# Fraud and bot glossary.

Source: https://kavralab.com/glossary/

Clear definitions of the terms fraud, risk and security teams use every day, written in plain language, with how each one shows up in real traffic.

- [Account takeover](https://kavralab.com/glossary/account-takeover/index.md): Account takeover is when a criminal gains control of someone else's online account. A short definition, the common routes in, and the full playbook linked.
- [AI agent](https://kavralab.com/glossary/ai-agent/index.md): An AI agent is software driven by a language model that browses sites, fills in forms and completes tasks for a person. Some are verified; many are not.
- [Antidetect browser](https://kavralab.com/glossary/antidetect-browser/index.md): A browser built to show each website a different, made-up device, so one operator can run many profiles that look like unrelated people.
- [Arbitrage betting](https://kavralab.com/glossary/arbitrage-betting/index.md): Arbitrage betting means backing every outcome of an event at different bookmakers to lock in a profit. How it works, why operators limit it and where bots come in.
- [ASN](https://kavralab.com/glossary/asn/index.md): An ASN is the number that identifies a network on the internet, such as an internet provider, a mobile carrier or a cloud host, and the IP ranges it owns.
- [Bad bot](https://kavralab.com/glossary/bad-bot/index.md): A bad bot is automation that hides what it is to take accounts, data, stock or money from a website. Here is how bad bots work and how to catch them.
- [BIN attack](https://kavralab.com/glossary/bin-attack/index.md): A BIN attack uses a bank's card number prefix to generate and test guessed card numbers until some are approved. How it works and how to stop it.
- [Bonus abuse](https://kavralab.com/glossary/bonus-abuse/index.md): Bonus abuse is claiming a welcome bonus, free bet or reward more times than the rules allow, usually through many accounts. A short definition, with the playbook linked.
- [Bot](https://kavralab.com/glossary/bot/index.md): A bot is software that visits websites and apps automatically. Some index your pages, others steal logins, copy prices or buy up stock.
- [Botnet](https://kavralab.com/glossary/botnet/index.md): A botnet is a network of hijacked computers, phones and routers controlled by one operator and rented out for floods, spam, login attacks and proxy traffic.
- [Browser fingerprinting](https://kavralab.com/glossary/browser-fingerprinting/index.md): Browser fingerprinting recognizes a web browser from the values it exposes to every page, such as its version, fonts, screen and language.
- [Canvas fingerprinting](https://kavralab.com/glossary/canvas-fingerprinting/index.md): Canvas fingerprinting asks a browser to draw a hidden image and reads the tiny differences in the result that come from its hardware and software.
- [CAPTCHA](https://kavralab.com/glossary/captcha/index.md): A CAPTCHA is a test meant to tell humans from bots, such as distorted text or picking images. How CAPTCHAs work, why bots now pass them and what replaces them.
- [Card testing](https://kavralab.com/glossary/card-testing/index.md): Card testing is using small payments or card checks to find out which stolen card numbers still work. A plain definition and how it differs from BIN attacks and carding.
- [Carding](https://kavralab.com/glossary/carding/index.md): Carding is the trade in stolen card data and the use of those cards to buy goods, gift cards and services for resale. How it works and how merchants stop it.
- [Chargeback](https://kavralab.com/glossary/chargeback/index.md): A chargeback is a card payment reversed by the cardholder's bank after a dispute. How it works, what it costs and how to prevent fraud-driven chargebacks.
- [Chip dumping](https://kavralab.com/glossary/chip-dumping/index.md): Chip dumping is when one poker player deliberately loses chips to another to move money, launder funds or consolidate bonus winnings. How it works and the signs.
- [Credential stuffing](https://kavralab.com/glossary/credential-stuffing/index.md): Credential stuffing is when bots try usernames and passwords leaked from one site on many others. A short definition, and how it differs from brute force.
- [Datacenter proxy](https://kavralab.com/glossary/datacenter-proxy/index.md): A datacenter proxy forwards traffic through an IP address owned by a hosting or cloud provider. It is fast and cheap, and easy to recognize.
- [Denial of inventory](https://kavralab.com/glossary/denial-of-inventory/index.md): Denial of inventory is when bots hold products, seats or rooms in carts and reservations without paying, so real customers see them as sold out.
- [Device farm](https://kavralab.com/glossary/device-farm/index.md): A device farm is a collection of real phones or tablets controlled by one operator, used to fake app installs, accounts and engagement at scale.
- [Device fingerprinting](https://kavralab.com/glossary/device-fingerprinting/index.md): Device fingerprinting recognizes a returning device from the combination of its hardware, software and settings, without storing anything on it.
- [Device ID](https://kavralab.com/glossary/device-id/index.md): A device ID is an identifier used to recognize the same device across visits, logins and accounts, from app IDs to fingerprint-based visitor IDs.
- [Device spoofing](https://kavralab.com/glossary/device-spoofing/index.md): Device spoofing is faking the device information a website or app sees, so a fraudster looks like someone else on a different phone or computer.
- [Emulator](https://kavralab.com/glossary/emulator/index.md): An emulator is software that imitates a phone or other device on a computer, letting one machine run many fake phones that look like separate customers.
- [Fake account](https://kavralab.com/glossary/fake-account/index.md): A fake account is a user account with no genuine customer behind it, made by bots, farms or fraudsters to abuse offers, spam or scam. Types, signs and how to stop them.
- [False positive](https://kavralab.com/glossary/false-positive/index.md): A false positive is a real customer wrongly flagged as fraud or a bot. Why they happen, what they cost, and how they trade off against false negatives.
- [Fingerprint rotation](https://kavralab.com/glossary/fingerprint-rotation/index.md): Fingerprint rotation means changing a device's fingerprint between sessions so one actor looks like a stream of new, unrelated visitors.
- [Fraud ring](https://kavralab.com/glossary/fraud-ring/index.md): A fraud ring is an organized group that shares tools, identities and infrastructure to commit fraud at scale. How rings operate and how to expose them.
- [Friendly fraud](https://kavralab.com/glossary/friendly-fraud/index.md): Friendly fraud is when a real cardholder disputes a purchase they made or authorized. Why it happens, how it differs from a chargeback, and how merchants fight it.
- [Gnoming](https://kavralab.com/glossary/gnoming/index.md): Gnoming is iGaming fraud where one player controls accounts opened in other people's names to claim bonuses repeatedly or gain an edge. How it works and how to spot it.
- [Good bot](https://kavralab.com/glossary/good-bot/index.md): A good bot identifies itself honestly, can be verified and does work you want done, like indexing pages or acting for a real user.
- [Headless browser](https://kavralab.com/glossary/headless-browser/index.md): A headless browser loads and runs web pages without a screen, driven by code. Used for testing, and for bots that need to look like real visitors.
- [Invisible challenge](https://kavralab.com/glossary/invisible-challenge/index.md): An invisible challenge is a background check that tests whether a visitor is a real browser and person, without showing a puzzle. How it works and where it fits.
- [IP reputation](https://kavralab.com/glossary/ip-reputation/index.md): IP reputation is a judgment of how risky an IP address is, based on what it is, who owns it and what traffic has come from it before.
- [Mobile proxy](https://kavralab.com/glossary/mobile-proxy/index.md): A mobile proxy routes traffic through a phone or modem on a cellular network, so requests appear to come from a mobile carrier's IP address.
- [Money mule](https://kavralab.com/glossary/money-mule/index.md): A money mule receives stolen funds and passes them on, hiding the trail. How mule schemes work, how mule accounts look in traffic and how to spot them.
- [Multi-accounting](https://kavralab.com/glossary/multi-accounting/index.md): Multi-accounting is when one person or group runs several accounts where only one is allowed. A short definition, with the full detection playbook linked.
- [Promo abuse](https://kavralab.com/glossary/promo-abuse/index.md): Promo abuse is using coupons, discount codes and first-order offers against the terms, often via many new accounts. How it works and how it differs from bonus abuse.
- [Residential proxy](https://kavralab.com/glossary/residential-proxy/index.md): A residential proxy routes traffic through the IP address of a real home internet connection, so requests look like they come from an ordinary household.
- [Risk score](https://kavralab.com/glossary/risk-score/index.md): A risk score is a number that sums up how likely a visit, login or payment is to be fraud. How scores are built, how to set thresholds and why the reasons matter.
- [Scalping](https://kavralab.com/glossary/scalping/index.md): Scalping is buying up limited tickets or products, usually with bots, to resell them at a markup. A plain definition, how it works and where it hits.
- [SMS pumping](https://kavralab.com/glossary/sms-pumping/index.md): SMS pumping is triggering floods of verification texts to numbers that earn the attacker a share of the fees. A clear definition, the signs and where to stop it.
- [Step-up authentication](https://kavralab.com/glossary/step-up-authentication/index.md): Step-up authentication asks for extra proof, like a one-time code or passkey, only when an action or session looks risky. How it works and when to trigger it.
- [Synthetic identity](https://kavralab.com/glossary/synthetic-identity/index.md): A synthetic identity is a fictitious person assembled from real and invented data, used to open accounts and build credit before a bust-out. How it works and the signs.
- [Tor](https://kavralab.com/glossary/tor/index.md): Tor is a free network that relays traffic through three volunteer servers with layered encryption, so no single server knows both who you are and where you go.
- [Velocity check](https://kavralab.com/glossary/velocity-check/index.md): A velocity check counts how often something happens in a time window, like logins per device or cards per account, and flags bursts that point to abuse.
- [Virtual machine](https://kavralab.com/glossary/virtual-machine/index.md): A virtual machine is a software computer that runs inside a physical one, with its own operating system, and can be copied or reset in seconds.
- [VPN](https://kavralab.com/glossary/vpn/index.md): A VPN sends a device's traffic through an encrypted tunnel to a server elsewhere, so websites see the VPN server's IP address instead of the user's.
- [Web scraping](https://kavralab.com/glossary/web-scraping/index.md): Web scraping is the automated extraction of data from websites, from prices and listings to whole articles. A short definition, with the full defense playbook linked.
