Newsletters Welcome, Guest Log In | Register

Data Security

Securing your data and network, inside and outside the perimeter

About this Blogger RSS

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

4

Fighting off Click Fraud

Posted by Ralph DeFrangesco Sep 21, 2009 9:16:13 AM

According to a recent posting at Click Forensics, a company that improves traffic quality for the online advertising community, a newly discovered botnet is capable of hiding itself as search ad traffic and fooling search engine filters. The botnet, dubbed the "Bahama botnet" because it is tied to 200,000 domains mostly in the Bahamas, but now also in Amsterdam, the UK, and Silicon Valley, affects online marketers who use pay-per-click advertising. The Click Forensics researchers believe that this botnet is controlled by the same people who are running scareware attacks that have affected The New York Times, among other sites, in recent weeks.

 

If you click through to the video in the Click Forensics post, you can see a demonstration of the click fraud working through searches on Google and Yahoo. Size does not frighten scammers when it comes to click fraud; Microsoft is vulnerable the scam, too. Microsoft filed a click fraud lawsuit against three people earlier this year claiming they made $250,000 in profit off of their online advertising service.

 

As security professionals, we have to keep an eye on click fraud from two perspectives: first, our Web sites might be vulnerable to it. When there is a will, there is a way, so don't think you are immune. Second, users are our weakest link. They are vulnerable to click fraud and can possibly expose our networks to malware. And click fraud can be an especially tricky area for user error, since end users often see no indication that anything is wrong as they go about their activities -- such as performing searches, in this case.

 

So how do we defend against click fraud? I offer the following advice:

 

  1. Use a scoring algorithm to detect and document click fraud. Pay-per-click advertising can be predicted using statistical methods.
  2. Measure traffic quality with Click Inflation Index (CII).
  3. Employ click fraud defense software.

Add a comment Leave a comment on this blog post.
Sep 22, 2009 3:23 AM Guest Roger  says:

I would like to suggest http://www.ClickMeter.com as an easy to use online service (link tracking tool) to monitor clickfraud. This service is free

Sep 22, 2009 7:02 AM Guest Lisa H  says:

Eventually we won't have to worry about PPC and click fraud at all. http://www.bravenewme.com/2009/09/paid-search-ppc-without-keywords/

 

Sep 22, 2009 9:39 AM Ralph DeFrangesco Ralph DeFrangesco    says in response to Roger:

Roger,

 

A slick little tool. Thank you for the link.

 

-Ralph

Sep 22, 2009 9:40 AM Ralph DeFrangesco Ralph DeFrangesco    says in response to Lisa H:

Lisa,

 

Yes it would, but I think we are a long way off yet.

 

-Ralph

Lowering Your IT Costs with Oracle Database 11g Release 2

This white paper identifies the key capabilities a database management solution needs to successfully deliver more information with higher quality of service, make more efficient use of IT budgets, and reduce the risk of change in data centers.

Software Forum: Information On Demand Virtual Experience

This interactive virtual forum presents leading IT experts providing the insights you need to turn your information into a strategic driver for innovation, business optimization and competitive differentiation.

Data Management Solutions

Data management and storage solutions, tips and best practices to improve the scalability, reliability, and accessability of your data.

Security Information and Event Management

Best practices, strategies and technologies to help you use security information and event log management efficiently and effectively in order to get business value in terms of increased security, reduced risk, regulatory compliance and increased business agility.

Application Grid

Learn more about this middleware layer that pools and dynamically provisions infrastruction application delivery resources to lower costs and improve efficiency.

Laptop Security

Answers to the ongoing challenges of the mobile office: to work anywhere, securely and efficiently.

The IT Service Catalog Management Toolkit

Bridge the it-business gap once and for all! A well documented IT services catalog is the conduit for IT services to the rest of the company.

Learn more >

Disaster Recovery & Business Continuity Template Pack

Prepare your company for any type of disaster you can envision and those you cannot. Immediately download this comprehensive set of templates and tools for documenting your business contingency plans.

Learn more >