July 24, 2015 By Douglas Bonderud 2 min read

To empower their brand, companies must spend on advertising. As print effectiveness continues to fall, businesses are compelled to seek out online alternatives — and tech giants like Google, Facebook and Yahoo are happy to oblige. According to Fortune, however, there’s a problem: While Internet bots account for more than half of all ad views, they’re nonetheless counted as impressions, and the views are billed to unsuspecting companies.

Now, the Trustworthy Accountability Group (TAG) has joined forced with these technology heavyweights to create a bot blacklist that should help clean up online advertising.

Why the Blacklist?

With a host of metrics to choose from, shouldn’t marketers and companies be able to pinpoint which ads make the biggest impact and which are ignored by online consumers? Part of the problem is choice: Are clicks or page views more telling about ad impact? Is time spent on a page more telling than unique monthly visitors?

There’s also another, more serious issue: As noted by Fortune, “a massive chunk of the advertising market is based on smoke and mirrors, or even outright fraud.” This can happen as a result of pixel stuffing, where ads are crammed in small spaces, or ad stacking, where multiple ads are shown layered one on top of the other. Some companies employ humans to click on ads and record impressions, while many others leverage the much faster route of using bots programmed to scroll and click through sites just like typical consumers.

The result? Companies have no idea if the ads they’re paying so much for are actually getting noticed and driving sales or if they’re victims of a bait and switch.

Robot Revolution

According to Threatpost, TAG has a possible solution: A blacklist of bad-IP data mined from Google, Facebook, Yahoo and other high-profile advertising platforms. While it’s not often that tech giants see eye to eye, they now have a common goal: If robot IP traffic dominates their data centers and drives down the value of ads, buyers will start looking elsewhere for human views.

With Google raking in over $50 billion in ad revenue, solving this problem is a high priority. With 8.9 percent of all clicks blacklisted under the new pilot program, there’s already a significant margin of error to correct. And with some 60 percent of all Internet traffic generated by robots and then sent through corporate data centers, there are other advantages to getting this problem under control: Fewer bots means better network performance.

Right now, tools like URL Spirit and HitLeap are generating millions of fake ad requests per day and raking in millions for malicious actors. Companies are largely held hostage by the need for digital advertising; without online campaigns and targeted ad placement, they risk falling behind the competition. But the market at large is being duped by robo-clickers and bot-scrollers designed to mimic human behavior and clog up data centers. Ideally, a TAG blacklist powered by IP data from some of the world’s foremost tech companies should help block the bad guys and bring down the bots.

More from

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

4 ways to bring cybersecurity into your community

4 min read - It’s easy to focus on technology when talking about cybersecurity. However, the best prevention measures rely on the education of those who use technology. Organizations training their employees is the first step. But the industry needs to expand the concept of a culture of cybersecurity and take it from where it currently stands as an organizational responsibility to a global perspective.When every person who uses technology — for work, personal use and school — views cybersecurity as their responsibility, it…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today