяқтығы аз болуы мүмкін.
IP Address: As bots run similar scripts from the same server, any click fraud on mobile ads will indicate a high density of clicks coming from the same IP address or a range of similar IP addresses. Advertisers can also run check on IP addresses to verify their history with another fraud. Click Timestamp: Click timestamp maintains the time at which the click is made on the ad. The bot based click fraud runs repeatedly to attempt clicking on the ads, which increases click frequency for that duration. A high range of clicks with almost similar timestamp points at the possibility of click fraud. A low duration and high frequency mean a high probability of fraud. Action Timestamp: Action timestamp is the time at which the user takes action on (or engages with) the app or website. With a bot based click attack, there can be a similarity with action timestamp. As bot clicks on the advertisement and then performs the action on app or website without any delay, the advertiser can notice a low or almost no action timestamp. Often the best an advertising network can do is to identify which clicks are most likely fraudulent and not charge the account of the advertiser. Even more sophisticated means of detection are used, but none are foolproof. The Tuzhilin Report produced by Alexander Tuzhilin as part of a click fraud lawsuit settlement, has a detailed and comprehensive discussion of these issues. In particular, it defines "the Fundamental Problem of invalid (fraudulent) clicks":
"There is no conceptual definition of invalid clicks that can be operationalized [except for certain obviously clear cases]." "An operational definition cannot be fully disclosed to the general public because of the concerns that unethical users will take advantage of it, which may lead to a massive click fraud. However, if it is not disclosed, advertisers cannot verify or even dispute why they have been charged for certain clicks." The PPC industry is lobbying for tighter laws on the issue. Many hope to have laws that will cover those not bound by contracts. A number of companies are developing viable solutions for click fraud identification and are developing intermediary relationships with advertising networks. Such solutions fall into two categories:
Forensic analysis of advertisers' web server log files. This analysis of the advertiser's web server data requires an in depth look at the source and behavior of the traffic. As industry standard log files are used for the analysis, the data is verifiable by advertising networks. The problem with this approach is that it relies on the honesty of the middlemen in identifying fraud. Third party corroboration. Third parties offer web based solutions that might involve placement of single pixel images or Javascript on the advertiser's web pages and suitable tagging of the ads. The visitor may be presented with a cookie. Visitor information is then collected in a third party data store and made available for download. The better offerings make it easy to highlight suspicious clicks, and they show the reasons for such a conclusion. Since an advertiser's log files can be tampered with, their accompaniment with corroborating data from a third party forms a more convincing body of evidence to present to the advertising network. However, the problem with third party solutions is that such solutions see only part of the traffic of the entire network. Hence, they can be less likely to identify patterns that span several advertisers. In addition, due to the limited amount of traffic they receive when compared to middlemen, they can be overly or less aggressive when judging traffic to be fraud. In a 2007 interview in Forbes, Google click fraud prevention expert Shuman Ghosemajumder said that one of the key challenges in click fraud detection by third parties was access to data beyond clicks, notably, ad impression data. Click fraud is less likely in cost per action models.
Зерттеу
Жарнама берушілер мен аралық делдалдар арасындағы мүдделер қақтығысының себебі – жарамсыз шертулерді анықтаудың практикалық шарттарында іздестіру жүйелері сияқты аралық делдалдардың үстемдік құқығында. Бұл мәселе Тужилин есебінде сипатталған. Мұндай зерттеулер нарықтық күштердің ықпалынан тыс болғандықтан, болашақ сот ісінде аралық делдалдың шерту алаятын қаншалықты қатаң анықтайтынын бағалау үшін осы зерттеулерді пайдалануға үміт бар. Дегенмен, бұл зерттеулер делдалдардың ішкі алаяққа қарсы жүйесін жария етуі мүмкін деген қауіп әлі де сақталады. Мұндай зерттеулердің мысалы – Метвали, Агравал және Эль Аббадидің UCSB-де жүргізген жұмыстары. Ал UC Riverside-дегі Маджумдар, Кулкарни және Равишанкардың басқа жұмыстары контент жеткізу желілеріндегі брокерлер мен басқа да аралық делдалдардың алаяқтық қызметін анықтауға арналған процедураларды ұсынады.