Invalid traffic & fraud · also called Browser fingerprinting, fingerprinting
Device fingerprinting
Device fingerprinting is identifying or characterising a device from the combination of its technical attributes, such as browser, fonts, screen, graphics and network traits, instead of a stored cookie or ID.
Every browser and device leaks small details: operating system, screen resolution, time zone, language, installed fonts, graphics card behaviour, audio processing quirks and many more. Combined, they can form a pattern distinctive enough to recognise the same device again, or to tell whether a device is what it claims to be.
Fingerprinting has two uses that must be kept apart. For tracking and targeting, it is controversial: users cannot clear it like a cookie, and the W3C, browser makers and regulators treat covert fingerprinting as a privacy concern. Apple bans using it for tracking in apps, and data protection laws such as GDPR generally treat it like other identifiers.
For fraud detection, fingerprints are a key SIVT signal. The question is not "who is this?" but "is this consistent?" A claimed iPhone that renders graphics like a Linux server, a "new" device whose traits exactly match thousands of others, or a browser exposing automation flags are strong indicators of device spoofing, emulators or headless bots. Fraud detection is one of the purposes privacy frameworks commonly recognise as legitimate.
Think of it like this
Fingerprinting is like recognising a friend's handwriting: no name on the envelope, but the loops and slants give it away, and a forgery looks subtly wrong.
An example
A verification vendor sees 50,000 "different" Android phones in Nigeria sharing an identical combination of screen size, GPU string, fonts and audio signature, which is statistically near-impossible for real devices, and flags them as an emulator cluster.
Related terms
Device spoofing
Device spoofing is faking the identity or type of device requesting an ad, such as a server posing as a smart TV or iPhone, to earn higher prices or dodge detection.
Headless browser
A headless browser is a web browser that runs without a visible window, controlled by code; widely used for testing and scraping, and by bots to fake human visits and ad views.
Behavioral analysis
Behavioral analysis in fraud detection is examining how a visitor interacts, such as mouse movements, taps, scrolling, typing rhythm and session timing, to tell real humans from bots and scripted activity.
User agent
A user agent is the text string a browser or app sends with each request describing its browser, version, operating system and device, used for compatibility, analytics and fraud detection.
Fraud detection
Fraud detection in advertising is the process and technology of identifying invalid or fraudulent impressions, clicks, installs and conversions, so they can be blocked in advance or excluded from billing.
Sources: W3C: Mitigating Browser Fingerprinting in Web Specifications, Apple: User privacy and data use, MRC Invalid Traffic Detection and Filtration Guidelines Addendum (2020 update)