Behavior + Device & Network Dashboards

Overview

Overview provides insight into the Behavior and Device & Network risk of observed interactions. Particular attention is given to those interactions categorized as high risk.

The Overview dashboard can help you:

  • Understand the distribution of low, medium and high risk interactions across your application(s) over time and monitor changes in that distribution (e.g., when meaningful increases in risky interactions are observed).
  • Understand what’s driving the assessed risk levels and monitor for meaningful changes over time.
  • Understand how the riskiness of users is distributed across device type (PC, mobile, tablet), and funnel (if applicable)

The data in this dashboard can be filtered by:

  • Signals to Include (Risk Summary & Risk Drivers tabs)
  • Timeframe
  • Funnel
  • Device Type
  • Customer Defined UserID (y/n)
  • Segment Count

Overview Tiles

The Overview chart tiles are divided into three tabs: Risk Summary, Risk Drivers, and Risky Users.

NameDescription
Total InteractionsDisplays the total number of interactions from which we collected behavior and/or device signals. Due to people with multiple sessions, session abandonment, and other factors, it is likely this count will be different from the number of unique users.
Low Risk InteractionsDisplays the number of interactions categorized as low risk.
Medium Risk InteractionsDisplays the number of interactions categorized as medium risk.
High Risk InteractionsDisplays the number of interactions categorized as high risk.
High Risk AlertsDisplays the number of alerts triggered by observed high risk behavior.
Risk Level Over TimeDisplays the distribution of high, medium, and low risk interactions (based on collected behavior and/or device signals) over the specified timeframe.
High Risk DriverDisplays the overall distribution of risk drivers (behavior, device & network or both) for interactions classified as high risk.
High Risk Driver Over TimeDisplays the risk driver distribution over time (behavior, device & network or both) for the interactions classified as high risk.
High Risk by Device TypeDisplays the overall distribution of device types (PC, Phone, Table, or Other) for interactions classified as high risk.
High Risk by Device Type Over TimeDisplays the device type distribution over time (PC, Phone, Table, or Other) for the interactions classified as high risk.
High Risk by FunnelDisplays the overall distribution of funnels for interactions classified as high risk.
High Risk by Funnel Over TimeDisplays the funnel distribution over time for the interactions classified as high risk.
Medium Risk by Rules ViolatedDisplays the distribution of the number of medium risk rules violated for interactions classified as medium risk.
Medium Risk by Rules Violated Over TimeDisplays the medium risk rules violated count distribution over time for the interactions classified as medium risk.
Risky Behavior by TypeDisplays the distribution of risky users by the type of risky behavior exhibited. A single user may exhibit more than one type of risky behavior and thus, may be counted in more than one category.
Risky Behavior by Type Over TimeDisplays the distribution of risky users by the type of risky behavior exhibited over time. A single user may exhibit more than one type of risky behavior and thus, may be counted in more than one category.
Automated Interactions by TypeDisplays the distribution of automated users by their type. A single user may exhibit more than one type of behavior and thus, may be counted in more than one category.
Automated Interactions by Type Over TimeDisplays the distribution of automated users by their type over time.

User Summary

User Summary provides thorough details of a specific user’s activities across all sessions detected for the specified User ID.

The User Summary dashboard can help you:

  • See if the specified user was classified as risky, neutral, or genuine including what device and/or network signals may have led to that classification, as well as if observed behaviors triggered a Fraud Ring Indicator or appeared to be automated.
  • Visualize how the user progressed through the individual steps and targets of the application (mouse clicks, tabs, etc.)
  • Identify where in an application the user struggled (repeat interactions, excessive time in fields, etc.)

The data in this dashboard is for a single User ID (required to display data) and can be further filtered by:

  • Session

User Summary Tiles

NameDescription
User OverviewDisplays the following information for each session for the specified User ID:

- Funnel (if applicable)
- Application Complete (true/false)
- Device ID
- Device
- Operating System
- Browser
- Overall Risk
- Behavior Risk
- Fraud Ring Indication (true/false)
- Automated User (true/false)
- Device & Network Risk
- Suspicious Device (true/false)
- Blocklisted IP Address (true/false)
- Blocklisted Device (true/false)
- Tor Browser (true/false)
- Multiple Users per Device (true/false)
- Multiple Sessions per Device (true/false)
- VPN Connection (true/false)
- Proxy Server Connection (true/false)
- Incognito Browser (true/false)
- IP Address Association (true/false)
- Bot Framework (true/false)
- IP Latitude, Longitude, Postal Code, Timezone, City, Country Code, Country, Continent Code, Continent, Subdivisions ISO Code, and Subdivisions
- Factory reset (true/false)
- GPS Spoofing (true/false)
Other Device UsersDisplays the same information as the User Overview tile for other users who were observed interacting with the same devices as the queried user.-
Observed BehaviorProvides more detail for each of the user’s interactions (ex: what was interacted with, how it was interacted with, for how long, etc.)
Step and Target TimelineProvides a Gantt-like view of the user’s target interactions, categorized by application step.

Link Analysis

The Link Analysis dashboard summarizes observed links (relationships) between Users, Devices, IP Addresses and Sessions. The dashboard contains three tabs, “Users,” “Devices,” and “IP Addresses” with each focusing on the links related to the object the tab is named for. For instance, on the Users tab, you can see things like:

  • How many times a single user is tied to one or more devices, IP addresses or session IDs and what those multiples are (ex: there were 10 times a single user was linked to 5 devices).
  • The risk breakdown of the associated sessions (ex: of the 50 sessions associated with the 10 users who each used 5 devices, how many were deemed to be high risk).
  • A list of the sessions that drove the counts displayed in the dashboard (by risk level and in total)

The data in this dashboard is for a single User ID (required to display data) and can be further filtered by:

  • Signals to Include
  • Timeframe
  • Device Type
  • Funnel
  • Customer-Defined User ID (y/n)

Link Analysis Tiles

NameDescription
One User with n DevicesDisplays the number of times a link was found between a single user and one or more devices, by the count of linked devices. It also displays the counts of sessions associated with those links.
One User with n IP AddressesDisplays the number of times a link was found between a single user and one or more IP addresses, by the count of linked IP addresses. It also displays the counts of sessions associated with those links.
One User with n Session IDsDisplays the number of times a link was found between a single user and one or more Session IDs, by the count of linked Session IDs. It also displays the counts of sessions associated with those links.
One Device with n UsersDisplays the number of times a link was found between a single device and one or more users, by the count of linked users. It also displays the counts of sessions associated with those links.
One Device with n IP AddressesDisplays the number of times a link was found between a single device and one or more IP addresses, by the count of linked IP addresses. It also displays the counts of sessions associated with those links.
One Device with n Session IDsDisplays the number of times a link was found between a single device and one or more Session IDs, by the count of linked Session IDs. It also displays the counts of sessions associated with those links.
One IP Address with n UsersDisplays the number of times a link was found between a single IP address and one or more users, by the count of linked users. It also displays the counts of sessions associated with those links.
One IP Address with n DevicesDisplays the number of times a link was found between a single IP address and one or more devices, by the count of linked devices. It also displays the counts of sessions associated with those links.
One IP Address with n Session IDsDisplays the number of times a link was found between a single IP address and one or more Session IDs, by the count of linked Session IDs. It also displays the counts of sessions associated with those links.

Alerts

Alerts provides a summary of crowd alerts received for the specified timeline.

The data in this dashboard can be filtered by:

  • Timeframe

Alerts Tiles

NameDescription
TimelineDisplays a timeline of crowd alerts and the counts of affected users by behavior type (ex: Automated Users, Fraud Ring, etc.). If the same user is identified in more than one fraud event, the user will be counted multiple times.
Alert DetailsProvides a tabular view of the data in the timeline.