Behavior + Device & Network Dashboards
Overview
Overview provides insight into the Behavior and Device & Network risk of observed interactions. Particular attention is given to those interactions categorized as high risk.
The Overview dashboard can help you:
- Understand the distribution of low, medium and high risk interactions across your application(s) over time and monitor changes in that distribution (e.g., when meaningful increases in risky interactions are observed).
- Understand what’s driving the assessed risk levels and monitor for meaningful changes over time.
- Understand how the riskiness of users is distributed across device type (PC, mobile, tablet), and funnel (if applicable)
The data in this dashboard can be filtered by:
- Signals to Include (Risk Summary & Risk Drivers tabs)
- Timeframe
- Funnel
- Device Type
- Customer Defined UserID (y/n)
- Segment Count
Overview Tiles
The Overview chart tiles are divided into three tabs: Risk Summary, Risk Drivers, and Risky Users.
Name | Description |
---|---|
Total Interactions | Displays the total number of interactions from which we collected behavior and/or device signals. Due to people with multiple sessions, session abandonment, and other factors, it is likely this count will be different from the number of unique users. |
Low Risk Interactions | Displays the number of interactions categorized as low risk. |
Medium Risk Interactions | Displays the number of interactions categorized as medium risk. |
High Risk Interactions | Displays the number of interactions categorized as high risk. |
High Risk Alerts | Displays the number of alerts triggered by observed high risk behavior. |
Risk Level Over Time | Displays the distribution of high, medium, and low risk interactions (based on collected behavior and/or device signals) over the specified timeframe. |
High Risk Driver | Displays the overall distribution of risk drivers (behavior, device & network or both) for interactions classified as high risk. |
High Risk Driver Over Time | Displays the risk driver distribution over time (behavior, device & network or both) for the interactions classified as high risk. |
High Risk by Device Type | Displays the overall distribution of device types (PC, Phone, Table, or Other) for interactions classified as high risk. |
High Risk by Device Type Over Time | Displays the device type distribution over time (PC, Phone, Table, or Other) for the interactions classified as high risk. |
High Risk by Funnel | Displays the overall distribution of funnels for interactions classified as high risk. |
High Risk by Funnel Over Time | Displays the funnel distribution over time for the interactions classified as high risk. |
Medium Risk by Rules Violated | Displays the distribution of the number of medium risk rules violated for interactions classified as medium risk. |
Medium Risk by Rules Violated Over Time | Displays the medium risk rules violated count distribution over time for the interactions classified as medium risk. |
Risky Behavior by Type | Displays the distribution of risky users by the type of risky behavior exhibited. A single user may exhibit more than one type of risky behavior and thus, may be counted in more than one category. |
Risky Behavior by Type Over Time | Displays the distribution of risky users by the type of risky behavior exhibited over time. A single user may exhibit more than one type of risky behavior and thus, may be counted in more than one category. |
Automated Interactions by Type | Displays the distribution of automated users by their type. A single user may exhibit more than one type of behavior and thus, may be counted in more than one category. |
Automated Interactions by Type Over Time | Displays the distribution of automated users by their type over time. |
User Summary
User Summary provides thorough details of a specific user’s activities across all sessions detected for the specified User ID.
The User Summary dashboard can help you:
- See if the specified user was classified as risky, neutral, or genuine including what device and/or network signals may have led to that classification, as well as if observed behaviors triggered a Fraud Ring Indicator or appeared to be automated.
- Visualize how the user progressed through the individual steps and targets of the application (mouse clicks, tabs, etc.)
- Identify where in an application the user struggled (repeat interactions, excessive time in fields, etc.)
The data in this dashboard is for a single User ID (required to display data) and can be further filtered by:
- Session
User Summary Tiles
Name | Description |
---|---|
User Overview | Displays the following information for each session for the specified User ID: - Funnel (if applicable) - Application Complete (true/false) - Device ID - Device - Operating System - Browser - Overall Risk - Behavior Risk - Fraud Ring Indication (true/false) - Automated User (true/false) - Device & Network Risk - Suspicious Device (true/false) - Blocklisted IP Address (true/false) - Blocklisted Device (true/false) - Tor Browser (true/false) - Multiple Users per Device (true/false) - Multiple Sessions per Device (true/false) - VPN Connection (true/false) - Proxy Server Connection (true/false) - Incognito Browser (true/false) - IP Address Association (true/false) - Bot Framework (true/false) - IP Latitude, Longitude, Postal Code, Timezone, City, Country Code, Country, Continent Code, Continent, Subdivisions ISO Code, and Subdivisions - Factory reset (true/false) - GPS Spoofing (true/false) |
Other Device Users | Displays the same information as the User Overview tile for other users who were observed interacting with the same devices as the queried user.- |
Observed Behavior | Provides more detail for each of the user’s interactions (ex: what was interacted with, how it was interacted with, for how long, etc.) |
Step and Target Timeline | Provides a Gantt-like view of the user’s target interactions, categorized by application step. |
Link Analysis
The Link Analysis dashboard summarizes observed links (relationships) between Users, Devices, IP Addresses and Sessions. The dashboard contains three tabs, “Users,” “Devices,” and “IP Addresses” with each focusing on the links related to the object the tab is named for. For instance, on the Users tab, you can see things like:
- How many times a single user is tied to one or more devices, IP addresses or session IDs and what those multiples are (ex: there were 10 times a single user was linked to 5 devices).
- The risk breakdown of the associated sessions (ex: of the 50 sessions associated with the 10 users who each used 5 devices, how many were deemed to be high risk).
- A list of the sessions that drove the counts displayed in the dashboard (by risk level and in total)
The data in this dashboard is for a single User ID (required to display data) and can be further filtered by:
- Signals to Include
- Timeframe
- Device Type
- Funnel
- Customer-Defined User ID (y/n)
Link Analysis Tiles
Name | Description |
---|---|
One User with n Devices | Displays the number of times a link was found between a single user and one or more devices, by the count of linked devices. It also displays the counts of sessions associated with those links. |
One User with n IP Addresses | Displays the number of times a link was found between a single user and one or more IP addresses, by the count of linked IP addresses. It also displays the counts of sessions associated with those links. |
One User with n Session IDs | Displays the number of times a link was found between a single user and one or more Session IDs, by the count of linked Session IDs. It also displays the counts of sessions associated with those links. |
One Device with n Users | Displays the number of times a link was found between a single device and one or more users, by the count of linked users. It also displays the counts of sessions associated with those links. |
One Device with n IP Addresses | Displays the number of times a link was found between a single device and one or more IP addresses, by the count of linked IP addresses. It also displays the counts of sessions associated with those links. |
One Device with n Session IDs | Displays the number of times a link was found between a single device and one or more Session IDs, by the count of linked Session IDs. It also displays the counts of sessions associated with those links. |
One IP Address with n Users | Displays the number of times a link was found between a single IP address and one or more users, by the count of linked users. It also displays the counts of sessions associated with those links. |
One IP Address with n Devices | Displays the number of times a link was found between a single IP address and one or more devices, by the count of linked devices. It also displays the counts of sessions associated with those links. |
One IP Address with n Session IDs | Displays the number of times a link was found between a single IP address and one or more Session IDs, by the count of linked Session IDs. It also displays the counts of sessions associated with those links. |
Alerts
Alerts provides a summary of crowd alerts received for the specified timeline.
The data in this dashboard can be filtered by:
- Timeframe
Alerts Tiles
Name | Description |
---|---|
Timeline | Displays a timeline of crowd alerts and the counts of affected users by behavior type (ex: Automated Users, Fraud Ring, etc.). If the same user is identified in more than one fraud event, the user will be counted multiple times. |
Alert Details | Provides a tabular view of the data in the timeline. |
Updated 9 months ago