Skip to main content

How Fraud Detection works

Fraud Detection analyzes your Cloud DRM and CDN traffic in real time, scores suspicious behavior, and groups it into incidents you can review in the console and act on from a single Block List.


What the module analyzes

Fraud Detection reads events that Cloud Video Kit already produces for your tenant:

  • DRM license requests, including requests that ended with an error.
  • CDN requests for manifests and segments, delivered through the Cloud Video Kit CDN Redirector. Traffic served by your own CDN isn't analyzed.

Events are always processed inside one tenant. Traffic from other Cloud Video Kit customers never affects your scores or your incidents.

For a summary of how much protection you have in place and what was detected recently, see Security Hub.

What an incident is about

Every incident points at one subject — the entity the suspicious behavior belongs to.

Subject typeDescription
UserThe user ID carried in the DRM or CDN token.
IPThe IP address the requests came from.
TokenA single token, when the abuse follows the credential rather than the user or the device.

Incident categories

CategoryWhat it means
PiracyFast, high-intensity abuse — request floods, token reuse, scripted access, content scanning. Short windows and high individual scores.
Account sharingSustained credential reuse — one account used from many places, devices, or countries. Longer windows, smaller scores, several contributions needed.

Acting on what you find

Reviewing an incident doesn't change anything on its own. Nothing is blocked automatically. To stop a user or an address, add it to the Block List, which is enforced by Cloud DRM, Concurrent Access Protection, and the CDN at the same time. For instructions, see Block List.