Click-fraud protection used to mean one thing: detect a bad IP, add it to a blocklist, repeat. That worked when fraudsters cycled through a small pool of cheap proxy IPs. Today, residential proxy networks rotate millions of IPs per minute, click farms operate from real consumer devices, and competitor click-bombers run mobile-tethered scripts that change IP every few clicks. IP-only filtering misses all of it. The category has split into two camps: tools that still optimize for IP exclusion as the primary mechanism, and tools (like AdProtektor) that build behavioral fingerprints of each visitor and use IP exclusion as one of many enforcement actions, not the only one.