Policy abuse
Query fraud
Searches are sent to the feed that no person actually typed or chose, so ads are shown against invented intent.
How it works
Search ads are valuable because a query is a statement of intent: the person asked for it. Query fraud manufactures that statement. A script submits searches, a page fires a search automatically on load, or software rewrites what the user typed into something that pays better.
Google's AdSense for Search rules set out where a query may come from: typed by the user, produced by an approved product feature such as related search, or an approved alternative query. Anything else is an invented query. Unlike a fake click, a fake query can involve a real person, who is shown results for a search they never made.
Who pays for it
Advertisers, who bid on intent that was not there. The search engine's marketplace, whose value depends on queries being genuine. Feed partners, for whom this is among the surest ways to lose the feed.
Who does it, and why
Publishers seeking more searches without more users, hijacking software, and traffic sellers converting any visit into a "search".
Warning signs
- More searches than visitors could plausibly type, or searches with no preceding page interaction.
- Query lists that look machine-made: alphabetical, templated or identical in bursts.
- A results page that appears on first load with a query already filled in.
- Queries that do not match the language or location of the users.
- High-value commercial queries from sources with no search box.
Defences
- Send the feed only queries that came from a user action or an approved feature.
- Log the user action behind each query so it can be shown on request.
- Never auto-submit searches on page load or rewrite the user's words.
- Audit partners' search box monetisation and extension implementations before going live.
An example
Real case: Bitdefender reported that the Redirector.Paco malware, on more than 900,000 IP addresses from 2014, intercepted victims' searches on a popular search engine and replaced the results with a custom search page carrying AdSense for Search ads. The users were real and so were their searches, but the search engine and the feed earning from them had been swapped in without their knowledge.
Documented cases
- Redirector.Paco (2016): Botnet that replaced real search results with a monetised custom search feed
- Bamital (2013): Search-hijacking and click-fraud botnet
- Fireball (2017): Browser hijacker bundled with free software to force searches through fake search engines