15 ms·
Discovered: Botnet Costing Display Advertisers over $6,000,000 per Month
- fein 14y agoWell, that's what you get for being in the click based ads game really. At this point, I would assume that these companies should just accept this as an occupational hazard. It's not like they can ever really beat the bots.
- pfarrell 14y agoAt Strata (O'Reilly's BigData conference), there was an entire session track dedicated to fraud prevention and legal movement on this type of stuff. Although, you will never be able to stop this (unless you stop people from being driven by money) the data community is taking this kind of detection very seriously. Every business, if it get large enough, is going to care about this type of fraud, if only to pay it some amount of lip service I saw a presentation. From a data scientist at bitly. She showed that spammer links have a distinctive traffic shape (constant over time) while real links have a totally different one (initial peak followed by logarithmic drop to zero). Similar patterns exist in advertising campaigns. 6MM/month seems like a lot of breakage that someone is fine cutting that check.
- adyus 14y agoWhat's to stop a botnet operator from incorporating that data scientist's findings into their bot behavior? It's a chicken & egg problem, and it will hopefully lead to a better alternative to online advertising (perhaps something more user-centric).
- darkarmani 14y ago> It's a chicken & egg problem I think you mean it's an arms race. Arms races are good markets to be in as the hash-checking AV companies have proved.
- pfarrell 14y agoThere will always be an incentive to commit fraud as long as there's money to be made. Why doesn't a robber of houses move to a new city each time they commit a crime? There are costs to all crime, especially in the setup. If you raise the input cost to generate a reward, then you make it less attractive as an avenue to fraud. At least among the unskilled criminals. I'll totally admit I'm skewed by operating on the data side and want to believe that my work has some lasting positive impact, and isn't a band-aid.
- elmuchoprez 14y ago"Well, that's what you get for being in the click based ads game really." Do you find something particularly sinister or unethical about click-based ads (more so than any advertising)?
- fein 14y agoOh no, not at all. I realize that could have come across as malignant, but it was just supposed to be a neutral assessment. I do freelance dev work for some guys that run ads; it's just another business to me.
- tatsuke95 14y agoI don't. But this is analogous to TV advertisers complaining about TiVO and the ability to skip commercials. Can't stop it!
- elliottcarlson 14y agoNo matter what line of work you are in, there is a cost of doing business related to fraud - that does not mean it doesn't require some kind of attention even when you can't combat 100% of the fraud.
- binarymax 14y agoVery informative and, though it is not explicitly stated, we can infer that this evidence cuts to the point of how low some competitors will stoop to exploit pitfalls of web advertising. The team at spider.io has found a great niche and has impressive results - I always enjoy seeing posts like these pop up from them. Keep up the great work!
- readme 14y agoThe infections by state chart would be more interesting if it was per capita.
- d23 14y agoI find this fascinating. How does chameleon infect its victims? Anyone have further reading? Botnets seem incredibly interesting.
- unix-dude 14y agoBotnets dont really infect their victims. A botnet is just a network of compromised computers (Bots). The malware that forces your computer to participate in the botnet can be delivered by any avenue imaginable. Drive-By Downloads, crapware, embedded into pirated software, etc. Not sure how chameleon specifically did it.
- andreasklinger 14y agoIs the comparison valid to say botnets are the bacteria of the Internet?
- JonnieCache 14y agoBotnets are inherently malicious. This is obviously not true of bacteria. But in a way they are similar I suppose. I don't think its a very fruitful analogy either way.
- andreasklinger 14y agoI am not sure if can be called non-malicious but there is definitely a new breed of botnets coming up e.g. http://internetcensus2012.bitbucket.org/ http://internetcensus2012.bitbucket.org/
- bd_at_rivenhill 14y agoMore like the parasites of the internet.
- lucb1e 14y agoExcept parasites have no central control or a will to do anything beyond survival.
- cletus 14y agoAs much as the HN crowd might rail against walled gardens (most notably iOS) and managed platforms like ChromeOS, every time I read one of these posts I think that for the vast majority of people, it's the best thing for them. Botnets typically don't spread in a sophisticated way. Most of the time it's spam emails or dodgy ads with "hey! install this random .exe file and you can have emoticons in Outlook!" I think Chrome has shown us the advantages of an automatically updated browser. The future in personal computing I think lies squarely in an automatically updated (even managed) sandboxed environment. This isn't to say that's right for everyone of course. But how much fraud, extortion, DDoSing, identity theft, invasion of privacy (eg ratting), etc do people need to put up with before they demand a better way? EDIT: to address two points: 1. Side-loading is orthogonal to the issue of a sandboxed managed environment. I agree users should be able to side-load. Most won't know how and won't care and that's a Good Thing [tm]; 2. Sure the central server can get compromised but the thing is botnets rarely spread in a sophisticated fashion. It's all social. The Facebooks, Apples and Googles of the world have far more experience and a far better track record in dealing with these kinds of threats.
- sc0rb 14y agoI don't think many home users are using Outlook.
- nmcfarl 14y agoUntil she got an iPad my mother ran Outlook. It’s all she knew how to operate for a mail program, and she "wasn’t learning something new". I don’t think she was alone - I’d bet a ridiculous number of $300 netbooks have a $100 Windows OS and $200 MS Office Suite installed on top.
- sc0rb 14y agoand my mother has been using yahoo mail forever... I still doubt most home users actually use outlook (most home users wouldn't even know how to set it up). It's very much an enterprise / business thing for the most part.
- 14y ago
- jpdoctor 14y agoUsing the assumption that there is never just one cockroach, what is a good multiplier to arrive at total-fraudulent dollars-per-month?
- Nursie 14y agoA few things - 1. Why? 2. How widespread is this in general? How long before most web advertising is bot-fraud as users learn about ad-blockers? 3. Didn't realise my mouse traces were being recorded by advertisers in such detail.... I do not like this.
- elmuchoprez 14y ago1.) The only "useful" application of this that I can immediately think of is to drive up the cost per impression on your competitors. But this seems like a very short term strategy as anyone doing meaningful online marketing is watching the cost per acquisition (a person who actually buys something) just as close or closer than impression cost, and your acquisition cost is going to go through the roof if you get a bot attack. 2.) I haven't been able to find meaningful info on this yet. 3.) I work in e-commerce tech. I had NO IDEA how bad it was before I got into this industry. Just had a sales call with a company who is tracking 400 unique data points per second on users. They track mouse clicks, mouse movements, what your highlight, how long on site, navigation pattern, buying behavior form other in-network sites, page position, etc... and then use that data in real time to dynamically generate promos and offers to "encourage buying behavior".
- Nursie 14y agoThat there is quite scary! May have to investigate "NoScript" a bit more closely...
- codesuela 14y agoGhostery should be enough and is less invasive. https://www.ghostery.com/download https://www.ghostery.com/download
- Nursie 14y agoThanks for that, had heard of it before but have now investigated and I like it! It does automatically what I'd been manually doing with Adblock i.e. block loading resources from facebook when not actually on facebook.com, and a whole lot more. Useful tool.
- rsingel 14y agoWell that leaves the real questions: what sites were the bots clicking ads on, who owns those sites and which ad networks were they using?
- deleted 14y ago[deleted]
- megablast 14y ago> spider.io has observed the Chameleon botnet targeting a cluster of at least 202 websites. 14 billion ad impressions are served across these 202 websites per month. The botnet accounts for at least 9 billion of these ad impressions. The odd thing is that either these sites are already very big, or there are others ways they are getting 5 billion ad impressions. A list of these 202 websites would be informative. I guess a number of them could be fake, to throw the scent off?
- oroup 14y agoPerhaps a coincidence, but this AdWeek report[1] flags a number of "ghost sites" that offer huge volume of impressions for sale on the exchanges and have real advertisers but don't seem to have any actual human beings present. One site in particular they mention usbuildingdigest.com has a very large number of DSP and other data integrations[2]. Suggestive to say the least. A number of other sites are mentioned in the AdWeek report. [1] http://www.adweek.com/news/technology/meet-most-suspect-publishers-web-148032 http://www.adweek.com/news/technology/meet-most-suspect-publ... [2] http://imgur.com/WHxmmHo http://imgur.com/WHxmmHo
- kreilly 14y agoThis list of sites will change in 60 days. This sites are like pop-up store fronts for ads.
- epmatsw 14y agoIt's interesting that the infection seems most common in the Southwest. Do botnets like this spread geographically based on email address or physical connection/proximity? Or are the targeted sites or infection points targeted at users in the southwest? Or are people in the north/northeast more likely to use anti-virus software or be savvy enough to avoid this?
- claudius 14y agoThey appear to have coloured states based on the number of infected hosts in such states. Since states in the northeast are generally smaller (i.e. less populous) than, say, California, we can assume that there are also fewer people getting infected there. E.g., there are approx. 1e6 people in Maine and 4e7 people in California. If you assume 1e2 infected hosts in Maine (0-99) and 3e4 in California (>1e4, 1.2e5 in total), you get an infection rate in California of about 7.5 that in Maine. Given the very coarse graining in the data source, such a factor can either be dismissed as statistical fluctuation or you could try to explain it using, for example, an infection model that favours geographical proximity, such as one based on Facebook friends. Furthermore, it might well be that internet connectivity is better in California than it is in Maine and the bot prefers hosts with high uplink rates. I don’t know :) Edit: We don’t know what websites were targeted, but maybe they ran ads that would prefer users from the southwest for some reason?
- epmatsw 14y agoAh, didn't realize they weren't weighted. Still, it'd be interesting to see if the apparent bias to the southwest is statistically significant.
- entropyneur 14y agoWow, I didn't realize the arms race has reached such heights already. Looks the bad guys are bound to win eventually.
- smtddr 14y agoThere are some crazy clever schemes out there for click fraud. Check out this link - _WARNING NFSW IMAGES_ http://www.behind-the-enemy-lines.com/2011/03/uncovering-advertising-fraud-scheme.html http://www.behind-the-enemy-lines.com/2011/03/uncovering-adv... This was estimated to be making $500K a month before being found... and was a work of pure genius.
- gingerlime 14y agoInteresting read. I'm still not sure I understood the role of the "HGTV" sites and how the fraudster was getting money by showing the HGTV ads (even after reading the comments on the post explaining this). Weren't the ads on those parked domains enough to generate the revenue for the fraudster?
- Panos 14y ago"Weren't the ads on those parked domains enough"? Is greed limited?
- gingerlime 14y agoIt's not about that. If the ads were only on their own domains, this could have gone undetected. The whole thing was discovered as a result of using those 'legit' websites, and as far as I can tell from the article, using those was an essential part of the scam, i.e. without it, it might not work... but I'm just wondering why.
- deleted 14y ago[deleted]
- brador 14y agoMaybe it really is just windows users running IE 9 on windows 7...and maybe it just crashes on clicks sometimes because the tracking overloads it? Do they have the bot code? I didn't see anything about where it came from...just an assumed analysis of effect. Just saying, it might not be a bot or malware at all.
- bcherry 14y agoThe analysis of click and mouse traces location distribution vs humans at the end makes it pretty clear that these are not humans.
- jdalgetty 14y agoAny idea what the list of 200 sites are?
- arbuge 14y agoThe only guaranteed antidote to this kind of fraud is performance advertising (pay per sale). I think pay per click and pay per impression, though arguably useful for brand advertising, will always be vulnerable to sophisticated scams like this.
- lutusp 14y ago> The only guaranteed antidote to this kind of fraud is performance advertising (pay per sale). It's guaranteed, but it probably won't work: "Thanks for doing business with us -- by the way, where did you hear about us?" "Online, but I forget where." Advertisers need to be able to associate an advertisement with a result. Otherwise the effectiveness of advertising is a myth.
- FollowSteph3 14y agoAll the scammers have to do is purchase say x% of clicks and the. Refund the money. It's very hard to track which ad click generated exactly which sale. For example through Adwords content network you don't know which site generated the click/purchase. You can know that content network ads gets more refunds, but without access to googles data you can't know the specifics. So as good as CPA sounds, its not full proof either. You can just bypass it with either stolen credit card purchases or refunds.
- skore 14y agoThat does not address what the post you're replying to stated: That PPS is a more trustworthy metric than PPC. The user is rarely, if ever, asked in this - it's all tracking.
- lutusp 14y agoYour argument assumes that sales follow from clicks (and can be tracked in the same way), so one need only follow the clicks to a sale. But this doesn't take into account that many sales take place long after a client has browsed online advertising. This is particularly true for big-ticket items. > That PPS is a more trustworthy metric than PPC. Yes, true, but only for sales that follow directly from an advertisement, with no intervening time or context changes. I agree with the basic argument the PPS is more reliable and meaningful, but it would be worthwhile to know how many sales follow directly from an initial advertising exposure, as opposed to a more complex decision-making process. Consider the diamond campaign waged by De Beers described in another HN thread today. The advertising costs were high, but the goal was to change consumer perceptions over a period of decades (and successfully). This is far removed from the model we're discussing, essentially an impulse purchase -- the De Beers campaign wasn't directly correlated with diamond sales at all. My point is that not all advertising can be shoehorned into a directly trackable purchase, yet those other kinds of advertising might still be valuable.
- von_tenia 14y agoI wonder if Ad platform companies like adwords will see a drop in their revenues once the Botnet will be dismantled...
- lucb1e 14y agoOr perhaps an increase because ads become worth more. Fake clicks make less sales, so if there are more sales, people can spend more on advertising. Of course it needs to be at a very large scale for it to influence the actual price per advertisement, but this botnet seems to be rather large-scale.
- gluejar 14y agoI'm wondering if this might be related to the twitter spam discussed at https://news.ycombinator.com/item?id=5373161 https://news.ycombinator.com/item?id=5373161
- chwolfe 14y agoBefore you blacklist the IPs listed in the article, it might be worthwhile to query your transactional history and verify real purchases are not occurring on those addresses. When I did this, a few of the IPs had a significant number of orders. Interestingly, the IP with the most orders mapped to E! corporate headquarters. http://www.networksolutions.com/whois/results.jsp?ip=208.78.120.35 http://www.networksolutions.com/whois/results.jsp?ip=208.78....
- kingkool68 14y agoI'm fairly confident all of the revenue from one of my sites comes from botnet ad clicks. I use CloudFlare and when I set it up at first I used the standard settings for blocking bots. My ad revenue flat lined. Took the botnet protections off and my ad revenue went right back to what it was before.
- GhotiFish 14y agohaha, I like this post. Are you gonna leave it? I must admit, screwing advertisers doesn't feel so wrong, I'm certainly no fan, but you can't ignore that it's not very ethical. Given that it's not technically your fault, you'd very likely never get blamed, and your actions will likely not change the world in any way, what will you do?