Lesson 2 of 8 · 8 min read · intermediate
GIVT vs SIVT: the two kinds of invalid traffic
The MRC splits invalid traffic into GIVT, caught with lists and rules, and SIVT, which needs advanced analytics. Learn exactly what falls in each.
If you read one lesson in this track closely, make it this one. Almost every fraud report, vendor dashboard and contract you will ever see uses two acronyms: GIVT (general invalid traffic) and SIVT (sophisticated invalid traffic). They come from the MRC's MRC IVT guidelines, and the dividing line between them is not how harmful the traffic is. It is how hard the traffic is to detect.
Think of airport security. The first layer is a list: passports are checked against a watch list and bags against a banned-items list. That is GIVT, cheap, fast and applied to everyone. The second layer is detective work: behaviour analysts, intelligence reports and investigators who notice that three unrelated passengers bought tickets with the same card. That is SIVT, expensive, slower and needed for anyone smart enough to pass the first check.
GIVT: caught by lists and standard parameter checks
The MRC describes GIVT as traffic identified through routine means of filtration, applied through lists or other standardised parameter checks. In plain English: if you can catch it by looking something up or applying a fixed rule, it is GIVT. Its key examples, paraphrased from the June 2020 MRC update, are:
- Known invalid data-center traffic: IP ranges belonging to cloud and hosting providers that consistently produce non-human traffic (data center traffic). Legitimate users routed through corporate networks or VPNs are meant to be excluded.
- Declared bots, spiders and crawlers, matched against lists such as the IAB/ABC Spiders & Bots List.
- Non-browser user agent headers or unknown browsers, such as a request claiming to be a scripting library rather than Chrome or Safari.
- Pre-fetch or pre-rendered traffic where the page was loaded speculatively and no real user ever saw the ad.
- Activity-based filtration: simple rules on transaction data, such as an impossible number of clicks from one ID in a minute.
- Invalid placements such as 0x0 or 1x1 ad sizes delivered on the page, and non-rendering sessions, such as a headless browser that claims to have displayed an ad it has no ability to display.
Every MRC-accredited measurer must filter GIVT. It is table stakes. Because GIVT is list-based, it is also shared: once a crawler or a data-center range is identified, everyone can block it.
SIVT: needs advanced analytics, corroboration or human investigation
The MRC describes SIVT as situations that are more difficult to detect and require advanced analytics, multi-point corroboration or coordination, or significant human intervention to identify. SIVT is traffic built to look normal. Its key examples include:
| SIVT category (MRC) | Plain-English example |
|---|---|
| Automated browsing from a dedicated device | Emulators and custom automation tools running on servers built only to generate traffic |
| Automated browsing from a non-dedicated device | Malware silently loading ads on an ordinary family laptop, phone or TV box (botnets) |
| Incentivised human invalid activity | Click farms and organised human fraud, where real people are paid to generate fake engagement |
| Manipulated activity | Forced clicks, forced app installs, clickjacking, hijacked measurement events |
| Falsified measurement events | Faked impressions, viewability, location, consent strings, conversions and SSAI spoofing |
| Domain and app misrepresentation | Domain spoofing, app ID spoofing and domain laundering |
| Hidden or obscured ad serving | Stacked ads, pixel stuffing, transparent ads, pop-unders that auto-close |
| Invalid proxy traffic | Traffic routed through proxies, including residential proxies, to disguise its origin |
| Adware and malware | Ad injection and unauthorised overlays on other people's pages |
| Cookie manipulation | Cookie stuffing, recycling or harvesting to fake prior user activity |
For accredited measurers, SIVT detection is strongly encouraged and required for those accredited for it, but it is not something a list can do. It requires modelling behaviour over time, correlating signals across millions of devices, planting traps, and sometimes reverse-engineering malware. This is why SIVT detection is a specialist business and why vendors are accredited separately for GIVT and SIVT.
GIVT
- Detected by lists and fixed parameter checks
- Applied to all traffic, often pre-bid
- Mostly harmless or unsophisticated sources
- Mandatory for every MRC-accredited measurer
- Cheap, fast, shared industry-wide
SIVT
- Detected by advanced analytics, corroboration, investigation
- Often needs rendering-time or post-serve signals
- Deliberate, adaptive, built to evade
- Separately accredited; strongly encouraged
- Expensive, proprietary, constantly changing
Three subtleties experts care about
- Categories migrateThe MRC expects that items now classed as SIVT may later be standardised into objective lists and re-categorised as GIVT. Yesterday's clever trick becomes tomorrow's list entry.
- Not every bot is GIVTA declared crawler is GIVT. A bot pretending to be a person, using a real browser on a hacked home computer, is SIVT, even though both are "bots". The disguise, not the robot, decides the bucket.
- Humans can be SIVTPaid click farms and incentivised activity designed to manipulate measurement count as SIVT. Disclosed reward programmes, where people knowingly watch ads for points, are not automatically invalid, but they should be reported separately.
Rates differ too. GIVT volume is often dominated by crawlers and is relatively stable. SIVT is lumpy: a single new scheme can push a channel's rate from near zero to double digits in weeks. That is why quality teams track both separately rather than as one blended IVT rate.
Here is how a single report might read. Of 50 million measured impressions, 1.5% are GIVT, mostly crawlers and a few data-center ranges, removed automatically. Another 2.5% are SIVT, concentrated in three apps and one reseller whose traffic shows proxy signals and hidden-ad behaviour. The GIVT number tells you your filters work. The SIVT number, and especially where it clusters, tells you whom to stop buying from.
Key takeaways
- GIVT is invalid traffic caught through lists and standardised parameter checks; SIVT needs advanced analytics, corroboration or human investigation.
- The split is about detection difficulty, not harm: a disguised bot is SIVT even though a declared bot is GIVT.
- All MRC-accredited measurers must filter GIVT; SIVT accreditation is separate and granted per environment.
- SIVT categories include hijacked devices, spoofed domains and apps, hidden ads, proxies, click farms and falsified events.
Questions people ask
What is the difference between GIVT and SIVT?
GIVT (general invalid traffic) is caught using lists and standard rules, such as known data-center IP ranges, declared crawlers on the IAB/ABC Spiders and Bots List, and non-browser user agents. SIVT (sophisticated invalid traffic) is built to look human and needs advanced analytics, multi-signal corroboration or human investigation to detect, such as malware on real devices, spoofed domains, hidden ads and residential proxies.
Who defines GIVT and SIVT?
The Media Rating Council (MRC) defines them in its Invalid Traffic Detection and Filtration Standards Addendum, first issued in 2015 and updated in June 2020. The MRC uses these definitions when auditing measurement vendors. TAG and the IAB use closely aligned vocabulary, so the terms are used worldwide, including in Europe, India and Asia-Pacific markets.
Is SIVT always ad fraud?
Almost always it is deliberate, but the category is defined by how hard it is to detect rather than by proven criminal intent. Some SIVT, such as certain proxy traffic or unintentional clicks caused by bad page design, may not be a crime. In practice, buyers should treat SIVT as unbillable and investigate the source, whether or not intent can be proven.