How detection works
AdProtektor scores each visit from more than 150 behavioural and device signals, then clusters visits that belong to the same person across different IPs, devices and browsers. That is why a fraudster who rotates VPNs or clears cookies is still recognised as the same repeat offender.
Most click-fraud tools work on IP addresses. That is a weak identifier: IPs rotate, mobile networks share them between thousands of users, and anyone determined enough can change theirs in seconds. AdProtektor works on people instead.
The three layers
Fingerprint
A stable visitor fingerprint is derived from canvas and WebGL rendering, installed fonts, screen and platform traits. The same browser produces the same fingerprint across sessions, even after cookies are cleared.
Behaviour
More than 150 signals are collected per visit: time on page, scroll depth and scroll-burst patterns, click count, mouse movement, keypresses, DOM-timing challenges, device, OS, browser, language, screen size, GeoIP including city, ISP, ASN and timezone, plus campaign parameters (gclid, wbraid, gbraid, UTMs and keyword).
Identity clustering
A probabilistic identity graph links fingerprints, IPs and devices that belong to the same person into one confidence-scored cluster. This is the layer that catches repeat offenders across networks.
The threat score
Each visit gets a score from 0 to 100, combining engagement quality, bot and user-agent signals, and mismatch between the campaign that brought the visitor and how they then behaved. Higher means more likely fraudulent. See Threat score and threshold for how the score drives blocking.
Network risk
Alongside per-visit scoring, AdProtektor keeps a network risk ledger at IP and ASN level. Traffic arriving from infrastructure with a history of fraud starts under more suspicion than traffic from a residential broadband line — which is how hosting providers and known-bad networks get caught quickly.
Detection improves with volume
Clustering needs observations. A visitor seen once is scored on that visit alone; a visitor seen repeatedly builds a much stronger profile. Expect accuracy to firm up over the first few days of real traffic.
Frequently asked questions
Does this work if the visitor uses a VPN?
Yes — that is largely the point. A VPN changes the IP but not the browser fingerprint or the behavioural pattern, so the identity graph still links the sessions to one person.
What happens if someone clears their cookies?
Clearing cookies does not reset the fingerprint, so the visitor is still recognised. This is the main reason person-based detection outperforms cookie- or IP-based approaches.
Can two real people be merged into one person?
Clusters are confidence-scored rather than absolute, and shared-network situations are treated cautiously. If you believe a legitimate visitor has been caught, whitelist them — see Manual blocks and whitelisting.
Related articles
Traffic classification
The five traffic categories AdProtektor sorts every visit into — Real, Crawler, Bot, Competitor and Click Farm — and the finer states shown in the dashboard.
Threat score and threshold
What the 0–100 threat score means, how the configurable threshold controls blocking, and when to move it.
Person profiles
Everything AdProtektor knows about one visitor — linked IPs and identities, session history, AI classification and replay.
