Click Spam
What it detects
Section titled “What it detects”Click spam is a broad-based fraud technique where malicious apps or websites generate clicks in the background without user interaction. Common methods include invisible iframes, background processes, and cookie dropping — all designed to place a click before an organic conversion occurs.
How it works
Section titled “How it works”Integr8 analyzes session characteristics to identify click spam signals:
- Zero or near-zero session time: Clicks recorded with no measurable user session indicate automated generation.
- Abnormal CTIT distribution: Legitimate install times cluster within predictable ranges. Click spam produces a flat or bimodal CTIT distribution spread across hours or days.
- Click-to-conversion ratio: A high ratio of clicks from a source with few matching conversions flags that source as a spam generator.
The filter evaluates these signals in combination. A single signal may not trigger a block, but multiple concurrent signals raise the fraud score above the block threshold.
Configuration
Section titled “Configuration”Navigate to Offers > Fraud Detection Groups > select a filter group > Click Spam.
Each lookback period (12 h, 24 h, 96 h, 720 h) can be enabled independently. Per-period fields:
| Parameter | Default | Description |
|---|---|---|
max_session_time_seconds |
3,600 (1 h) | Conversions with a session time above this are counted as high session time |
threshold_percentage |
50% | Percentage of high-session-time conversions before the source is blocked |
minimum_request_count |
50 | Minimum conversions required before the threshold check runs |
check_by_sub_id |
false | Calculate threshold at sub ID level instead of publisher level |
These settings are managed by administrators. Contact your account admin to review or update the configuration.
What happens when triggered
Section titled “What happens when triggered”When a click source is identified as spam:
- Block mode: Subsequent clicks from that source are rejected. Conversions that arrive after a blocked click do not receive attribution.
- Flag mode: Clicks are recorded with
fraud_reason: click_spam. You can audit flagged traffic in Reports > Click Reports.
Start with Flag mode for at least a week before switching to Block mode. Review flagged traffic to confirm the filter is not catching legitimate publisher traffic with naturally long session times.
Related filters
Section titled “Related filters”- Click Flooding — detects high-volume click attacks from single sources
- Low Session Time Anomaly — flags sessions with abnormally short engagement time