Can anti-fraud make large-scale attacks unprofitable?

Posted by jezzwar 5 hours ago

Counter3Comment1OpenOriginal

I’m interested in feedback from people who have experience with fraud prevention, security, ad-tech, or abuse systems.

Let’s assume a platform where users receive some form of benefit based on verified real activity. A major concern is whether organized fraud operations can scale profitably.

A common assumption is that attackers will always find a way around individual defenses. So instead of trying to make abuse impossible, the approach is to increase the cost of abuse:

device reputation and fingerprinting; IP/network reputation; VPN/proxy/datacenter detection; behavioral analysis; account reputation over time; graph analysis to detect connected accounts; risk-based limits and delayed payouts; manual review and feedback loops.

The idea is that a fraudster might be able to create accounts, but maintaining profitable accounts at scale becomes difficult.

The question:

Does this actually change the economics of fraud, or will sophisticated operators always find a way to stay profitable?

For example, attackers can theoretically use virtual machines, proxies, automation, and other infrastructure. But they also have ongoing costs:

infrastructure; acquiring and maintaining identities/accounts; operational overhead; adapting to detection systems; losing accounts and reputation.

At what point does the cost of running the operation exceed the expected return?

I’m especially interested in perspectives from people who have worked on the offensive or defensive side of fraud. What weaknesses would you expect in this approach? Which signals are actually valuable, and which are mostly security theater?

Looking for criticism, not validation.

Comments

Comment by DamonHD 4 hours ago

It's always about costs - cost to run the service, cost to abuse the service.

I was founder/CTO of a UK small e-money issuer, and while I am no fan of Musk, at PayPal he made a good observation that while the money handling bit is not so hard, the anti-fraud part is.

I also created/ran an early UK ISP, helped moderate a busy (US) forum, etc, etc, and I observe that while you generally cannot eliminate bad behaviour, you can make it costly enough that you stop being the easy target and attention goes elsewhere...

And you should have a range of broad signals to evaluate with.