Skip to main content

Incidents

The Incidents page lists every suspicious pattern Fraud Detection has found in your traffic, with the risk score behind it and the subject you can block.


Choosing the period

Everything on the page — the chart, the counter, and the list — covers the period set at the top.

  1. Set Date from and Date to, either by typing the date and time or by picking them in the calendar.
  2. Leave Granularity on Auto to let the console size the chart buckets for the period you chose, or select a fixed bucket size.
  3. Click Refresh to reload the data. Use it while you watch a live attack, because the page doesn't refresh on its own.

The chart shows how many incidents were created, and Total Incidents above the list gives the count for the whole period. A short granularity shows the shape of an attack. A long one shows whether blocking a subject actually stopped it.


Understanding the incidents list

Each row is one incident — one subject with an accumulated risk score, not one request. The list is sorted by score, highest first. By default it includes the following information:

  • Score: The accumulated score of every signal attached to the incident. The higher the score, the stronger the evidence.
  • Timestamp: When the behavior happened, taken from the analyzed events.
  • Category: Piracy or Account sharing. For more information, see Incident categories.
  • Source: The traffic the incident was built from — DRM or CDN.
  • Subject type: Whether the incident is about a user, an IP address, or a token.
  • Subject: The user ID, IP address, or token the incident is about.

An incident stays open as new signals arrive, so its score can rise after you first see it.

Customizing columns

To change which columns are displayed, click the columns icon above the list and select or clear the columns you want.

Filtering incidents

  1. Click Filters.
  2. Enter a user ID, IP address, or token in the Subject field to follow one entity.
  3. Select a Subject type to see only user, IP, or token incidents.
  4. Select a Category to separate piracy from account sharing.
  5. Select an Investigation status to hide what your team has already handled.
  6. Click Apply filters.

To go back to the full list, click Clear filters. Filters work on top of the period set at the top of the page, so widen the dates as well if you expected more results.


Reading an incident

Click an incident to open the detail panel. It answers three questions: what happened, what you should do, and what the evidence is.

  • Risk score: The total score and the category, with a written summary of what the subject did.
  • Recommendations: What to turn on so this pattern stops working, for example single-use tokens against license flooding or CDN tokenization against scripted pulling.
  • Subject: The user ID, IP address, or token, with a copy icon and an Add to block list button.
  • Contributing signals: One entry per detection rule that fired, with the points it added, the traffic it came from, how many times it fired, and a chart of when. Switch the range between the last 24 hours, 7 days, and 30 days to see whether the behavior is still going on.
  • Investigation: A link that opens the Request Log already filtered to this subject, so you can look at the individual requests.

A single signal rarely proves abuse. Several signals on the same subject usually do — an IP address that both floods the license server and sends a scripted User-Agent isn't a viewer with a poor connection.

Tracking what your team has handled

Every incident carries an investigation status that you set from the drop-down list at the top of the detail panel. Fraud Detection never changes it for you.

StatusUse it for
UnresolvedNobody has looked at the incident yet. This is the status it starts with.
InvestigatingSomeone on your team is working on it.
SolvedThe abuse was dealt with, for example by blocking the subject.
DismissedA false positive, or behavior you accept.

Changing the status doesn't block or unblock anything. It only records where the incident stands, so the list can be filtered down to what still needs attention.


Acting on an incident

Reading an incident doesn't change what the subject can do, and nothing is blocked automatically. To cut a subject off, click Add to block list in the detail panel, or add its user ID or IP address on the Block List page. The block applies to Cloud DRM, Concurrent Access Protection, and the CDN at the same time.