Search this site
268 results found with an empty search
- Anti-Money Laundering using Graph Analytics
What is money laundering? The technique of transforming huge monetary gains from illicit activity into legal assets while hiding their real origins is known as money laundering. To combat such acts, governments all over the world have been increasingly tightening AML policies. Financial institutions are now obligated to adhere to strong anti-money laundering rules and to disclose any suspicions of money laundering activities. Money laundering has a significant societal impact since it fuels terrorism, trafficking, drug dealing, and other criminal activities. The problems and challenges with money laundering starts with: Rising AML operational costs: it is pushing financial institutions to seek alternatives to their present tools and technologies in order to avoid fines and penalties. The rise in false positives: it keeps compliance personnel distracted and as a result, resources are spread thin across all phases of the AML process. The prevalence of false negatives: sophisticated criminals who are able to circumvent AML protocols in order to perpetrate crimes. Difficulty is locating money laundering practices: Every year, money launderers become more skilled, establishing an elaborate network of identities and accounts through which to channel their illicit activities which makes locating the false negatives hidden deep inside the mountain of valid transactions very difficult and time-consuming. The graph approach A graph or network is a collection of nodes and connections (also called edges). Graph analytics is a collection of analytic tools that enable the investigation of links between items of interest such as companies, individuals, and transactions. It assists data and analytics executives in analysing linkages in data and reviewing data that is difficult to evaluate using standard analytics. In the field of anti-money laundering systems, the concept of networks and connection analysis is fundamental because it helps expose hidden aspects of transactions that are not discoverable by any other means. When paired with ML algorithms, these technologies have the potential to trawl through hundreds of data sources and documents, allowing financial institutions and AML specialists to quickly uncover hidden patterns and relationships in transactions. Graph analytics is essentially a set of analytic tools that allow you to "dig down" into complicated interrelationships between businesses, individuals, and transactions. For example, a major international investment bank in the United States is utilising sophisticated graph analytics to strengthen its fraud prevention activities, especially fraud detection for debit and credit cards. The organisation is integrating graph analytics into its machine learning system to discover data links between “known fraud” credit card applications and fresh ones. As a consequence, the bank can discover more suspicious trends, reveal fraud rings, and close down fraudulent cards more quickly. The bank will save millions of dollars each year as a result. Graphs may be used to detect anomalous patterns, which can aid in the prevention of fraudulent transactions. Terrorist activity has been found in certain cases by examining the flow of money across interconnected banking networks. Fig 1 : Fraud detection with regular analytics and with advanced graph analytics can be visualised from Fig. 1. The use of graph analytics allows for the dynamic study of relationships within a huge dataset. It is possible to investigate and visualised who and what a client is linked to using data as diverse as an email, a phone number, a device, transactions, and so on. The detection of accomplices becomes very rapid A regular fraud detection case A tip or a detection system may occasionally flag a client or a transaction as suspicious. In this circumstance, it is vital to determine whether or not this particular questionable circumstance is isolated. The customer might be a member of a larger criminal ring, or the transaction might be part of a broader operation. In the absence of more information, it is critical to pursue as many leads as possible. This necessitates investigating what the customer or transaction are related to. Consider a simple payment made using a digital payment provider such as PayTM, PayPal, Google Pay, Amazon Pay, or Razor Pay to see an example of possible fraud and why it is so hard to identify using standard analytics. A user has opened a new account that is connected to their Bank X credit card. They have connected their phone number and email address to their account as part of the setup and two-factor authentication. The user uses an Apple iPhone X with the registered phone number as their device and starts a payment of Rs. 5000 to another account. Because the user is a new user with a new phone number and email address, there are no red lights or alerts in a standard financial services fraud detection solution at this stage (none of these have been associated with any fraudulent transactions in past). Regular analytics does not uncover anything strange or suspect and the payment passes through without being reported or refused. Use of Graph analytics on the case Deeper analysis with a native parallel graph analytics technology, on the other hand, offers a different image. There is a fraudulent activity related with a gadget, phone number, and stolen credit card six levels inside. Here's how it goes down: The payment's recipient account belongs to a user who authenticated the account with a Phone Number as part of the account registration procedure, and that phone number is used with a different device Apple iPhone Y. As the deep link analysis searches the history of previous fraudulent transactions for devices linked with those transactions, it discovers that this Device was used last year with a different Phone Number to set up a separate Account. This account initiated a payment that was subsequently discovered to be fraudulent since it was paid using a stolen credit card. Advanced analytics using graph analytics may go deep into the related data, in this case six links deeper, to uncover the link to earlier fraud in real time, and the payment transaction is refused as a consequence. As you can see, advanced graph analytics is required for real-time payment fraud detection — and this analytics identifies fraud three layers "deeper" than normal analytics. This disparity between normal and advanced graph analytics can result in hundreds of millions of dollars in fraud losses. Advanced graph analytics with real-time processing can process the payment transaction in under a second and then perform the multi-connections query on the related dataset. In other words, the system must check every connection along the path from the person initiating the payment to the ultimate receiver, the one involved in fraudulent Payment. Clearly, fraud detection is at the top of every financial services organisation's priority list – and this is unlikely to change. As fraudsters grow increasingly tech-savvy, it is critical for businesses to keep one step ahead of them. These deeper insights are enabled by advanced graph analytics, which complements conventional BI technologies and powers AI and machine learning. Hence, as a consequence, firms can anticipate and avoid possible fraud while also safeguarding their consumers.
- What blockchain won't solve for advertising fraud? Insightful 2020
Advertising Fraud is a rampant problem. Fraudsters, from faking user behaviours or stealing Organic/Google/Facebook converted users and tagging it as their own using programmatic mis-sequences is become a common problem for performance marketers. People or Group of people committing to advertising fraud in their head feel that they have been completely able to shadow the unethical practices, and have successfully created what we call a black box model. Today, even the most strict KPI's ain't safe, with advertiser paying almost twice for the acquisition of the same customer. Block-chained user flow, which is programmatically hashing the last attribute to the the next attribute. Any addition, deletion to the flow, can automatically raise alarms of suspicion. Market dominating leaders have already tested flows of block-chaining the user journeys, but are highly unsure on industry vide adaptability and success rates on B2B partnerships. While it seems promising for Google or Facebook to test these new capabilities, it becomes imperative for fraudsters to understand the hashing criteria to reverse engineer and show conversion theft legibly. Why networks/affiliates want to move in adopting blockchain? 1. Lesser transparency to the advertiser. The advertiser will be made to believe that their technology is cryptic, which is using blockchain, which helps build the trust back which networks and affiliates have lost over last 5 years because of advertising fraud. 2. They want to move away from the big data attribution. Over last 5 years, big data has provided advertisers not just understand how brand consumers behave but also how to create personalised experiences. On the other hand, big data has been a huge game changer for fraud detection. Majority of advertisers today deploy either in house or an outsourced 3rd party effort to keep a watch on fraud spends. This isn't good for networks or affiliates, as it makes their unethical game out in public. 3. Blockchain will give more darkness to the advertising fraud prevalent in the market, as it would become more decentralised and behave like a black box model. With technology, data science and machine learning creating a bigger view for marketers, now CXO's are looking for tools that can enhance their view further to make much bigger and better decisions.
- Com Olho ready with digital governance patent, single bullet solution for affiliate fraud & piracy
Com Olho which in 2020 became the first company in India to be granted a patent for non-rule based mobile ad fraud detection and prevention has created a single bullet solution for fighting the menace of affiliate fraud and content piracy. While working with top advertisers in India, the team realised the need for tech based digital governance to fight affiliate fraud. In India today, a lot of vendors are deploying rule based methodologies to fight the menace of affiliate fraud i.e VPN detection, disposable email and phone numbers detection, fake data fills and device farms detection. This methodology of detecting affiliate fraud is old school and leads to more affiliate fraud than it was at the first place. Addressing these problems, Com Olho has come up with proprietary system that leverages military grade encryption and serves it using real time API which has been a core research focus of the company over last few quarters. The company has beta-tested the product already and looking to bring this to market by end of this year. Affiliate fraud is not only impacting advertisers, but is also impacting consumers by stealing away sensitive data information. Over the last fews weeks of testing the technology, Com Olho has been able to detect tag-based affiliate fraud impacting leading e-commerce companies, financial institutions etc and government ministries. We have also seen a large amount of pirated content in circulation stolen from all the famous OTT players in India. Radhe, a movie recently released digitally under SKF banner has been compromised because of this menace, which has led to huge losses to the content makers. Using trademarked brand names, the fraudsters are aiming to spread mis-information, fake news and also earn advertising dollars through affiliates and google display network. Founder & CTO at Com Olho, Abhinav Bangia says, even with anti-ad fraud vendors in India, the problem remains unchecked for a simple reason, ineffective non-tech solutions. Instead of delivering tech-enabled solutions, vendors are focusing on creating blacklists and involving huge human bias for detection of ad fraud and content piracy. We are in final stages of filling the patent, and hopefully would address this unchecked problem plaguing our advertisers and content markers budgets and reputation.
- Ad Fraud is an Intentional Compromised State of Advertising Technology
If you have been in the ad tech industry, you would often hear people say "Fraudsters are always a step ahead in the industry". Can we conclude if the fraudster in the industry is some of the ad-tech vendors itself? Consider solving the case below by following the conversation. Case : Three people form the advertising industry. The advertisers always tell the truth. The ad-tech vendor never tell the truth. The fraud detection vendor alternatively tells truth and lie. The world's renowned explorer questioned all of them. The advertiser, ad-tech vendor and the fraud detection vendor. Let the 3 people be Jack, John and James not in the same order. Explorer : Jack, which section of industry do you belong to? Jack : I'm an Advertiser. Explorer : John, to which section do you belong to? John : I'm an Ad-Tech Vendor. Explorer : Was Jack telling the truth? John : Yes. Explorer : James, to which section do you belong to? James : I'm an Advertiser Explorer : To which section does Jack belong to? James : Jack is a Fraud Detection Vendor. Now that you have heard the conversation above, can you tell which person is the Ad-Tech vendor? A) Jack B) John c) James Once you arrive to the answer, you would be able to get a bitter insight of the advertising industry today. Below find an interesting structure of Ad-Tech ecosystem, understand the bridging layers here that lead to fraud. 1. A layer of semi owned dummy mobile apps are needed to steal data inventory from real publishers, fraudulent publishers and ad networks. This allows the ad tech company to mix traffic, shadow the original traffic sources not allowing transparency across supply chain. 2. A layer of semi owned dummy mobile apps are needed to simulate human behavior through bots after reverse engineering fraud suites which are build internally or externally. We at AdIQ, are building an encrypted inventory matching technology which would help us expose this layer of dummy apps with legal addresses that ad tech vendors use in the industry to gain inventory and game the system now and then. We are also studying what personality traits make up these cyber criminals in the market and how they been in the industry for over the decade. "What is clear is that we need to cut through the chaos and focus what is best for our advertisers, not anything else."
- Error 504 : Mobile Ad Fraud Found
Given all the developments in digital advertising over the last year, with Apple and Google announcing major platform changes, staying vigilant against mobile ad fraud may have taken a back seat. Mobile ad fraud, however, is never going away. Mobile Ad Fraud is a subset of ad fraud plaguing mobile based performance campaigns. It is a collective term used to describe a combination of tactics used to stop digital ads from being delivered to the audiences or spaces for which they were intended. These tactics often include the use of bots, click injection, click spamming, organic hijacking, device farms, SDK spoofing etc. These tactics allow ad fraudsters to syphon off enterprise’s ad spend dollars while the ads themselves fail to generate brand exposure, leads and sales because they were never seen by an actual person. Besides hurting the advertisers, mobile ad fraud also hurts publishers by driving down the ROAS and decreasing the overall value of ads. Advertisement-related frauds will continue to be a major threat in mobile environments in 2022. Last year broke records for ad spending. According to a recent forecast, global digital advertising in 2021 was expected to grow by 15.6% over 2020, reaching $705 billion — well above pre-pandemic levels. Unfortunately, this advertising boom also triggered mobile advertising fraud. As businesses kick off their 2022 marketing plans, there's one thing they shouldn't overlook — a strategy for combating mobile ad fraud to protect their return on ad spend (ROAS). According to a study, ad fraud costs the marketing industry an estimated $51 million per day, and these losses are likely to increase to $100 billion annually by 2023. Sophisticated nonhuman bots, which are actively involved in ad fraud, are responsible for roughly 18% of all internet traffic in the marketing business. Digital advertising operates within a complex system with many loopholes where fraud can infiltrate, but with a little guidance, advertisers can mitigate fraud that gets past prevention measures. Approaches To Fighting Mobile Ad Fraud Fraud is a moving and changing target, and it hides behind the performance numbers CMOs are looking for in the first place. The goal is to not wait until something major occurs to make you pay attention. The goal is to pay attention on saving ad spend that doesn’t take much time or resources from enterprise's marketing team. Look Beyond Install Numbers Examine your conversions, post-install rates and numbers using cohort. This is where you're more likely to notice anomalies like a strange device ID or email address, and then check into the behaviours linked with these potentially fraudulent identities. Click to install time is another metric to consider. Instal events that happen too quickly or in groups can be marked for further evaluation. Be Aware Of Your Audience Reach User acquisition is one of the most important aspects, however the farther your reach, the less trustworthy the traffic becomes. You'll be more exposed to fraud if you use lower CPIs or have a wider reach. There are only so many ad partners out there, therefore in order to meet demand and for client's growth, they may have to rely on marginal traffic. To stop suspicious traffic, make sure you have traffic verification methods in place. Mobile Ad Fraud Detection Some enterprises use mobile ad fraud detection software to spot invalid clicks across their programmatic/display advertising, as well as paid search and social channels. The software can detect clicks and impressions that are generated by bots on paid campaigns and then blocks them, thus preventing them from continuing to syphon money away from the campaign. Mobile ad fraud detection software relies on detecting patterns that resemble suspicious actions in an ad’s impressions, clicks, traffic or IP addresses — or a mix of all those data sources. It compares clicks on ads to its database, and if it detects an anomaly, it notifies users in real time so advertisers can analyse their data. Data Analytics Data analytics helps enterprises pinpoint sources of fraud. Advertisers can use data analytics tools to get a variety of performance indicators on their marketing efforts, such as web traffic across their digital assets and information on potential customers who interact with their ads. With this much bad data in enterprises marketing stacks, it’s no surprise that a significant portion of their total ad spend doesn't deliver any return on investment. Modern data analytics tools utilise machine learning to analyse massive amounts of data and discover anomalies that often indicate fraudulent activity. In turn, this helps enable advertisers to identify fraudulent traffic and prevent further damage by quickly adjusting their ad strategy and divesting from bad traffic in favour of good traffic. Verifying their data across multiple channels also helps enterprises prevent bad data from impacting the rest of their data set, ensuring that their ads reach real and actual target customers. The Takeaway Mobile ad fraud has been a major issue worldwide in the last two years, fuelled by rise in digital during the pandemic and it's projected to become an even more concerning issue in 2022. To get the most from their campaigns, enterprises will want to consider investing in solutions that validate the accuracy of their data and ensure that their ad budgets result in impressions and clicks that actually generate the desired results and values.
- How machine learning is a ‘requisite’ for ad fraud detection
Marketers/advertisers are bundled with data today. They are collecting data behind every touchpoint the consumer makes, right from click data, install data, engagement data, etc. In today’s world, there are 2 major activities marketers are involved in: Using click and install data, marketers keep investigating different forms of campaigns to drive bigger volumes down the digital funnel Using engagement data, marketers study channels of engagement and message throughout the lifecycle of a digital consumer to enable a higher LTV However, this isn’t enough to study whether the incoming data is attributed correctly or not. Vanity matrices today are merely numbers on a digital dashboard, but the correctness is immensely suspected throughout. Finding attribution manipulation can be problematic and estimating an analogical behaviour of the traffic to a constant is merely impossible. For the same, because of the problem and the largeness of the data, it requires machine led understanding of the data over time. Usage of filters, boundary conditions, threshold, etc gives a good descriptive statistical understanding of the data in hand and can estimate rule-based anomaly finding. However, this misses on predictive and prescription data science. AI In Advertising Fraud In order to build a true machine learning model, one must look at the data very closely and build a homogeneous learning model that only injects consumer journey behaviour as a learning variable. Examples of Common Ad Fraud Schemes in which ML helps : Some sub-publisher based mobile application’s track consumer’s keyword search in google play store or iOS store, and if a consumer searches for a particular advertiser that is active and running performance led campaigns, a click is generated. These clicks hijack traffic from other networks and steal the organic traffic as well. A CTIT learning might not be enough to highlight such an anomaly, as these hijacks generally have a CTIT of more than 20 seconds. Some sub-publisher based mobile application’s track customer’s’ APK changes. In case, a customer installs a particular android or apple app package, a click is generated to hijack this form of traffic. Generally, these lie in the CTIT anomaly limit of 20 seconds, but a back timed click is sometimes even injected to claim the attribution. Incase of installs and engagement based KPI for performance campaigns, APK drops are a common thing for acquiring new customers from tier 2, tier 3 and rural India. The sub-publisher-based mobile application works as adware and takes the rights of installing new-APK on the mobile device. These kinds of installs are generally greyed at half a cent at the value to many aware marketers. Marketers opt for it for reaching the quick 1 million mark, or high listing on google play or apple store. However, these installs are generally not brand-safe and might allow data theft. Finding attribution manipulation is not easy. The objective behind the mere click manipulation is to hijack the last-click attribution model for monetary gains. Anyone with mere contacts of these adware/malware enabled apps can help one in growing the business in no time which in return fuels corruption, fake news, tax evasion and cross-border cyber warfare. Detection for these kinds of traffic sources is a must, as it incentivises the above, but also affects digital consumers and the country in the long run. As published in : Financial Express
- Why is bot measurement important for brands
According to Elon Musk, Parag Agarwal, the CEO of Twitter, has publicly refused to present proof that Twitter has fewer than 5% of accounts that are fake. Hence, CEO of Tesla, Elon Musk’s deal to buy Twitter, for approximately $ 44 Billion, might not see the light of the day due to massive mismatch between Twitter’s total and real user’s database. In fact, Twitter earlier this year also admitted that it had been overestimating its user base by 1.9 Million users every quarter for the previous three years. The platform in March 2019, launched a feature that allowed people to link multiple accounts together in order to conveniently switch between accounts. However, at that time an error was made at the time, such that actions taken in the primary account resulted in all linked accounts being counted as mDAU (Monetizable daily active users). This once again has drawn attention to the prevalence of bots and fake accounts on social media platforms. This now raises a bigger question – Are Twitter and other social media platforms as transparent as they are supposed to be? The answer is crucial since many enterprises and brands are spending 30-40 percent of their digital ad spending on social media and influencer marketing, unaware that a significant amount of their social media base could be fake. What exactly is a bot? To measure the prevalence of fake accounts and bots on Twitter, a clear definition of them is necessary. Fake accounts are those that impersonate people. Bots, on the other hand, are accounts that are partially controlled by software and can automatically post content or carry out simple interactions, like retweeting. Bots are meant to either skew enterprises’s advertising matrices or to mix with existing human traffic to increase financial gain for ad fraudsters. Bots can be used to increase impression, click and engagement matrices and are often mixed with traffic that is either organically hijacked or hijacked via last click attribution. If you are a website owner, it becomes your duty to provide such content to your audience which your website visitors and advertisers can trust upon. After all, advertisers and readers are like the two wheels of the bicycle of a website’s bottom line because they help us in generating revenue over our content. And, Invalid Traffic (IVT) or bots can majorly affect your relationship with your audience. Importance of bot measurement Bots and fake accounts are a known growing evil in the digital ecosystem becoming more sophisticated in today's world of emerging AI and ML technologies, portraying real and human-like persona. Automated bots can generate massive volumes of conversation, chats and trolls on social media platforms. While fake bots/ accounts may appear as an easy and simple way to gain followers and promote your brand, they can actually dilute your brand’s image and credibility. Bots can reduce engagement and lead to higher customer acquisition costs. Consider a campaign where the marketers spend money on targeting and retargeting such bots. While the digital medium is becoming the most important medium for advertisers, accuracy still exists as a challenge across social media platforms and marketers should not judge performance and effectiveness solely based on these platforms. What is the industry's strategy for dealing with bots? The majority of Twitter’s revenue comes from selling ad space on its platform to global advertisers. And to attract advertisers, it requires a huge and growing user base. In 2021, Twitter generated more than $4.5 billion in advertising, up from $77 million a decade ago. Leading car and other significant brands are partnering with Twitter for marketing campaigns and product launches. Bots and fake accounts exist on all social media platforms and it is an open secret to all advertisers. Marketers now wonder if the controversy will have an impact on their enterprises and ad revenue. Many advertisers employ bots for promotional activities in order to push for organic communication. However, many of them are consciously making decisions to not use such bots, releasing it will affect the brand in the longer run. Customer lifetime value is becoming the key focus for the enterprises, and they will have to look beyond the campaign numbers. Enterprises do realise how damaging bot traffic can be to their digital advertising strategy. Bot traffic leads to businesses wasting money on fraudulent ad clicks that will not generate any revenue. With distorted numbers that can be terrible for enterprises, it's critical to understand how to identify bot traffic and protect your digital campaign from it in the most effective way possible. Advertisers who wish to drive performance via social media won’t be affected right away. However, enterprises and brands may want to decrease their budgets or pull out until all of this gets cleared. There may not be an immediate impact, but in the longer run, revenue will get affected when the response of the ad spend won’t come out as expected.
- Clickjacking : Methods & Ways
To begin, let's define what clickjacking means and how it can lead to ad-fraud. When the user clicks on the hijacked link, the attacker will start downloading the malware. In a certain area of the screen where the attacker knows that the user is clicking, the attacker can replace the real and hidden cursor with a fake cursor, and manipulate the screen in such a way that the user knows that they are clicking on a malicious link instead of clicking on something else. The successful Tweet bomb attack in 2009 was a continuous loop. Users have clicked the tweet link to open the web page, clicked the link to open the tweet, and then tweeted the link to their account to encourage followers to click the link. Clickjacking is one of the leading causes of ad-fraud in the tech industry. Clickjacking or clickjacking is a network attack in which an invisible malicious link is placed on the user interface of a website. Clickjacking can facilitate or facilitate other cyber-attacks, such as XS. Classic clickjacking means a situation where a scammer deploys a secreted layer on a web page to manipulate the targeted user's cursor, causing the target to click. Clickjacking is an attack that makes the target user click on parts that are indistinguishable or disguised as different items. Clickjacking attacks attempt to induce users to click on unexpected elements on web pages. The attacks are generally carried out by allowing users to see invisible HTML elements or iframes at the top of the page. On the page that is clicked, the attacker loads the page as the original page with a transparent overlay and prompts the user to take action, even if the result is not as expected. The user believes that they have clicked on the visible page, even if they just clicked on an invisible item or moved to an additional page from the visible page. An example of a click page that causes users to take unwanted actions by clicking on a hidden link. In similar hacking attacks, if a user clicks on the current link, they will be tricked into clicking the Facebook button. How does it work? As we have learned that clickjacking is basically an interface-based scam or an attack which targets the users and deceives them into clicking on an actionable content on a concealed websites or additional content on trap websites. Network users can win prizes by clicking the link provided in the email or clicking the button to visit the decoy page. Clickjacking, commonly referred to as a countervailing attack, refers to the use of large amounts of transparent or opaque coatings by scammers to get specific users to click on the page they want to click, rather than a button or link on the homepage. The attacker tricked the network user into pressing a spare "hide" button to make payment to the account on the website. This is a complex form of click spam, and it is even more insidious because the user's net CPI payment device may be hijacked by criminals. In addition, click injection (also known as clickjacking) has long been one of the most popular types of CPI ad fraud. Click on malware that can be hidden in applications, legitimate applications downloaded from third-party app stores, people who sent you copies of false click reports, or network hijackers click to perform detection of potential client installations. Clickjacking is one of the most common ad-fraud and click spam mapping methods. Clickjacking is a click-to-install mobile ad fraud that sends a fraudulent click report immediately after the actual click. Click flooding (also known as click spam) is another type of scam that occurs when bad actors report a large number of fraudulent clicks in the hope of obtaining credit for biological application installations. Clickjacking is classified as a user interface attack (or repair), which is a malicious technique that tricks users into clicking on something outside of their perception, revealing sensitive information, and allowing others to control it. By clicking on harmless objects, your computer, including websites. The most common method of clicking is to show users a combination of two or more hierarchical websites or browser windows to stimulate some motivation to click at a specified location. Finally, the user clicks on the part named iframe on the target web page with the cursor, so that the browser window can be divided into several parts so that different elements can be shown or hidden, and attackers can be launched as necessary. The attacker first loads the vulnerable web page into an iframe, places it completely transparently, and places it in front of the created malicious web page to trigger clicks in the appropriate location. The attacker then hides the iframe behind a harmless link on the website (such as the New York Times headline or Digg button). When the victim clicks on the link, the cursor will click on the iframe. For example, an attacker may want to entice users to purchase items from a retail website, but the item must be added to the shopping cart before an order can be placed. This attack is different from the CSRF attack in that the user must take an action, such as clicking a button, and the entire request must be spoofed without the user's knowledge or input. We have developed a new detection method for this type of attack, which is based on the behaviour and reaction of the active content on the website when the user clicks on the request. In our experiments, we found that our detection method can detect advanced and scalable vector graphics attacks (SVG-based attacks) that most modern tools cannot. Having understood click hijacking it must not be hard to understand how this is one of popular means of conducting ad-fraud. How to prevent? The clickjacking scam/ attack cloaks a page where the targeted user believes the iframe, and then displays invisible elements at the top of the frame. To ensure that your site is not used for clickjacking attacks, you must ensure that malicious sites cannot wrap it in an iframe. This can be made possible by instructing the browser directly via HTTP headers, or in older versions of browsers by use client-side JavaScript (frame termination). Some suggested ways include: Framebusting or framebreak: Before support for new HTTP headers becomes widespread, website developers must implement special frame buster (or frame killer) scripts to prevent their pages from being framed. To be assured that this is the current page, the preliminary framebusting script verifies and checks top.location; if not then, top.location is set to self. However, these scripts are easily blocked or ignored by external frameworks, so more complex solutions have been developed. Even so, there are still plenty of ways to bypass the more complex frame-breaking programs, and such scripts should only be used to provide basic protection for older browsers. The existing method suggested by OWASP is to hide or conceal the complete body of the HTML document and show it only after the verification page has no frame. 2. X Frame Options: The best solution at this point may be to use the HTTP XFrameOptions (XFO) response header in the server response. Microsoft on its Internet Explorer 8 and later versions originally introduced and formalised RFC 7034, in which the XFO header is employed to postulate and specify if the page can be embedded in & lt; frame & gt;, & lt; iframe & gt;, & lt; embed> or the element & lt; object>. The header supports three possible commands: deny to block all framing attempts, same origin only allows framing of pages from the same source, or allow form to allow pages of a specific URI to be framed. However, several browsers (including Chrome and Safari) don't support allow from, so if you need to specify the font, it's better to use CSP (see below). For overall anti-frame protection, one only needs to postulate XFrameOptions: deny or XFrameOptions: sameOrigin in the server header. 3. Content Security Policy with frame ancestors: The ContentSecurityPolicy (CSP) HTTP header was originally developed to prevent XSS and other data injection attacks. However, it also provides a frame ancestors directive to specify the source (in ,
- The Importance of Ad Fraud Detection in the Digital Landscape
Cybercrime and cyber threats do not have a very long or illustrious history. In fact, it just came into the picture when the internet was booming. Despite its novelty, its severity cannot be understated. Cybersecurity experts predict that global cybercrimes are expected to rise and could result in $10.5 trillion losses annually by 2025. As a result, there has been a necessity for more comprehensive and organised cybersecurity measures to prevent rising crimes on the internet. Furthermore, various industries in India, particularly in the aftermath of the COVID outbreak, are experiencing massive engagement of audiences and customers through digital means. Resultantly, it makes them more and more vulnerable to digital frauds and attacks. An Overview: Digital Ad Fraud Cybercrime isn't confined to banking or financial frauds only, that defraud customers of their hard-earned money. Instead, fraudsters are becoming more inventive, developing new malicious ways to steal money from marketers and major brands as well. Digital Marketing was envisioned as the future of marketing, predicted to overtake the traditional methods, because of its immense potential. However, it became a hub for scammers looking to deceive marketers and brands. In 2021, $59 billion were reported in loss, due to digital ad frauds. Networks of malicious bots are costing brands every day and this is happening at an alarming rate. Enterprises have started spending more and more on digital advertising, which has also piqued the interest of criminals looking to make quick money. The more money an enterprise spends on advertising, the more it stands to lose due to digital ad fraud. Fraudsters tend to use fraudulent practices such as Click Injection, Ad Stacking, Domain Spoofing, etc to defraud marketers. As a result, ad fraud detection has become an essential step in ensuring the safety of brands and the interests of their customers. Importance of Ad Fraud Detection Like any other cybercriminal activity, digital ad frauds are also relatively new. Thus its modern roots make it challenging to combat such frauds. In most cases, marketers are uninformed or unaware of the fact that they have been scammed. Thus, it is more important than ever to fight such malicious activities. Most ad fraud affects the advertising budget of an organisation without producing results. These ad frauds claim credit for coincidental site visits or generate fake clicks and impressions, which results in wastage of ad spending of marketers. Eventually, this will have a negative impact on the marketing strategies of the enterprises and wasted efforts. In addition, it can also do reputational damage to brands, when associated with inappropriate or objectionable content. When a brand is a victim of ad fraud for an extended period of time, it can significantly lose its potential customers. Heading towards the good part, it is safe to say that the Indian startup ecosystem is fortunate to have some of the most talented and committed individuals who are determined to tackle these problems. Many of these young entrepreneurs have recognised the importance of cybersecurity, especially in this ever-growing digital space. A recent article published by YourStory details the path and goals of six Indian cybersecurity startups that are redefining the digital security landscape. We, at Com Olho, are proud to be able to share this platform and convey our goals and aspirations; to remove digital ad fraud from our digital landscape. All enterprises, large and small, should understand the importance of digital security. With the rise in cyberattacks, Com Olho has realised the significance of cybersecurity solutions and is committed to assisting brands and marketers to safeguard their interests. Com Olho takes pride in actively contributing to the advancement of India's cybersecurity business and is determined to add value to this ever-growing industry. We are a Gurugram-based cyber security startup that uses patented technology for non-rule-based digital ad fraud detection. In Conclusion Every organisation must protect itself from the costs of ad fraud and they must detect it early and put a stop to it as soon as possible. Com Olho, in this aspect, has always helped brands and is on a mission to assist Enterprises and the Government to create a Digital Safe India.
- Elon Musk's takeover of Twitter and its impact on Brand Safety
Last year, when advertisers and marketers expressed their concerns regarding the safety of their brand, social media site Twitter claimed to have placed their interests as its top priority. Caitlin Rush, the Head of Global Brand Safety Strategy at Twitter stated, “Brand safety is not only about brands, but it is about people.” She further added, “When we focus on the safety of people, we also protect brands from the reputational damage of supporting things like hate, abuse, and misinformation with their ad dollars.” This has been viewed as Twitter’s response to safeguarding its ad revenue from brands, accounting for 4.5 billion USD. However, Elon Musk's decision to take over Twitter, and his outright plans with the platform, may worry many brands. Ad income accounts for roughly 90 percent of Twitter's total revenue. It still is nowhere close to its competitors and other social media platforms. Moreover, Twitter's user reach is also substantially smaller than its competitors, with around 200 million users seeing advertising compared to 800 million on LinkedIn and almost 2 billion on Facebook. It is understandable, given that Twitter has a niche audience, and marketers prefer platforms with a large user base and engagements. Nonetheless, Twitter has been hell-bent to make its platform as much accessible for brands as possible. This has been evident in their various policies, including content moderation, manual human review assisted with machine learning, and brand safety policies. In addition, Birdwatch and Conversation settings are two other recent Twitter applications for safe conversations. It allows users to recognize potentially misleading information in Tweets and then report or add notes that provide context. More than 11 million individuals have used the conversation settings that allow everyone to determine who can reply to their Tweets. And there have been further efforts by the company to make it more accessible for brands. Until now. The discussion around an edit button and its impact on Brand Safety Earlier this year, Elon Musk conducted a poll, surprisingly on Twitter itself, expressing his desire to have an edit button on Twitter. This feature has been long missing from the platform and would allow users to edit and make changes to their posts. Surprisingly, over three-fourths of over 4 million voters agreed that an edit button is needed. Meanwhile, Twitter also announced that they are working on an edit feature to be implemented on their platform. This is likely to be good news for users and brands, who can always have an option to modify their earlier tweets. Brands are always mindful of their status, and any objectionable posts on a platform with 300 million monthly active users can always result in backlash. On the other hand, Twitter has always been viewed as a platform where real conversations take place. Your viewpoint or stance is constantly in the public domain since you can't alter your tweets or statements. And that is what makes Twitter unique. The addition of an edit feature may detract from the distinctiveness of Twitter posts, as a result, lowering their relevance. For Marketers, it is important to identify and select the right medium to market their product, while ensuring brand safety. An edit option can have a significant impact on how marketers approach campaign plans, and it will undoubtedly affect Twitter's forthcoming businesses. Brands have always welcomed any initiative that allows them to be associated with posts or tweets, that won't do them any reputational damage. Twitter has always shown efforts to make its platform a safe haven for brands of all sizes. All of that could change if Elon Musk takes over the social media platform later this year. Elon Musk and his plans with Twitter Just days after his post about the edit button, news surfaced that Elon Musk will now acquire Twitter. The CEO of Tesla and SpaceX has agreed to buy Twitter for $44 billion, and if it goes through, it'll be one of the largest leveraged buyouts ever. Now that it is evident that Elon Musk will be the owner of the platform, we are not yet certain how the platform is going to function in the future. And one of the concerns for marketers is the billionaire’s repeated admiration for free speech. This will have a direct impact on the principles that the platform has been building over the years. And now, with limited content moderation and the freedom to express oneself freely, the platform may introduce new complications. Giving a free speech platform, for example, has the potential to spread hate speech and other forms of misinformation. As a result, no brand wants to be associated with such content and may opt for a different medium. Some advertisers are worried that Elon Musk's potential takeover of Twitter will push the app away from the brand safety path that Twitter has established through standards and relationships with the advertising industry over the years. Furthermore, several advertising executives have stated that if Elon Musk removes the features that allowed Twitter to remove objectionable content, they are willing to allocate their ad spending elsewhere. In Conclusion Elon Musk has made it clear that advertising is not a priority. He said that he wants to loosen the service's content moderation policies, which marketers say have helped keep ads from appearing alongside hate speech and misinformation. Additionally, he has mentioned making money from Twitter in other ways, such as charging some users to use the service. It will be interesting to see how the world's richest person manages to strike a balance between his vision for Twitter and the prior business partnerships that the platform has built through its security measures.
- The mandate on VPN and its implications on Data Privacy and User Safety
It was last year when the Government of India reported that they were working on a measure to prohibit the use of all types of VPNs (Virtual Private Networks) in the country. Regarding the same, the Indian Government has now mandated all the VPN providers to collect and store data of their users for five years. Although they stated that this is being done amid security concerns, the impact it can have on all parties involved is alarming, to say the least. As per a new directive issued by CERT-IN (Indian Computer Emergency Response Team), companies will now be required to store user data, including their IP addresses, emails, names, contact numbers, and addresses, for up to five years even after a user has terminated their service. Furthermore, the ministry can request this information at any moment, and VPN providers will be required to cooperate under the new regulation. As a result, there are growing tensions among the service providers as well as users. The ministry said the move was an effort to “coordinate response activities as well as emergency measures with respect to cyber security incidents” and help it fill “certain gaps” that cause hindrance in handling cyber threats. What are VPN services? Simply put, Virtual Private Network (VPN) allows the users to establish a secure network connection. This way, the service protects a user's identity by hiding their device's IP address, encrypting their data, and routing it through secure networks.There are more than 270 million Indians who use virtual private networks (VPNs). People use VPNs to get access to websites that might have been restricted by the government and browse the internet safely, without being monitored at all. Additionally, it can also be used to browse internet content accessible in other states or countries or utilise it for privacy on the internet, which is rife with marketing tracking. Another common use for VPN is to protect oneself when connecting to a public network. When connected to a public Wi-Fi, users often expose themselves to the risk of security breaches and data theft. VPN enables the user to establish a secure network connection. It encrypts internet traffic and conceals a user's identity, making it difficult for third parties to track and steal user data. However, these regulations will simply contradict the established intent of using VPNs. If there is no data privacy and user data are not protected, users will be hesitant to use VPN services, affecting the businesses of these service providers. The use of VPNs in corporations Additionally, VPNs are also used by organisations for data protection. Many companies and enterprises instruct their employees to use an internal VPN to access the office network. However, their use of VPN differs significantly from that of the general public. A business VPN, as it is called, is uninterested in surfing restricted content, but rather it is used to track its employee’s digital footprint. In some ways, this is what the government intends to achieve with the country's new VPN mandate. The new regulation will most likely not affect enterprises or private VPNs since they already collect user data and information for so-called “data and user safety”. However, it will be interesting to see the impact of this regulation on major public VPN service providers. Overall Impact According to several reports, as soon as the new regulation surfaced, major VPN service providers in India, like Nord and Surfshark have stated that they will relocate their servers from India instead of complying with the new rules. This was expected since most of these services prioritise data privacy and user safety. More importantly, these service providers offer a no-log policy, which means they don't keep track of what users do with their VPN. As a result, they won't be able to assist the ministry with any data they might request, and thus, it seems difficult if they will be able to comply with these regulations. Only if these VPN services adjust their practices in a way that makes them less secure can they comply with Indian regulations. However, this will simply go against their promise of securing the user data and providing data privacy. As a result, other VPN providers are likely to dismiss their operations in the country. VPNs that do not comply with Indian regulations will be temporarily blocked. In Conclusion VPNs indeed allow users to cloak themselves, allowing them to engage in malicious activities which could be a concern. However, many experts consider these measures to be excessive. These rules are likely intended for state-sponsored surveillance and defeat the purpose of user privacy. They have been designed such that, to drive all VPN services that provide privacy and anti-censorship out of the nation. By the looks of it, it appears that the government has taken the first step in achieving its initial goal of outright banning VPN services. Whether VPNs comply with the new rule or not, it is the user's privacy that will be put at risk. The new VPN rules in India will take effect in June. For the time being, this will be strictly enforced. Interesting fact: Many countries that either ban or regulate VPNs include China, Russia, Iraq, North Korea, Belarus, the United Arab Emirates, and Oman.
- Beginning my second year at Com Olho with exponential growth.
“Never doubt that a small group of thoughtful, committed people can change the world. Indeed, it is the only thing that ever has.” – Margaret Mead I was the first employee at Com Olho. And I believe that the best analogy for what it’s like to be the first employee is that it's extremely similar to the experience and feelings of being a cofounder. I was a part of every conversation and every decision. The open culture and transparency between senior management and other employees is one of the best aspects of Com Olho. I joined Com Olho with no expertise in marketing, but with a strong belief in the company’s mission - “To assist Enterprises and the Government to create Digital Safe India.” However, as I reflect on my journey, the opportunities that have been provided to me have allowed me to grow both personally and professionally. I'm getting goosebumps today thinking about how far we've come. In the last one year, I have gained significant insight into where my true strengths lie by wearing many hats. Nothing makes me happier than taking on new tasks and overcoming unexpected problems, or, to put it another way, stepping outside of my comfort zone. As the company grew and pivoted, I adapted and moved from one set of responsibilities to another. Com Olho has provided me with a diverse range of experience that has helped me advance in my career. It takes commitment to build a successful business. Working hard entails more than just putting in long hours. It's all about commitment to one's belief and aiming for greatness. And the beauty of working here at Com Olho is that everyone works hard towards the same goal to get it done. Working here has been an exciting journey and an amazing learning experience. I'm grateful to our Co-founder, Abhinav Bangia for believing in me from the start, giving me responsibility and the freedom to do whatever I wanted. It has equipped me with invaluable hands-on experience, allowing me to grow my skills, and knowledge. I believe I still have a lot to learn and grow in, and I'm looking forward to doing so with Com Olho. Connect with me on LinkedIn: Link
- Reading large CSV files in Python - A perpetual problem
The growing pace of data is exponential in today's society, where every business and institution is transforming itself into a data-savvy entity. As a result, dealing with large amounts of data has become necessary. The CSV (Comma-Separated Values) format is one of the most frequent ways to store data efficiently. Importing a large CSV file directly into a Python script can cause an 'Out of memory' error or a system crash owing to a lack of RAM. The internet has plenty of tips and strategies for reading large CSV files at once, such as defining the chunksize of the data in the pd.read csv() command or utilising Dask dataframes or Datatables. After extensive testing and hours spent developing the best code to read massive quantities of data, I personally believe that all of these solutions have some form of barrier at some point of time. For example, defining chunksize and breaking the data into chunks necessitates an extra step of concatenating the data into one dataset, which takes almost as long as simply reading the data. And the first obstacle with Dask dataframes is specifying the dtype for all of the columns (even when there are 200+ columns); second, dealing with Dask dataframes is not as straightforward as working with Pandas dataframes. Following extensive research, one feasible and efficient method for reading large dataframes is to not read them all at once. This leads us to the concept of 'Structurization.' Most datasets can be divided into subsets based on the year, quarter, month, day, or any other criterion. Creating subsets while saving the data according to the datetime column makes it very simple to read and concatenate the required data. Amongst the various ways to create subsets of a dataset, one very efficient way is described below: 1. From the timestamp column in dataframe, create a new column of just the Year (or Month, or Date): df['year'] = df['timestamp'].dt.year df['month'] = df['timestamp'].dt.month df['date'] = df['timestamp'].dt.date 2. Use groupby function on one of the columns that you created above: grouped_df = df.groupby('year') 3. Using for-loop, you can print all of the data-frame groups created and their shape: for name, group in grouped_df: print(str(name)) print(group.shape) 4. To save the subsetted groups as CSV in a folder, use the same for-loop as above and specify the folder path: output_folder_path = "C:\\Users\\ABC\\year_wise_files\\" for name, group in grouped_df: output_file = str(name) + '.csv' output_dir = Path(output_folder_path) output_dir.mkdir(exist_ok=True) group.to_csv(output_dir/output_file)
- Accelerate your path to GDPR and India's PDPB compliance with Com Olho
What is GDPR? The European Union (EU), 20 years ago through the Data Protection Directive 95/46/EC introduced its data protection standard. Since the European Union needs each member state to implement a directive into national law, Europe ended up with a patchwork of different privacy laws across different countries. Additionally, increasing security breaches, rapid technological developments, and globalisation over the last 20 years saw new challenges for the protection of personal information come to the forefront. In order to address this situation, the EU developed the GDPR, which is directly applicable as law across all member states. What is India’s PDPB? India's Personal Data Protection Bill (PDPB) is one of the most comprehensive data privacy laws in the world. The Personal Data Protection Bill (PDPB) will impose obligations on practically all businesses operating in India. PDPB requires businesses to reassess all of the company's data processing practices, policies, and safeguards. Why does GDPR and India’s PDPB matter? With the increase in user-generated data and the exponential industrial value of data, it’s becoming vital that necessary steps are being taken to protect the data rights of the citizens. Data protection regulations ensure the security of individuals’ personal information and regulate the collection, usage, transfer, and disclosure of the said data. They also provide access to data of the individuals and place accountability measures for organisations processing personal data information and supplements it by providing remedies for unauthorised and harmful processing. Privacy laws like the EU’s General Data Protection Regulation (GDPR), and India’s PDPB have changed two things: They acknowledge that devices like smartphones are an intrinsic part of a person’s identity, and hence, any data and information that can be used to profile an individual comes under the ambit of laws; and These laws articulate what is consent and that it should be free, informed, specific, clear, and capable of being withdrawn. How is Com Olho GDPR and India's PDPB compliant? Privacy, security and protection of the customer data are shared responsibilities between the clients and Com Olho. This shared responsibility in the context of the General Data Protection Regulation (GDPR) is defined by two key actors: Data Controller: Determines how personal data information is processed and the purposes for which it's processed. Data Processor: An entity that maintains and processes personal data records only at the controller’s command. India's Personal Data Protection Bill (PDPB) scope is broader than General Data Protection Regulation (GDPR). PDPB regulates the processing of personal data by the state, any citizen of India, or any individual or body incorporated or created under Indian law. Com Olho ensures that the data rights access fulfilment — and automate processes for client’s individual requests. Under India's PDPB, data principles receive certain rights similar to those covered by GDPR. These data rights include: – the right to access data – the right to correction – the right to data portability – the right to erasure – the right to be forgotten Accelerate your path to GDPR and India's PDPB compliance with Com Olho Com Olho is committed to help businesses develop a strategy to achieve GDPR security and India’s PDPB compliance. We give our clients a SaaS advantage by offering service that is designed to be secure at every layer—for their entire business. Managing your business’s data is easier when there is one centralised location you can trust for storing it, instead of it being spread across a range of different storage media and what better source you can trust than your own server. Com Olho stores and maintains the clients data by deploying AI agents on the clients server itself. This reduces the risk of data theft/manipulation and offers simplicity, with a single set of policies and standards for your business processes. Our intelligent and secure service- lightens the load for administrators and users alike, allowing you to focus more on your business. In a constantly changing regulatory landscape, Com Olho can help your organisation address regulatory compliance more efficiently and easily. Businesses all over the world are focusing on ensuring their systems, processes, and policies support GDPR and India’s PDPB guidelines. All their teams continue to be tasked with implementing changes in the way they manage processes, people, and technical controls in order to comply with the legislation. Com Olho welcomes the positive changes the GDPR and India’s PDPB has brought to our services and we remain committed to helping our clients address GDPR and India’s PDPB requirements that are relevant to our services.














