Results tagged “Fraud” from IABlog

I have been in multiple conversations recently with clients about video fraud, safety and content verification and how those impact video advertising today. I was asked questions such as “How concerned should I be? What’s the best way to prevent issues? What are my options? It became clear to me that while there’s overall concern about the topic of video verification, there’s also a knowledge gap that needs to be addressed. 

So here is a cheat sheet of the things you may want to consider in your solution. All the items below are critical to ensuring maximum protection for your brand. 

1) Media Neutrality
The single most important thing is to ensure that you are not using a solution that is provided by a company that also sells you the media. There are several verification solutions on the market, but many of them are homegrown solutions offered by media sellers that aim to offer insight into the quality, or lack thereof, of their competitors’ inventory. In other words, if Company A sells you media and also tells you, here’s a solution that will verify our media - can you believe that this is a viable solution? To avoid this conflict of interest and ensure that you’re getting accurate information, you should prioritize solutions that are media neutral.

2) Methodology and Technology
It is also crucial that you are confident in and comfortable with the technologies and the methodologies used by your solution of choice. Here are 3 questions you want to ask:
  • What’s your measurable Rate? - This KPI measures the percent of impressions verified out of the total impressions delivered in the campaign. Your goal should be to get as close as possible to a measurable rate of 100%.
  • Are you MRC accredited? - A solution that carries the MRC seal means it is a trusted solution that has gone through a rigorous set of tests and has been validated to meet a certain set of guidelines and industry standards. 
  • What’s your level of publisher transparency and cooperation? - Keeping your media partners in the dark is counterproductive and ensures the negative outcomes you are trying to avoid. Make sure the relevant data is available to your media partners in real time and that you frequently communicate with them to address any issues that may come up. 
3) Fraud Detection and Brand Safety
No verification solution can be considered viable without addressing these two topics. 

Fraud detection identifies whether an impression was generated by a human (i.e. real or not). Fraud has been an ongoing issue since the early days of online advertising with click fraud in search marketing and other CPC driven marketing. Since then, the problem evolved and started affecting CPM based advertising such as display and video. There is already a great deal of industry buzz, so let it suffice to say that there are many forms and tactics of impression fraud as the fraud committers become increasingly sophisticated. That said, there are several companies dedicated to solving the problem with robust solutions to address different methods of fraud. 

Brand safety focuses on identifying areas which are not suitable for brand advertising. An impression may be real and viewable but if the ad ends up appearing next to inappropriate content such as adult material, hate speech, violence, etc. - it can lead to a disaster for a brand which invested years in building its public image.

4) Full Campaign Visibility
You should make sure that you get granular data and reporting that gives you full visibility into what affected the performance of your campaign: How many issues were detected? How were they distributed across your media partners? How many impressions were affected? How did it affect your overall campaign performance? Etc. 

It is also important to combine your display verification and video verification reporting. There are solutions on the market that offer one or the other, and solutions that do both. The advantage in combining both is streamlined operations and the benefit of utilizing display verification data in video verification and vice versa. The more historical data you use, the more accurate your detectionand thus protection, will be.

That said, reporting is only good at detecting the issues and giving you a backward look at things. This is good for understanding what happened and suggesting measures for future campaigns. 

5) Impression Blocking 
The best measure to ensure that issues will actually be prevented is to deny the delivery of the impression. Several techniques exist to do this:
  • Blacklists - A list of domains is created where your ads must not run.  Ads can run on any site that isn’t on the blacklist.
  • Whitelists - A list of domains is created where your ads may run.  Ads must not run on any site that isn’t on the whitelist.
  • Impression-level analysis - Inspecting each impression and determining whether it meets the advertiser’s specific criteria, including brand or message conflict, along with fraud, brand safety, and other requirements, and denying ad delivery when these criteria aren’t met for the specific impression.  
Many advertisers today use black and white lists. However, this is like throwing out an entire container of eggs because one is broken. Making a decision per impression is preferred to making a collective assumption that a domain is always safe or never safe as it ensures fewer bad ad impressions where something went wrong on a trusted site, and more good ad impressions on sites that otherwise might have been totally excluded with a less granular solution. 

6) Page Verification & Video Player Content Verification
It’s important to understand that online video appears on pages composed of two separate pieces - one being the video player where the video content and your video ad appear, and the second being the actual page that hosts the video player. Verification issues can happen both on the page and inside the video player, but most solutions on the market focus on detecting issues within the page only. Often times, the page content may be safe while the video content inside the video player is inappropriate for your brand. You must be able to detect BOTH issues related to the page and issues related to the video content itself. 

6 Steps to Video Campaign Recovery
Once you are over the hump of admitting that fraud and a general lack of visibility represent a threat to your digital campaigns, use this list of six key considerations as your guide to recovery. When the curtain is pulled aside to reveal an industry problem, many technology providers will race to offer proprietary solutions. Not all solutions are created equal, so find a solution that deals with each of these verification considerations for you so that you have the most complete capabilities possible.

About the Author

Ronnie Lavi, Innovid.jpg

Ronnie Lavi

Ronnie Lavi is vice president, product, at Innovid, a technology platform for delivering immersive video advertising anywhere. Ronnie is a digital advertising technology veteran with nearly a decade of product development and product marketing experience.



We are at war.  The industry is under siege from organized criminals who proliferate malware to steal individuals’ sensitive information, turn consumers’ devices into bots that generate billions of fraudulent ad impressions and clicks, and who pirate valuable content—all for their own financial gain.  

We are also at war with ourselves.  We have created an overly complex and porous supply chain that is obfuscated from the very marketers we hope to sell to.  And, we have not shown the necessary vision and commitment to effectively fight back.  

Without trust between marketers, publishers, consumers, and the multitude of parties in between, the growth of our industry—and by extension all of the monumental innovations our industry supports—is indefinitely debilitated. As IAB President and CEO Randall Rothenberg said in a powerful call-to-action earlier this year, we need an industry-wide behavior change at an unprecedented scale.

 IAB is uniquely positioned to lead this charge. Our members have driven the advancements that created this complex supply chain and can propel the progress that will lift us out of this morass.  Success, however, will require all of you.  Only with the help and dedication of the entire advertising community will we be able to instill confidence in consumers, security in content creators, and better understanding in marketers. 

To accomplish this ambitious and essential goal, the IAB is launching a Trustworthy Digital Supply Chain Initiative, comprised of 5 distinct objectives: 

  • Eliminate Fraudulent Traffic
  • Combat Malware
  • Fight Internet Piracy
  • Promote Brand Safety through greater Transparency
  • Create Accountability

Here is the roadmap for accomplishing each objective: 

Eliminate Fraudulent Traffic

No economic model in which a significant percentage of the goods sold are fraudulent is sustainable.  We must identify bot-generated, non-human traffic and remove it from the supply chain.  The first step is to develop a common taxonomy so the entire ecosystem can speak the same language when talking about “transacting in only human traffic”.  Second, we must have a set of principles, operational and technical in nature, that help guide sellers of inventory in the identification and filtering of fraudulent activity.  Lastly, there needs to be better communication across the industry on known threat vectors and cutting edge solutions.  

IAB is currently leading the Traffic of Good Intent Task Force, which earlier this year scoped the cause and nature of this problem and produced a set of definitions. This group will soon expand upon that product with the release of new principles that establish best practices for fraud detection and set institutional limits on selling that inventory.  Following this work, the group will focus on adoption and accountability across the entire industry.

Combat Malware

Eliminating fraudulent traffic and combatting malware are two sides of the same coin. Malware is the malicious software downloaded onto consumers’ devices as they browse the web, download apps, or click on an infected link or advertisement. By decreasing the proliferation of malware the industry will create a safer, more enjoyable experience for consumers, and will help thwart the creation of botnets, which in turn create fraudulent traffic. 

To organize industry’s efforts on this front, IAB is establishing a new Malware Task Force within the Trustworthy Digital Supply Chain Initiative.  This group will create a set of high-level security principles to help companies detect malware attacks on their sites, as well as to help define technological baselines for companies to deploy against criminal activity. Malware attacks are constantly evolving, thus this group will also serve as an information sharing platform in which one company can share the latest intelligence on malware threats with other companies.  IAB will also form a partnership with law enforcement agencies to help them more effectively investigate and prosecute criminal activity.  Finally, the industry must work to plug the most commonly exploited security hole, which is outdated software on individuals’ devices.  We must educate consumers about these security risks and encourage them to update their browsers, operating systems, and other software. 

Fight Internet Piracy

Advertising revenue should never flow to criminals who steal copyrighted material and place it on “pirate” sites.  IAB and many of its members have already made strides toward this imperative through the Quality Assurance Guidelines, which include the prohibition of the sale of advertising on sites dedicated to copyright infringement. While many networks and exchanges already devote a great deal of time and resources to detecting this illegal activity, more must be done. IAB is participating in a cross-industry effort to standardize best practices and piracy detection technologies, thus making it easier for companies to double down on their existing efforts.  In addition, the Quality Assurance Guidelines program recently established a complaint system, whereby rights holders can notify networks and exchanges about potential pirate sites.  However, the process must be simpler, detection more accurate, and participation ubiquitous. And finally, marketers and agencies must build upon their own commitment to not purchase inventory on pirate sites by including this language in their contracts for every advertising campaign.

Promote Brand Safety through Increased Transparency

There is no easy way to say it, but too many marketers and agencies do not fully understand the inner workings of the digital advertising supply chain. The path an ad travels today, from insertion order to the screens of a target group of consumers, is a labyrinthine and far too opaque to the buyer. As Rothenberg said in his article, “Even if you know that your own suppliers are reliable, you can’t tell whether your suppliers’ suppliers are secure.”  Unchecked, this lack of transparency deters brand spending in our ecosystem.  To build openness, understanding and trust, sellers must continue to grow the transparency provisions contained within the Quality Assurance Guidelines—particularly in light of the rise of programmatic—and evolve the compliance program so that it governs every transaction flowing through the trusted supply chain. 

Transparency is one of the foundational goals of the Quality Assurance Guidelines. As its mission states, the Quality Assurance Guidelines aim to provide “clear, common language that describes characteristics of advertising inventory and transactions across the advertising value chain.” Already 29 top digital companies are certified under the program, with many additional leaders en route. We must continue to build out participation and increase awareness of the program amongst marketers and agencies.

Create Accountability 

Principles and guidelines are only effective when you have industry-wide adoption and compliance.  This kind of accountability ensures each participant can rely on the multitude of other actors in the supply chain to do the right thing. Without it, trust erodes. 

We have the building blocks of an industry wide compliance program in the current IAB Quality Assurance Guidelines.  To build this out to ensure a trustworthy digital supply chain, it must be expanded to cover areas such as fraud and malware and to additional areas as they arise. The compliance mechanism must be strengthened to include active monitoring systems and serious consequences for non-compliance. Last but not least, ALL actors in the digital advertising supply chain, from marketers and agencies to ad technology intermediaries and publishers, need to certify against the parts of the guidelines that are relevant to their business model.  Advertisers then must request, demand if you will, this seal of approval from those with which they buy. Only then will we have an accountability program that truly becomes the “Good Housekeeping seal of approval,” meaningfully signifying who to trust in the digital ad supply chain.   

These five discrete objectives compose a roadmap toward a more trustworthy digital supply chain, one that will increase the entire industry’s value and worth. They will be discussed in more depth at the Advertising Technology: IAB Marketplace event happening today in New York. However, it should be said, there is no such thing as a completely trustworthy supply chain. Most of our efforts are directed at fighting criminal activity, and it’s impossible to stamp out all crime. But we can implement successful programs that make it difficult for the criminals to be successful. That’s what we are doing today and we need your help to achieve our goals. 


About the Author

sp_mane_sherrill.jpg

Mike Zaneis

Mike Zaneis is SVP & General Counsel at the IAB.

Although Integral has been on the forefront of the fight against impression fraud in the digital advertising industry, I have been largely silent on the topic.  Despite that I’m a battle-scarred ad tech vet with strong opinions, I have been quiet because I know that many will perceive my words as biased due to Integral’s role in fraud prevention.  Two recent incidents, however, prompted me to end my silence.  Some will be surprised by my conclusions.

For the record, my definition of impression fraud - as recognized by the IAB - is a situation where an advertiser buys a digital ad that has zero chance of being seen by a human.  Fraud comes in many flavors, including ad stacking, whole websites stuffed into non-viewable i-frames, and botnets of infected consumers’ computers, which surreptitiously mimic humans’ surfing behavior.  Although all cause harm to the advertising ecosystem, I will be referring mainly to bot traffic here as we believe it’s the most common form of fraud and probably the hardest to detect.

The first aforementioned incident that caused me to speak out was a call I received from an old colleague who runs a media company that produces valuable fitness-related content.  He called me in panic because he was told by one of his big clients that they were discontinuing advertising with his company.  Their reason was that a technology vendor had found that 100 percent of his site’s impressions were fraudulent.  Given what I knew of the site, 100 percent fraudulent traffic sounded improbable.  I quickly offered to help by running a test on his site.  The results showed that my former colleague’s site did have some fraud, but the levels were closer to 20 percent.  It became quite clear that the technology vendor measuring fraud was labeling a lot of legitimate inventory (in this case 80 percent) as bad inventory.  I thought that this may have been an isolated case, but with further investigation, I found that this was happening to a lot of other publishers as well.  Sites that had even a modicum of fraud were being labeled as fraudulent by this well-known vendor.  

This issue seemed like a micro-level problem to me.  Human traffic was being incorrectly categorized as bot traffic on domains with any level of fraud, and while unfortunate, only impacted those sites affected.  The second incident, a call from an investment bank research analyst, made me realize that there is a macro-issue at play as well.  This bank was putting the final touches on its special report on the state of digital media and wanted me to verify that the annual loss from impression fraud in the online display ad industry was over $20 billion.  Say what?  I have read some pretty aggressive predictions around the dollars lost to fraud, but $20 billion?  That estimate is way too high. 

So, I feel I need to come forward and take a stand.  Fraud is a problem in the online advertising industry, but NOT a problem of this magnitude.  Whether on purpose or not, the fraud problem is being exaggerated.  We have a problem, but it’s been blown out of proportion and it’s not as big as what we read.  There, I said it.  A year ago, I was concerned because I felt that the industry was not talking enough about the fraud problem, and now, I am worried about the opposite.  If we’re not careful, we are going to get carried away and cause irreparable harm to the future of digital advertising.

image3.jpg
So how did we get here exactly?  I put the blame into a couple of categories.  The first category has to do with limitations in technology.  The unnamed vendor labeling my former colleague’s website as having 100 percent fraudulent traffic is a good example of technological limitations.  In this case, the vendor correctly detected some fraudulent activity, but extrapolated this information to the domain or site level.  In other words, bot-related fraud happens at a user level (an infected computer), but due to technical restrictions, it is often tied to a domain level (e.g., fitness-related-site.com).  To make matters worse, many solutions only have two classifications of the entire site: fraudulent or clean.  Thus, if the solution sees any reasonable fraction of fraudulent impressions on a website, it has to make a decision to label the site as fraudulent or clean.  The threshold for fraud is typically set quite low in order to eliminate as much bot traffic as possible.  The end result is that a relatively few fraudulent visitors can cause a vendor to mislabel a large percentage of normal impressions fraudulent.  And as most fraud appears on legitimate sites that are buying traffic (a portion of which turns out to be non-human), as opposed to whole fake sites with 100% fraudulent traffic, this mis-labeling is very common.  When you start to aggregate these mis-labeled statistics and extrapolate on what it means industry-wide on a percentage of total impressions, the amount of fraud present looks downright scary.  Then, if you apply industry average CPMs to these extrapolated estimates (despite the fact that fraudulent inventory is usually cheaper than average), suddenly $20 billion appears plausible. 

So, what’s the alternative to rolling up fraud statistics and detecting at the domain level?  The better option is to intercept the ad call as soon as you detect a fraudulent user and thus only block the one ad from serving to this specific bot.  However, you need to do this detection at the ad impression level.  It’s the equivalent of using a laser to perform surgery rather than a butcher knife.   Here are a couple of things to look out for:  If more than 15 percent of your campaign impressions overall are identified as fraudulent and blocked, there is a good chance fraud detection is at the domain level.  This means you are using a butcher knife, and this will likely cause friction with partners and needlessly hurt your scale.

Additionally, if you ever hear that blocking is not possible or bad because it tips off the fraudsters, you should know that you have been given false information.  If done correctly, there is absolutely NO truth to this claim.  It’s an urban myth - similar to one that claims freezing water in plastic bottles release dangerous dioxins - so don’t fall for it!  Even if fraudsters were able to somehow detect that a specific bot did not receive the originally intended ad each time (not likely), there is no data that would give them the ability to reverse engineer the reasons why.  People claiming that blocking is bad because it helps the bad guys are either naïve, rely on only one method for detecting fraud (like side channel analysis) or are purposely deceitful.  In any case, it means that they’re suggesting a solution that does not have the technological sophistication to block at the impression level, and thus not as effective in preventing fraud and saving money for advertisers.

The second category of blame for exaggerating the fraud problem is related more to commercial reasons.  The fraud problem has created lots of opportunity and companies have popped up almost overnight to capitalize on it.  Many of the companies are made up of people who have never bought or sold an ad and have no appreciation for the media or the technology behind it.  They see dollar signs and exaggerate the problem to give their company attention and help them create more demand for their product and services.  Furthermore, most of these companies see only a small percentage of the online population - typically the worst stuff.  They make the assumption that their tiny sample of media is representative of the entire industry’s media and use these biased samples to wildly extrapolate.  Needless to say, the industry’s long-term health is not their top concern.  

So, where do we go from here?  Well, first it starts with a little perspective.  We have a fraud problem.  It has been exaggerated, however, and it’s not as big as many of the pundits say.  It definitely won’t ruin the industry - we won’t allow it to — and it’s not out of control.  That’s the good news.  The bad news is fraud is still a problem nonetheless.  It’s not only a sell side problem nor is it only a buy side problem.  It’s an industry problem.  And this problem will not go away anytime soon and may never completely vanish.  The bad guys are made up of amateurs and very sophisticated professionals.  We can eliminate the amateurs, but the pros are making a lot of money in fraud and they will continue to invest heavily in building better deceptions.  Our goal has to be to work together as an industry to shut down all amateur activity and get the professional levels to a very small, manageable amount.  The good news is that we are making progress.  Despite what you may hear, fraud levels have dropped over the past year.  We are at the beginning of the battle, but we’ve got the bad guys on the run. 


About the Author


Scott_headshot_hi-res.jpgScott Knoll

Scott Knoll is the CEO of Integral Ad Science