How detection works

AdProtektor scores each visit from more than 150 behavioural and device signals, then clusters visits that belong to the same person across different IPs, devices and browsers. That is why a fraudster who rotates VPNs or clears cookies is still recognised as the same repeat offender.

Most click-fraud tools work on IP addresses. That is a weak identifier: IPs rotate, mobile networks share them between thousands of users, and anyone determined enough can change theirs in seconds. AdProtektor works on people instead.

The three layers

  1. Fingerprint

    A stable visitor fingerprint is derived from canvas and WebGL rendering, installed fonts, screen and platform traits. The same browser produces the same fingerprint across sessions, even after cookies are cleared.

  2. Behaviour

    More than 150 signals are collected per visit: time on page, scroll depth and scroll-burst patterns, click count, mouse movement, keypresses, DOM-timing challenges, device, OS, browser, language, screen size, GeoIP including city, ISP, ASN and timezone, plus campaign parameters (gclid, wbraid, gbraid, UTMs and keyword).

  3. Identity clustering

    A probabilistic identity graph links fingerprints, IPs and devices that belong to the same person into one confidence-scored cluster. This is the layer that catches repeat offenders across networks.

The threat score

Each visit gets a score from 0 to 100, combining engagement quality, bot and user-agent signals, and mismatch between the campaign that brought the visitor and how they then behaved. Higher means more likely fraudulent. See Threat score and threshold for how the score drives blocking.

Network risk

Alongside per-visit scoring, AdProtektor keeps a network risk ledger at IP and ASN level. Traffic arriving from infrastructure with a history of fraud starts under more suspicion than traffic from a residential broadband line — which is how hosting providers and known-bad networks get caught quickly.

Detection improves with volume

Clustering needs observations. A visitor seen once is scored on that visit alone; a visitor seen repeatedly builds a much stronger profile. Expect accuracy to firm up over the first few days of real traffic.

Frequently asked questions

Does this work if the visitor uses a VPN?

Yes — that is largely the point. A VPN changes the IP but not the browser fingerprint or the behavioural pattern, so the identity graph still links the sessions to one person.

What happens if someone clears their cookies?

Clearing cookies does not reset the fingerprint, so the visitor is still recognised. This is the main reason person-based detection outperforms cookie- or IP-based approaches.

Can two real people be merged into one person?

Clusters are confidence-scored rather than absolute, and shared-network situations are treated cautiously. If you believe a legitimate visitor has been caught, whitelist them — see Manual blocks and whitelisting.

Related articles

Stop bleeding ad budget

See how much fraud is hiding in your traffic — in 5 minutes.

Most accounts find that 10–20% of paid clicks are bot, click-farm, or repeat-offender traffic. Start your free trial — the first numbers come back the same day you install.

free trial • Cancel anytime • See results on day one • Already a customer? Log in