Invalid traffic & fraud
SSAI spoofing
SSAI spoofing is CTV and video fraud in which fraudsters imitate a server-side ad insertion system, sending fake ad requests that appear to come from real viewers watching real streams.
With server-side ad insertion, a streaming service's server, not the TV, requests ads and stitches them into the video. Because one server makes requests on behalf of many viewers, ad systems accept lots of requests from a single IP and trust headers that pass along each viewer's device details. SSAI spoofing exploits that trust: fraudsters set up servers that pretend to be SSAI systems and fabricate requests for millions of "viewers" who do not exist.
The spoofed requests usually carry fake device information (device spoofing) and fake app identities (app spoofing), and they may fire fabricated viewing beacons so impressions look completed. HUMAN (then White Ops) described a scheme it called ICEBUCKET in 2021 as one of the largest SSAI spoofing operations it had seen. The MRC IVT guidelines treat this kind of misrepresentation as SIVT.
Defences include IAB Tech Lab guidance for SSAI systems to pass consistent device and IP headers, verifying that SSAI server IPs belong to known vendors, app-ads.txt and sellers.json checks, and signed requests. Buyers should favour direct paths to streaming publishers.
Think of it like this
It is like a fake tour operator telling a museum it is bringing 500 visitors, collecting the group rate commission, while the coach outside is empty.
An example
A buyer sees one "SSAI server" IP sending requests for 2 million unique TV devices a day across 40 apps. The IP belongs to a generic cloud provider, not a known SSAI vendor, and none of the apps list its seller in app-ads.txt.
Related terms
SSAI (server-side ad insertion)
SSAI (server-side ad insertion) stitches video ads directly into the content stream on a server before it reaches the viewer, creating seamless, TV-like playback that ad blockers find hard to detect.
CTV fraud
CTV fraud is ad fraud targeting connected TV and streaming inventory, such as spoofed apps, fake devices, SSAI spoofing and infected streaming boxes, exploiting CTV's high prices and harder verification.
Device spoofing
Device spoofing is faking the identity or type of device requesting an ad, such as a server posing as a smart TV or iPhone, to earn higher prices or dodge detection.
App spoofing
App spoofing is misrepresenting which mobile or CTV app an ad slot belongs to, typically by faking the app's bundle ID, so cheap or fake inventory is sold as a popular app.
SIVT (sophisticated invalid traffic)
SIVT (sophisticated invalid traffic) is invalid traffic designed to look human or legitimate, which can only be found through advanced analytics, multi-point corroboration and often human review.
Sources: MRC Invalid Traffic Detection and Filtration Guidelines Addendum (2020 update), IAB Tech Lab CTV standards