SlideShare une entreprise Scribd logo
1  sur  30
Télécharger pour lire hors ligne
Mobile Display Fraud
is Rampant Beyond Belief
June 2018
Augustine Fou, PhD.
acfou [at] mktsci.com
212. 203 .7239
June 2018 / Page 1marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Mobile is 57% of digital spend
Source: IAB Full-year 2017 Digital Advertising Report
June 2018 / Page 2marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
"Fraud in mobile advertising is more tricky than just fake
impressions, clicks, or installs. App advertisers can check
when a user actually takes an action with their app after
install to check legitimacy. The issue becomes which ad-
network supplier gets credit for delivering that install. So
attribution fraud is the major concern: where advertisers
pay ad-networks, based on attribution vendor reporting, for
installs that happened organically or by different marketing
methods." -- Shailin Dhar, Method Media Intelligence
June 2018 / Page 3marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Main forms of mobile fraud
Install FraudImpression Fraud
“fake devices installing legit
apps, get paid on CPI”
“fake or fraud apps load
display ads, get paid CPM”
Mobile display spend $25B (2017)
Source: eMarketer, April 2017
App install spend $6B (2017E)
Source: BusinessInsider, June 2016
This deck focuses on
mobile display fraud
June 2018 / Page 5marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Which is easiest for bad guys?
Fake Apps on
Fake Devices
Adware SDK in
Real Apps
Malware On
Real Devices
Limitation
Wait until unsuspecting
humans accidentally
downloads malware on
real mobile devices
Limitation
Wait until app developers
install SDK into their real
apps and humans to
download and use apps.
Limitation
No limits - apps are easily
cloned, and mobile
emulators are easily
“spun up” in data centers
June 2018 / Page 6marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Half of humans download 0 apps/mo
June 2018 / Page 7marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Apps’ primary revenue is ads
In-App
Advertising
App Store
Source: SensorTower
June 2018 / Page 8marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
75% mobile revenue from games
Source: SensorTower
June 2018 / Page 9marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Top mobile apps by ad revenue
Top mobile apps
by ad revenue
Are entirely
different than
ones humans
spend the most
time with
June 2018 / Page 10marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Massive, scalable display fraud
“Judy Malware”
• 40 bad apps to load ads
• 36 million fake devices to load
bad apps that load display ads
• e.g. 30 ads per device /minute
• 30 ads per minute = 1 billion
fraud impressions per minute
“Fireball Malware”
• 250 million infected computers
• primary use = traffic for ad fraud
• 4 ads /pageview (2s load time)
• fraudulent impressions at the
rate of 30 billion per minute
Source: Forbes, May 2017 Source: Checkpoint
June 2018 / Page 11marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
(2015) Apps doing ad fraud
Source: BusinessInsider, July 2015
“A user downloads an app
from the official app store
— which may look
legitimate and have
hundreds of positive reviews
— which then runs in the
background, serving
hundreds of ads at a rate as
high as 20 ads per minute”
Known and documented
for years – now mobile is
majority of digital spend
June 2018 / Page 12marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
(2017) Handful of bad apps
1 (52% of impressions) 2 (48% of impr)
66% avg fraud
18% avg fraud
1. 9% of the apps caused 52% of impressions; 66% outright fraud
2. Remaining 91% of apps caused 48% of impressions, 18% outright fraud
• 1 billion mobile display impressions
• Nearly 1,000 apps cross referenced with SDK
Source: https://www.slideshare.net/augustinefou/mobile-display-fraud-case-study
June 2018 / Page 13marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Fraud apps load impressions
Source: ImpScore.io - https://www.youtube.com/watch?v=w-i-ue8fPCc
“fake apps or fraud apps (real apps that misbehave) continuously
load display ad impressions in the background, inflate revenue”
June 2018 / Page 14marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
App cloning, free adware SDKs
Apps are cloned
thousands of times;
some didn’t even
bother to change
the colors or cover
graphics.
Bad guys accidentally
cloned apps that
already had detection
SDK in it – from 312, to
750, to 1,330 copies.
Source: CNBC, Aug 2017
June 2018 / Page 15marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Fake apps from real campaigns
com.obpmirzste.ldsjpv
com.zmm.shmxvjxnsagndui
com.nqzwr.leusrmpmsq
com.rced.zcdsglptpdlwpu
com.kerms.ehlsgnc
com.cmia.iabhheltm
com.skggynmtx.tyyjnwpefvqtll
com.kgdtltnuv.hayvfhob
com.ztzsiqg.dyojlxdscxws
com.xlwuqe.ddrdhsuosbn
com.rkrhmzee.wjcoznxu
com.ebhzb.hbzvomzpcctovj
com.dxnxbgj.mkridqxviiqaogw
com.obugniljhe.fptvznqwhmcjm
com.bpo.ksuhpsdkgvbtlsw
com.rlcznwgouw.vvtexstbfttngc
com.kasbgf.sbzwtgpcbjexi
com.bprlgbl.vbze
com.zka.lzhsoueilo
com.alxsavx.mizzucnlb
com.jxknvk.lrwfdfirdzpsw
com.tvwvqbt.wbshaguqy
com.iwnxtpahcu.leyuehdwdbb
com.okf.rhvemtykfibzpxj
June 2018 / Page 16marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
“Naked Ad Calls” (load ad, not page)
Why load the entire webpage when you can just
load the ad (save bandwidth) and get paid?
Pass fake data
via query strings
June 2018 / Page 17marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Apps load webpages
“fraud apps sell traffic; use hidden webview browser to load pages”
June 2018 / Page 18marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Fake app traffic – real dataRepeatedly load webpages (e.g. galleries) in sequence or random
June 2018 / Page 19marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Apps load webpages, disguise
“fraud sites’ traffic from apps that also pass fake HTTP headers”
Source: SimilarWeb
June 2018 / Page 20marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Fake devices (mobile simulators)
Download and Install Apps
Launch and Interact
June 2018 / Page 21marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Fake mobile devices – real data
Repeated hits by same device/browser, same ip address
June 2018 / Page 22marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Fake devices pass fake location
Houston, TX Bozeman, MT
Fake devices declare fake locations to absorb higher ad spend
June 2018 / Page 23marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
90-99% of geolocation bad or faked
Source: Placed, Sept 2017
Source: SafeGraph
June 2018 / Page 24marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Bad guys trick measurement
SDK Spoofing— code in an app that sends simulated ad
clicks and engagement signals to the attribution provider
… [to] fool an advertiser into paying for fraudulent
impressions/views.
Attribution Fraud— code that executes clicks (click
spamming, click injection) so fraudster can claim credit
for downstream conversions.
Detection Tag Blocking— fake or fraudulent apps can
selectively block fraud detection tags or manipulate
analytics data.
June 2018 / Page 25marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Mobile fraud is not caught
Source:
https://mumbrella.com.au/iabs-
first-australian-figures-claim-just-4-
of-digital-ads-fraudulent-429776
IAB: mobile fraud is
“almost non-existent”
“it’s NOT
non-existent”
June 2018 / Page 26marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Any device with chip/connectivity
Traffic cameras
turned into
botnet (Engadget,
Oct 2015)
mobile devices
webcams
connected
traffic lights
connected cars
thermostat
connected fridge
Security cams
used as 400
Gbps DDoS
botnet (Engadget,
Jun 2016)
…can be used as a bot
June 2018 / Page 27marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Economics of botnets explained
Source: MIT Tech Review, May 2018
“distributed denial-of-service
attacks using a network of 30,000
bots can generate around
$26,000 a month. Spam
advertising with 10,000 bots
generates around $300,000 a
month, and bank fraud with
30,000 bots can generate over
$18 million per month. But the
most profitable undertaking is
click fraud, which generates well
over $20 million a month of
profit.”
Botnets can be used
for a variety of things
June 2018 / Page 28marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
About the Author
Augustine Fou, PhD.
acfou [@] mktsci.com
212. 203 .7239
June 2018 / Page 29marketing.scienceconsulting group, inc.
linkedin.com/in/augustinefou
Dr. Augustine Fou – Independent Ad Fraud Researcher
2013
2014
Published slide decks and posts:
http://www.slideshare.net/augustinefou/presentations
https://www.linkedin.com/today/author/augustinefou
2016
2015
2017

Contenu connexe

Tendances

Suzuki Violin Method Vol 01
Suzuki Violin Method   Vol 01Suzuki Violin Method   Vol 01
Suzuki Violin Method Vol 01
Orquesta2009
 
Cambridge academic english upper intermediate student's book ( pdf drive.com )
Cambridge academic english upper intermediate student's book ( pdf drive.com )Cambridge academic english upper intermediate student's book ( pdf drive.com )
Cambridge academic english upper intermediate student's book ( pdf drive.com )
Dammar Singh Saud
 
Strategic Analysis of Facebook
Strategic Analysis of FacebookStrategic Analysis of Facebook
Strategic Analysis of Facebook
Vishal Sharma
 

Tendances (11)

Vietnam edtech-elearning-report-2021-tam
Vietnam edtech-elearning-report-2021-tamVietnam edtech-elearning-report-2021-tam
Vietnam edtech-elearning-report-2021-tam
 
Suzuki Violin Method Vol 01
Suzuki Violin Method   Vol 01Suzuki Violin Method   Vol 01
Suzuki Violin Method Vol 01
 
Cambridge academic english upper intermediate student's book ( pdf drive.com )
Cambridge academic english upper intermediate student's book ( pdf drive.com )Cambridge academic english upper intermediate student's book ( pdf drive.com )
Cambridge academic english upper intermediate student's book ( pdf drive.com )
 
Digital in 2016 Vietnam - We Are Social
Digital in 2016 Vietnam -  We Are SocialDigital in 2016 Vietnam -  We Are Social
Digital in 2016 Vietnam - We Are Social
 
Báo cáo Think Consumer Health - Google Webinar 2021
Báo cáo Think Consumer Health - Google Webinar 2021Báo cáo Think Consumer Health - Google Webinar 2021
Báo cáo Think Consumer Health - Google Webinar 2021
 
Shan e kainat pdf book.Hazrat Allama Saim Chishti. urdu punjabi naatia poetry
Shan e kainat pdf book.Hazrat Allama Saim Chishti. urdu punjabi naatia poetryShan e kainat pdf book.Hazrat Allama Saim Chishti. urdu punjabi naatia poetry
Shan e kainat pdf book.Hazrat Allama Saim Chishti. urdu punjabi naatia poetry
 
Space Invaders Africa
Space Invaders AfricaSpace Invaders Africa
Space Invaders Africa
 
Shift AI 2020: How to identify and treat biases in ML Models | Navdeep Sharma...
Shift AI 2020: How to identify and treat biases in ML Models | Navdeep Sharma...Shift AI 2020: How to identify and treat biases in ML Models | Navdeep Sharma...
Shift AI 2020: How to identify and treat biases in ML Models | Navdeep Sharma...
 
Strategic Analysis of Facebook
Strategic Analysis of FacebookStrategic Analysis of Facebook
Strategic Analysis of Facebook
 
Curso de Marketing Digital, Mãe, to no Google.
Curso de Marketing Digital, Mãe, to no Google.Curso de Marketing Digital, Mãe, to no Google.
Curso de Marketing Digital, Mãe, to no Google.
 
Space Invaders Cologne
Space Invaders CologneSpace Invaders Cologne
Space Invaders Cologne
 

Similaire à Mobile display fraud is rampant beyond belief

Similaire à Mobile display fraud is rampant beyond belief (20)

State of Digital Ad Fraud Q4 2018
State of Digital Ad Fraud Q4 2018State of Digital Ad Fraud Q4 2018
State of Digital Ad Fraud Q4 2018
 
Why Fraud detection doesn't work
Why Fraud detection doesn't workWhy Fraud detection doesn't work
Why Fraud detection doesn't work
 
Digital ad fraud impact on class action notice industry
Digital ad fraud impact on class action notice industryDigital ad fraud impact on class action notice industry
Digital ad fraud impact on class action notice industry
 
State of Digital Ad Fraud Q2 2018
State of Digital Ad Fraud Q2 2018State of Digital Ad Fraud Q2 2018
State of Digital Ad Fraud Q2 2018
 
What CFEs can do about digital ad fraud
What CFEs can do about digital ad fraudWhat CFEs can do about digital ad fraud
What CFEs can do about digital ad fraud
 
Procurement to Help Fight Ad Fraud
Procurement to Help Fight Ad FraudProcurement to Help Fight Ad Fraud
Procurement to Help Fight Ad Fraud
 
How Brands are Solving Ad Fraud Themselves
How Brands are Solving Ad Fraud ThemselvesHow Brands are Solving Ad Fraud Themselves
How Brands are Solving Ad Fraud Themselves
 
Mobile Ad Fraud - Betcha Didn't Know
Mobile Ad Fraud - Betcha Didn't KnowMobile Ad Fraud - Betcha Didn't Know
Mobile Ad Fraud - Betcha Didn't Know
 
Low-Cost, No-Tech Ways to Fight Fraud vMiMA
Low-Cost, No-Tech Ways to Fight Fraud vMiMALow-Cost, No-Tech Ways to Fight Fraud vMiMA
Low-Cost, No-Tech Ways to Fight Fraud vMiMA
 
State of Digital Ad Fraud Q2 2017 by Augustine Fou
State of Digital Ad Fraud Q2 2017 by Augustine FouState of Digital Ad Fraud Q2 2017 by Augustine Fou
State of Digital Ad Fraud Q2 2017 by Augustine Fou
 
State of digital ad fraud 2017 by augustine fou
State of digital ad fraud 2017 by augustine fouState of digital ad fraud 2017 by augustine fou
State of digital ad fraud 2017 by augustine fou
 
DMA_PPT_Analytics FINAL Sept 2017
DMA_PPT_Analytics FINAL Sept 2017DMA_PPT_Analytics FINAL Sept 2017
DMA_PPT_Analytics FINAL Sept 2017
 
Hidden Costs in Digital Media Supply Path
Hidden Costs in Digital Media Supply PathHidden Costs in Digital Media Supply Path
Hidden Costs in Digital Media Supply Path
 
Investigating digital ad fraud spi virtual meeting
Investigating digital ad fraud   spi virtual meetingInvestigating digital ad fraud   spi virtual meeting
Investigating digital ad fraud spi virtual meeting
 
Marketers Take Control Run Experiments
Marketers Take Control Run ExperimentsMarketers Take Control Run Experiments
Marketers Take Control Run Experiments
 
Unintended Consequences for Publishers using Adtech
Unintended Consequences for Publishers using AdtechUnintended Consequences for Publishers using Adtech
Unintended Consequences for Publishers using Adtech
 
Marketers' Playbook Questions to Ask Verification Vendors
Marketers' Playbook   Questions to Ask Verification VendorsMarketers' Playbook   Questions to Ask Verification Vendors
Marketers' Playbook Questions to Ask Verification Vendors
 
Where the Wild Bots are OPSNY June 2016
Where the Wild Bots are OPSNY June 2016Where the Wild Bots are OPSNY June 2016
Where the Wild Bots are OPSNY June 2016
 
Fraud Detection is Easily Fooled
Fraud Detection is Easily FooledFraud Detection is Easily Fooled
Fraud Detection is Easily Fooled
 
Good Publishers Will Save Digital Marketing v2019
Good Publishers Will Save Digital Marketing v2019Good Publishers Will Save Digital Marketing v2019
Good Publishers Will Save Digital Marketing v2019
 

Plus de Dr. Augustine Fou - Independent Ad Fraud Researcher

Plus de Dr. Augustine Fou - Independent Ad Fraud Researcher (20)

Q1 2022 Update on ad fraud for AMM
Q1 2022 Update on ad fraud for AMMQ1 2022 Update on ad fraud for AMM
Q1 2022 Update on ad fraud for AMM
 
Ad blocking benchmarks q4 2021
Ad blocking benchmarks q4 2021Ad blocking benchmarks q4 2021
Ad blocking benchmarks q4 2021
 
Digital ad dollars trickle down chart
Digital ad dollars trickle down chartDigital ad dollars trickle down chart
Digital ad dollars trickle down chart
 
Still nothing but ad fraud 2021 dr augustine fou
Still nothing but ad fraud 2021 dr augustine fouStill nothing but ad fraud 2021 dr augustine fou
Still nothing but ad fraud 2021 dr augustine fou
 
Bad guys optimize ad fraud efficiency
Bad guys optimize ad fraud efficiencyBad guys optimize ad fraud efficiency
Bad guys optimize ad fraud efficiency
 
Impact of Loss of 3P Cookies on Publishers' Ad Revenue
Impact of Loss of 3P Cookies on Publishers' Ad RevenueImpact of Loss of 3P Cookies on Publishers' Ad Revenue
Impact of Loss of 3P Cookies on Publishers' Ad Revenue
 
Entire ecosystem supporting ad fraud 2018
Entire ecosystem supporting ad fraud 2018Entire ecosystem supporting ad fraud 2018
Entire ecosystem supporting ad fraud 2018
 
Digital Media Trust Collaborative
Digital Media Trust CollaborativeDigital Media Trust Collaborative
Digital Media Trust Collaborative
 
Programmatic reach analysis 2021
Programmatic reach analysis 2021Programmatic reach analysis 2021
Programmatic reach analysis 2021
 
2021 update on ad fraud brand safety privacy
2021 update on ad fraud brand safety privacy2021 update on ad fraud brand safety privacy
2021 update on ad fraud brand safety privacy
 
Browser and OS Share Jan 2021
Browser and OS Share Jan 2021Browser and OS Share Jan 2021
Browser and OS Share Jan 2021
 
Checking abnormal referrer traffic in google analytics
Checking abnormal referrer traffic in google analyticsChecking abnormal referrer traffic in google analytics
Checking abnormal referrer traffic in google analytics
 
History and Impact of Digital Ad Fraud
History and Impact of Digital Ad FraudHistory and Impact of Digital Ad Fraud
History and Impact of Digital Ad Fraud
 
Digital Fraud Viewability Benchmarks Q4 2020
Digital Fraud Viewability Benchmarks Q4 2020Digital Fraud Viewability Benchmarks Q4 2020
Digital Fraud Viewability Benchmarks Q4 2020
 
Four types of digital ad spend updated august 2020
Four types of digital ad spend updated august 2020Four types of digital ad spend updated august 2020
Four types of digital ad spend updated august 2020
 
How to Use FouAnalytics For Marketers
How to Use FouAnalytics   For MarketersHow to Use FouAnalytics   For Marketers
How to Use FouAnalytics For Marketers
 
FouAnalytics DIY site media analytics fraud detection baked in
FouAnalytics DIY site media analytics fraud detection baked inFouAnalytics DIY site media analytics fraud detection baked in
FouAnalytics DIY site media analytics fraud detection baked in
 
Fraud by Browser Study
Fraud by Browser StudyFraud by Browser Study
Fraud by Browser Study
 
Digital Ad Fraud FAQ Question 1
Digital Ad Fraud FAQ Question 1Digital Ad Fraud FAQ Question 1
Digital Ad Fraud FAQ Question 1
 
Digital ad dollars trickle down chart
Digital ad dollars trickle down chartDigital ad dollars trickle down chart
Digital ad dollars trickle down chart
 

Dernier

Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)
Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)
Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)
Cara Menggugurkan Kandungan 087776558899
 

Dernier (6)

Powerful Love Spells in Arkansas, AR (310) 882-6330 Bring Back Lost Lover
Powerful Love Spells in Arkansas, AR (310) 882-6330 Bring Back Lost LoverPowerful Love Spells in Arkansas, AR (310) 882-6330 Bring Back Lost Lover
Powerful Love Spells in Arkansas, AR (310) 882-6330 Bring Back Lost Lover
 
BDSM⚡Call Girls in Sector 71 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 71 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 71 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 71 Noida Escorts >༒8448380779 Escort Service
 
FULL ENJOY - 9999218229 Call Girls in {Mahipalpur}| Delhi NCR
FULL ENJOY - 9999218229 Call Girls in {Mahipalpur}| Delhi NCRFULL ENJOY - 9999218229 Call Girls in {Mahipalpur}| Delhi NCR
FULL ENJOY - 9999218229 Call Girls in {Mahipalpur}| Delhi NCR
 
Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)
Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)
Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)
 
Leading Mobile App Development Companies in India (2).pdf
Leading Mobile App Development Companies in India (2).pdfLeading Mobile App Development Companies in India (2).pdf
Leading Mobile App Development Companies in India (2).pdf
 
9999266834 Call Girls In Noida Sector 52 (Delhi) Call Girl Service
9999266834 Call Girls In Noida Sector 52 (Delhi) Call Girl Service9999266834 Call Girls In Noida Sector 52 (Delhi) Call Girl Service
9999266834 Call Girls In Noida Sector 52 (Delhi) Call Girl Service
 

Mobile display fraud is rampant beyond belief

  • 1. Mobile Display Fraud is Rampant Beyond Belief June 2018 Augustine Fou, PhD. acfou [at] mktsci.com 212. 203 .7239
  • 2. June 2018 / Page 1marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Mobile is 57% of digital spend Source: IAB Full-year 2017 Digital Advertising Report
  • 3. June 2018 / Page 2marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou "Fraud in mobile advertising is more tricky than just fake impressions, clicks, or installs. App advertisers can check when a user actually takes an action with their app after install to check legitimacy. The issue becomes which ad- network supplier gets credit for delivering that install. So attribution fraud is the major concern: where advertisers pay ad-networks, based on attribution vendor reporting, for installs that happened organically or by different marketing methods." -- Shailin Dhar, Method Media Intelligence
  • 4. June 2018 / Page 3marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Main forms of mobile fraud Install FraudImpression Fraud “fake devices installing legit apps, get paid on CPI” “fake or fraud apps load display ads, get paid CPM” Mobile display spend $25B (2017) Source: eMarketer, April 2017 App install spend $6B (2017E) Source: BusinessInsider, June 2016
  • 5. This deck focuses on mobile display fraud
  • 6. June 2018 / Page 5marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Which is easiest for bad guys? Fake Apps on Fake Devices Adware SDK in Real Apps Malware On Real Devices Limitation Wait until unsuspecting humans accidentally downloads malware on real mobile devices Limitation Wait until app developers install SDK into their real apps and humans to download and use apps. Limitation No limits - apps are easily cloned, and mobile emulators are easily “spun up” in data centers
  • 7. June 2018 / Page 6marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Half of humans download 0 apps/mo
  • 8. June 2018 / Page 7marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Apps’ primary revenue is ads In-App Advertising App Store Source: SensorTower
  • 9. June 2018 / Page 8marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou 75% mobile revenue from games Source: SensorTower
  • 10. June 2018 / Page 9marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Top mobile apps by ad revenue Top mobile apps by ad revenue Are entirely different than ones humans spend the most time with
  • 11. June 2018 / Page 10marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Massive, scalable display fraud “Judy Malware” • 40 bad apps to load ads • 36 million fake devices to load bad apps that load display ads • e.g. 30 ads per device /minute • 30 ads per minute = 1 billion fraud impressions per minute “Fireball Malware” • 250 million infected computers • primary use = traffic for ad fraud • 4 ads /pageview (2s load time) • fraudulent impressions at the rate of 30 billion per minute Source: Forbes, May 2017 Source: Checkpoint
  • 12. June 2018 / Page 11marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou (2015) Apps doing ad fraud Source: BusinessInsider, July 2015 “A user downloads an app from the official app store — which may look legitimate and have hundreds of positive reviews — which then runs in the background, serving hundreds of ads at a rate as high as 20 ads per minute” Known and documented for years – now mobile is majority of digital spend
  • 13. June 2018 / Page 12marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou (2017) Handful of bad apps 1 (52% of impressions) 2 (48% of impr) 66% avg fraud 18% avg fraud 1. 9% of the apps caused 52% of impressions; 66% outright fraud 2. Remaining 91% of apps caused 48% of impressions, 18% outright fraud • 1 billion mobile display impressions • Nearly 1,000 apps cross referenced with SDK Source: https://www.slideshare.net/augustinefou/mobile-display-fraud-case-study
  • 14. June 2018 / Page 13marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Fraud apps load impressions Source: ImpScore.io - https://www.youtube.com/watch?v=w-i-ue8fPCc “fake apps or fraud apps (real apps that misbehave) continuously load display ad impressions in the background, inflate revenue”
  • 15. June 2018 / Page 14marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou App cloning, free adware SDKs Apps are cloned thousands of times; some didn’t even bother to change the colors or cover graphics. Bad guys accidentally cloned apps that already had detection SDK in it – from 312, to 750, to 1,330 copies. Source: CNBC, Aug 2017
  • 16. June 2018 / Page 15marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Fake apps from real campaigns com.obpmirzste.ldsjpv com.zmm.shmxvjxnsagndui com.nqzwr.leusrmpmsq com.rced.zcdsglptpdlwpu com.kerms.ehlsgnc com.cmia.iabhheltm com.skggynmtx.tyyjnwpefvqtll com.kgdtltnuv.hayvfhob com.ztzsiqg.dyojlxdscxws com.xlwuqe.ddrdhsuosbn com.rkrhmzee.wjcoznxu com.ebhzb.hbzvomzpcctovj com.dxnxbgj.mkridqxviiqaogw com.obugniljhe.fptvznqwhmcjm com.bpo.ksuhpsdkgvbtlsw com.rlcznwgouw.vvtexstbfttngc com.kasbgf.sbzwtgpcbjexi com.bprlgbl.vbze com.zka.lzhsoueilo com.alxsavx.mizzucnlb com.jxknvk.lrwfdfirdzpsw com.tvwvqbt.wbshaguqy com.iwnxtpahcu.leyuehdwdbb com.okf.rhvemtykfibzpxj
  • 17. June 2018 / Page 16marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou “Naked Ad Calls” (load ad, not page) Why load the entire webpage when you can just load the ad (save bandwidth) and get paid? Pass fake data via query strings
  • 18. June 2018 / Page 17marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Apps load webpages “fraud apps sell traffic; use hidden webview browser to load pages”
  • 19. June 2018 / Page 18marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Fake app traffic – real dataRepeatedly load webpages (e.g. galleries) in sequence or random
  • 20. June 2018 / Page 19marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Apps load webpages, disguise “fraud sites’ traffic from apps that also pass fake HTTP headers” Source: SimilarWeb
  • 21. June 2018 / Page 20marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Fake devices (mobile simulators) Download and Install Apps Launch and Interact
  • 22. June 2018 / Page 21marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Fake mobile devices – real data Repeated hits by same device/browser, same ip address
  • 23. June 2018 / Page 22marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Fake devices pass fake location Houston, TX Bozeman, MT Fake devices declare fake locations to absorb higher ad spend
  • 24. June 2018 / Page 23marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou 90-99% of geolocation bad or faked Source: Placed, Sept 2017 Source: SafeGraph
  • 25. June 2018 / Page 24marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Bad guys trick measurement SDK Spoofing— code in an app that sends simulated ad clicks and engagement signals to the attribution provider … [to] fool an advertiser into paying for fraudulent impressions/views. Attribution Fraud— code that executes clicks (click spamming, click injection) so fraudster can claim credit for downstream conversions. Detection Tag Blocking— fake or fraudulent apps can selectively block fraud detection tags or manipulate analytics data.
  • 26. June 2018 / Page 25marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Mobile fraud is not caught Source: https://mumbrella.com.au/iabs- first-australian-figures-claim-just-4- of-digital-ads-fraudulent-429776 IAB: mobile fraud is “almost non-existent” “it’s NOT non-existent”
  • 27. June 2018 / Page 26marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Any device with chip/connectivity Traffic cameras turned into botnet (Engadget, Oct 2015) mobile devices webcams connected traffic lights connected cars thermostat connected fridge Security cams used as 400 Gbps DDoS botnet (Engadget, Jun 2016) …can be used as a bot
  • 28. June 2018 / Page 27marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Economics of botnets explained Source: MIT Tech Review, May 2018 “distributed denial-of-service attacks using a network of 30,000 bots can generate around $26,000 a month. Spam advertising with 10,000 bots generates around $300,000 a month, and bank fraud with 30,000 bots can generate over $18 million per month. But the most profitable undertaking is click fraud, which generates well over $20 million a month of profit.” Botnets can be used for a variety of things
  • 29. June 2018 / Page 28marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou About the Author Augustine Fou, PhD. acfou [@] mktsci.com 212. 203 .7239
  • 30. June 2018 / Page 29marketing.scienceconsulting group, inc. linkedin.com/in/augustinefou Dr. Augustine Fou – Independent Ad Fraud Researcher 2013 2014 Published slide decks and posts: http://www.slideshare.net/augustinefou/presentations https://www.linkedin.com/today/author/augustinefou 2016 2015 2017