Fraud Validation Rules
Injection Prevention identifies fraudulent touchpoints based on their timestamps. The typical flow and timestamps recorded during an app installation are as follows:- The user opens the Google Play Store. At this point,
referrerClickTimestampSecondsis recorded. - The user clicks the “Install” button in the Play Store. At this point,
installBeginTimestampSecondsis recorded. - App installation is completed on the user’s device. At this point,
systemInstallTimestampis recorded. - When the user opens the app for the first time, the Airbridge SDK is activated and an Install (App) event occurs. At this point,
eventTimestampis recorded.

Settings
Go to [Settings]>[Fraud Validation Rules]>[Injection Prevention] to configure the default settings and the settings by channel.Default Settings
NoteFor Airbridge Apps registered with Airbridge before October 23, 2024, the Default Settings for both Click and Impression will be automatically enabled with the prevention level set to “Level 3.”
- Switch on the toggle for click or impression, or both, depending on how you want to set the rule.
- Select the [Prevention Level] and click Save.
AttentionIt is advised to start from “Prevention Level 1” and switch to higher levels after consulting with your media partner, as the prevention level setting may have a direct impact on the ad performance.
Settings by Channel
Customized settings apply only to specific channels. The default settings don’t apply to channel with customized settings. Note that the customized settings can be configured for only non-SAN channels. The events that are attributed to the suspicious touchpoints will be processed according to the set prevention levels.- Click Add a rule.
- Select a channel. The customized settings can be configured for non-SAN channels only, and therefore, the SAN channels and custom channels won’t appear in the search bar.
- Switch on the toggle for click or impression, or both, depending on how you want to set the rule.
- Select [Prevention Level] and click Save.
Prevention Level
Events attributed to the suspicious touchpoints detected by the injection prevention rules are processed according to the set prevention levels.Postbacks for suspicious events
Postbacks for suspicious events
When the Prevention Level is set to 2 or higher, suspected fraud events are excluded from postbacks. However, you can send them with limitations by completing the Postback settings below.
Data included in postbacks
- Sends Target events only: Installs (App), Deeplink Opens (App), and Deeplink Pageviews (App).
- Sends events as unattributed.
- Sends the identified fraud type.
Eligible channels
- Postbacks are sent to channels that would have received attribution if not suspected as fraud. These are channels that met all other Airbridge attribution model rules, including touchpoint priority and last-touch attribution (LTA).
- Postbacks are sent only to channels with the Postback settings below configured.
Postback settings
- In the postback delivery rule, set [Attribution] to All Events
- Edit the postback URL as follows. If using the POST method, contact your CSM or reach out through the Airbridge Help Center.
- Add a postback parameter. Enter the parameter name specified by the channel and select
{unattributedTouchpointFraudReason}as the parameter value. - Some channels require
{unattributedTouchpointClickID}as the Click ID parameter value. Confirm with the channel.
- Add a postback parameter. Enter the parameter name specified by the channel and select
Reporting
The events attributed to the suspicious touchpoints detected by the set rules can be viewed in your Airbridge reports and raw data export files.How to view in raw data export files
How to view in raw data export files
NoteMedia Partner cannot access the [App Raw Data Export] menu. The results can only be accessed though the Airbridge reports.Agency users need to get access permission to the [App Raw Data Export] menu and event properties by the Owner or In-house Marketer. Refer to this article and request access to the Owner or In-house marketer.
- Navigate to [Raw Data]>[App Raw Data].
- In the [Request History] tab, click Export raw data.
- In the [Select Event] step, select the event you want to export. In the [Select Property] step, select Conversion Fraud Tag and Fraud Tags.
- Export raw data. Events determined to be suspicious by the injection prevention rules are tagged with the Conversion Fraud Tag,
Fraud_Touchpoint_FutureTime.
How to view in Airbridge reports
How to view in Airbridge reports
Events that are attributed to the suspicious touchpoints detected by the injection prevention rule can be viewed in the Airbridge reports that support “Touchpoint Fraud Tag” as a GroupBy option.
- Supported Airbridge reports: Actuals Report, Trend Report, Retention Report, Revenue Report, Funnel Report with cohort configuration
Touchpoint Fraud TagisFraud_Touchpoint_FutureTime