Key takeaways
- Signal families reduce double-counting of correlated evidence.
- Missing evidence is not evidence of safety.
- Thresholds and model versions must be reconstructable.
- Human-readable reasons make review and correction possible.
Seven useful signal families
Behaviour covers navigation and interaction patterns; velocity covers frequency over time; network covers hosting, proxy, and routing context; device covers consistency and automation clues; acquisition covers campaign and referrer context; identity covers continuity; outcomes cover conversion and lead quality.
Some indicators overlap. A data-centre network and an automation signature may describe the same underlying condition, so a model should not count them as two fully independent confirmations.
Attach eligibility and confidence
Every calculation should state the website, time range, eligible population, missing-data conditions, freshness, model version, and confidence. An unavailable signal should not quietly become a negative signal.
- Observed facts remain separate from calculated features.
- Scores remain separate from labels and decisions.
- Historical results retain the version used at the time.
- Low evidence produces an unclassified result.
Evaluate usefulness, not just detection volume
Monitor false-positive reviews, later outcomes, action reversals, provider feedback, and data-quality incidents. A detector that labels more traffic is not necessarily better; it must support decisions without causing disproportionate collateral harm.
Limitations
What this guide does not claim
Signals indicate patterns, not intent. Thresholds depend on channel, website behaviour, volume, data coverage, and acceptable operational risk.
Evidence
Primary sources
- Automated Threats to Web ApplicationsOWASP Foundation
- About invalid trafficGoogle Ads Help
- AI Risk Management FrameworkNIST
Read how we source, review, update, and correct content in our editorial standards.
