> For the complete documentation index, see [llms.txt](https://docs.facephi.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.facephi.com/docs.facephi-en/products/facephi-intelligence-platform/modulos/behaviour/behavioral-detection-system.md).

# Behavioral Detection System

BDS (Behavioural Detection System) analyzes behavior during a session to detect patterns, anomalies, and signals that may indicate risky activity.

Unlike a one-off check, BDS analyzes how the interaction evolves throughout the entire session and provides context to investigate behavior that deviates from what is expected.

<figure><img src="/files/f3649fd23a8019d0f9d6e38e741f97420e87c74d" alt=""><figcaption></figcaption></figure>

From BDS, you can:

* Review session activity.
* Analyze its geographic distribution.
* Identify Smart signals and track their evolution.
* Search and filter sessions.
* Open a session to investigate what happened.
* Review the alerts detected.
* Analyze the person's biometric behavior.
* Review device, network, and location information.
* Review telephony information when available.
* Analyze interaction metrics.
* Reconstruct the session chronologically.
* Review the available traceability.
* Generate or review a session report, when available.

{% hint style="info" %}
BDS is an analysis and observability tool. A signal or anomaly does not by itself confirm fraud. Use the full set of session information to put it into context.
{% endhint %}

***

## How it's organized

BDS is organized into four main areas:

* **Dashboard**, to review an aggregated view of activity.
* **Sessions**, to locate specific sessions.
* **Session detail**, to investigate a session in depth.
* **Report**, to review consolidated information available about a session.

Within the detail, you can find:

* **Summary**
* **Alerts**
* **Biometrics**
* **Device**
* **Network & Location**
* **Telephony**
* **Analytics**
* **Timeline**
* **Audit log**

The available information may vary depending on the platform, the device, and the data that could have been collected during the session.

***

## Dashboard

Dashboard provides an aggregated view of the sessions analyzed by BDS and makes it possible to quickly detect changes in risk, alerts, signals, and decisions recorded during the selected period.

Use it as a starting point to identify which activity requires a more detailed investigation.

### Filter the information

The controls at the top affect the information shown in Dashboard.

<figure><img src="/files/585f50945881b66834d963d6f14a4988566d7849" alt=""><figcaption></figcaption></figure>

#### Time range

Select **Time range** to define the period you want to analyze.

The indicators and widgets are updated with the sessions corresponding to the selected interval.

When a variation is shown, the value is compared with the equivalent previous period.

#### Additional filters

Select **Filter** to apply other available criteria.

The number next to the control indicates how many filters are active.

#### Remove filters

Select **Clear all** to remove the applied filters and restore the initial view.

***

### Main indicators

The top of Dashboard shows four indicators that summarize the activity for the period.

<figure><img src="/files/55dbd0565691e6c26be63214421ab2dd8a2539c5" alt=""><figcaption></figcaption></figure>

#### Total sessions

Shows the total number of sessions analyzed.

The indicator includes all channels considered by BDS and shows their evolution compared with the previous period.

Use it to understand the overall volume of activity before interpreting the rest of the metrics.

#### Average risk score

Shows the average risk of the analyzed sessions on a scale of `0–100`.

The variation indicates how many points it has increased or decreased compared with the previous period.

An increase in average risk does not mean that all sessions are risky. Use **Risk over time**, **Risk alerts** and the sessions list to identify where it is concentrated.

#### Alerts generated

Shows the total number of alerts generated during the period.

It can also indicate how many correspond to a high risk level.

Use **Risk alerts** to find out which types of alert appear most frequently.

#### Sessions with alerts

Shows how many sessions have at least one associated alert.

It also indicates what percentage they represent of the total number of sessions.

This indicator makes it possible to distinguish between:

* The total volume of alerts.
* The number of sessions affected by those alerts.

The same session can contain multiple alerts.

{% hint style="info" %}
The four indicators show aggregated information. To find out what happened in a specific session, use the sessions list and open its detail.
{% endhint %}

***

### Risk over time

Risk over time shows how sessions and risk evolve during the selected period.

The chart compares:

* **Total sessions**, with the total volume of sessions.
* **Risk sessions**, with the sessions identified as risky.

<figure><img src="/files/763c3839d436f754ad38836571866c29cd7abb40" alt=""><figcaption></figcaption></figure>

Use it to identify:

* Sudden increases in risk.
* Periods with a higher concentration of risky sessions.
* Whether an increase in risk coincides with an overall increase in volume.
* Trend changes that require a more detailed investigation.

Compare this chart with **Risk alerts** and **Smart signals** to understand what may be causing a variation.

***

### Smart signals

Smart signals shows the signals detected most frequently during the analyzed sessions.

Each card shows:

* Signal name.
* Number of detections.
* Variation compared with the previous period.
* Signal source.
* Access to additional information about its meaning.

<figure><img src="/files/d83976de0d0fd3d812ba639ba459de5aae2130d8" alt=""><figcaption></figcaption></figure>

#### Signal source

Each Smart signal includes a label that identifies its origin:

* **DIS**, when the signal comes from Device Intelligence.
* **BDS**, when it comes from Behaviour analysis.

The BDS Dashboard can show signals from both sources to provide a combined view of session risk.

{% hint style="info" %}
The DIS or BDS label indicates where the detection comes from. It does not represent the risk level of the signal.
{% endhint %}

#### Sort signals

Use the selector above the cards to change the sorting criterion.

By default, you can prioritize signals with the highest number of detections using **Most detections first**.

#### Review a signal

Select the information icon for a Smart signal to learn its meaning and get more context about the detection.

See the [**Smart signals**](#smart-signals-1) section of this documentation to learn the details of each signal.

#### See all signals

Select **View all** to access the full set of available Smart signals.

### Meaning of Smart signals

#### VPN

Indicates that the session uses a virtual private network (VPN).

A VPN can modify or hide the visible IP address or location of the connection.

Interpret this signal together with the location, the network used, and the rest of the session indicators.

#### Incognito mode

Indicates that the session is running in private or incognito browsing mode.

This mode may limit some of the information available about the browser or the session.

Its use does not by itself imply suspicious activity.

#### Unknown device

Indicates that the session is being carried out from a device that does not match previously known or recognized information.

Review the available history, the associated identity, and the rest of the context before determining its relevance.

#### Residential proxy

Indicates that the connection uses a proxy associated with a residential IP address.

This type of connection can make it harder to identify the true origin of the traffic by making it appear to come from a conventional residential connection.

#### Datacenter IP

Indicates that the connection comes from an IP address associated with a data center, hosting provider, or similar infrastructure.

This can be common in certain technical contexts, but it is less common in a session carried out directly from a residential connection.

#### High-activity device

Indicates that the device shows an unusually high volume of activity during the analyzed period.

It can help identify devices used intensively or associated with a high number of interactions.

Also review the session frequency and the rest of the signals associated with the device.

#### Suspicious Behaviour

Indicates that BDS has identified an interaction pattern that deviates from expected behavior and requires additional context.

View **Biometrics** and **Analytics** to learn about the metrics that contribute to this detection.

#### Developer tools

Indicates that active developer tools were detected during the session.

These tools can be used for legitimate purposes, but they also allow the behavior of an application or website to be inspected or modified.

#### Bad bots

Indicates that the activity shows characteristics associated with malicious automation or bots classified as risky.

Review the interaction, the activity speed, and the rest of the signals to put the detection into context.

#### Device anomalies

Indicates that anomalous characteristics have been detected on the device or in its execution environment.

View **Device** and the rest of the associated signals to see the available context.

#### Rooted device

Indicates that an Android device shows signs of root access.

Root access changes the usual operating system restrictions and may reduce some of its security guarantees.

#### Tor

Indicates that the IP address used is associated with the Tor network or appears in a list of known Tor nodes.

Tor can hide the true origin of a connection by routing traffic through different nodes.

#### Network anomalies

Indicates that BDS has detected unusual or inconsistent characteristics in the network used during the session.

View **Network & Location** to analyze the IP, the provider, the location, and the rest of the available context.

#### Android Emulator

Indicates that the application may be running in an emulated Android environment rather than on a conventional physical device.

Emulators can be used for legitimate development and testing purposes, but they can also be part of automated or manipulated environments.

#### Velocity anomaly

Indicates that an activity or movement pattern inconsistent with the elapsed time was detected.

For example, it may be related to rapid changes between IP addresses, countries, or locations.

Review related sessions to understand the context of the anomaly.

#### Factory reset

Indicates signs compatible with a recent factory reset of the device.

A reset can modify or remove some of the information used to recognize a previously known device.

#### Attack IP blocklist

Indicates that the IP address used appears on a list associated with attack sources or known malicious activity.

Review the session and the other network signals before determining its relevance.

#### Geolocation spoofing

Indicates that there are signs the location reported by the device may have been manipulated.

Compare this information with the location obtained through the network and with previous sessions when available.

#### Tampering

Indicates that signs of tampering with the application, the device, or its runtime environment were detected.

The detection may be related to modifications that alter the expected behavior of the application.

#### Jailbreak

Indicates that an iOS device shows signs of jailbreak.

Jailbreaking removes or modifies certain operating system restrictions and can reduce some of its security protections.

#### Frida

Indicates that signals related to Frida or other runtime instrumentation techniques have been detected.

These tools can be used to inspect or modify the behavior of an application while it is running.

#### Cloned app

Indicates that the application may be running from a copy or cloned instance.

Review the device and the rest of the signals to determine whether the situation corresponds to an expected environment.

#### MitM attack

Indicates signs compatible with a Man-in-the-Middle attack.

In this type of situation, a third party may try to intercept or alter the communication between the device and the service.

{% hint style="warning" %}
Smart signals should be analyzed together. The combination of several signals can provide more context than an isolated detection.
{% endhint %}

***

#### Risk alerts

Risk alerts shows the types of alert generated most frequently during the sessions.

Each row shows:

* Alert type.
* Number of detections.

<figure><img src="/files/70a6a2c522ce70220d4ecc2c464cd2787c7243fc" alt=""><figcaption></figcaption></figure>

The view may show alerts such as:

* **Unknown Device**
* **ATO**
* **Mobile Malware**
* **Location Spoofing**
* **Language Tampering**
* **Suspicious Behaviour**

Use this widget to identify which types of risk are most prevalent during the period.

An alert can appear multiple times, and the same session can contain more than one.

#### Open the sessions with alerts

Select **View sessions with alerts** to access the list of sessions that contain alerts and continue the investigation.

From the list, you can use the available filters to narrow down the results.

***

### Decision flags

Decision flags shows how the recorded responses to the risk detected during the sessions are distributed.

<figure><img src="/files/6643b921df3abcdff07fd1bb41e7437938d571f4" alt=""><figcaption></figcaption></figure>

It may include:

* **Allow**
* **Challenge**
* **Block**
* **Quarantine**

Each category shows the number of associated sessions.

#### Allow

Indicates that the session could continue without requiring any additional action.

#### Challenge

Indicates that an additional check was requested before allowing the flow to continue.

#### Block

Indicates that the session was blocked due to the evaluated conditions.

#### Quarantine

Indicates that the session was set aside to apply the treatment defined by the corresponding configuration.

{% hint style="info" %}
Decision flags is reference information. BDS shows the response recorded during the session, but the rules and actions that produce it are configured outside this screen.
{% endhint %}

***

### Geolocation

Geolocation provides a summarized view of the geographic distribution of the sessions included in the analyzed period.

Use this section to quickly identify from which countries or areas the activity is concentrated and detect distributions that may require a more detailed review.

<figure><img src="/files/be787b4025b53fc36e79c3be543278fd2b95310f" alt=""><figcaption></figcaption></figure>

The information shown is updated according to the filters applied in Dashboard.

#### Open the session map

Select **View session map** to access the full view of sessions on the map.

{% hint style="info" %}
The location may be approximate and depends on the information available during the session.
{% endhint %}

### Network threats

Network threats shows the volume of sessions associated with different network categories or detected threats.

<figure><img src="/files/57c499fdf123e9432489d352c9fc8bc5a07c3aa7" alt=""><figcaption></figcaption></figure>

It may include:

* **STD**
* **VPN**
* **Proxy**
* **Bot**
* **Tor**

Each category shows the number of detections recorded.

Use this information together with the Smart signals and **Network & Location** to put possible anomalies related to the connection origin into context.

{% hint style="info" %}
A VPN, proxy, or Tor network does not by itself confirm fraudulent activity.
{% endhint %}

***

## Session map

Session map lets you explore recorded sessions geographically and locate those you need to investigate.

The map represents sessions using points or clusters according to their location.

### Review a location

Select a point or cluster on the map to review the information available about the sessions in that area.

Depending on the zoom level and the number of sessions, you may find:

* Individual sessions.
* Clusters of multiple sessions.
* Information about the selected country or location.

Use the map controls to zoom in or out and explore other areas.

### Open a session

Select a session from the map to review the available information.

From there, you can open its detail and continue the investigation.

{% hint style="info" %}
The location may be approximate and depends on the information obtained during the session. Interpret it together with the rest of the available signals and evidence.
{% endhint %}

***

## Review sessions

Sessions gathers the sessions analyzed by BDS and lets you locate those that need a more detailed investigation.

<figure><img src="/files/15aa6f5c2ac9bf40583930a12f9aa7e62dfa5ae2" alt=""><figcaption></figcaption></figure>

From this screen, you can:

* Search for a session.
* Apply filters.
* Sort the results.
* Review its risk and alerts.
* Review basic information about the device and network.
* Open its detail.

### Search sessions

Use **Search** to locate a session using any of the available identifiers.

According to the recorded information, you can search by data such as:

* Session ID.
* User ID.
* Visitor ID.
* Device ID.
* IP address.

The search can be combined with active filters.

### Filter sessions

Select **Filters** to narrow down the results.

Available filters may include:

* **Risk**
* **Alerts**
* **Channel**
* **Operating system**
* **ISP**
* **Network type**
* **Date range**
* **Tags**

Filters from different categories are applied together.

Active filters remain visible so you can identify which criteria affect the list.

### Results

Each row represents a session.

The list shows the information needed to identify it and quickly assess whether it requires a more detailed investigation.

#### Risk

Shows the risk level or score associated with the session.

Use it together with Alerts and the rest of the available information.

A high score indicates that the session needs more context, not that fraud is confirmed.

#### Alerts

Shows the number of alerts associated with the session.

A session can contain several alerts of different types.

#### Date

Shows the date and time when the session was recorded.

By default, the most recent sessions appear first.

#### Session ID

Shows the unique identifier of the session.

#### Duration

Shows how long the session lasted.

Use this information together with Analytics when you need to understand the speed or behavior of the interaction.

#### Location

Shows the location available for the session.

The accuracy depends on the collected data and should be interpreted together with the network information.

#### Channel

Indicates which channel the session was carried out through.

#### Operating system

Shows the detected operating system.

#### Device

Shows the information available to identify the device used.

#### ISP

Shows the Internet service provider associated with the connection.

#### Actions

Includes the action to open the session detail.

### Sort results

Select the header of a sortable column to switch between ascending and descending order.

Sorting is applied to the results that match the active filters.

By default, the most recent sessions appear first.

### Open a session

Select the view action for a session.

It will open **Session detail** with all the available information for that session.

When you return to the list, the search and filter context is preserved as long as navigation allows it.

***

## Session detail

Session detail brings together the evidence and data collected during a session.

Use it to reconstruct what happened, understand the detected signals, and relate them to the observed behavior.

The header lets you identify the session and may include:

* Session ID.
* Associated identity.
* Date and time.
* Available status or result.
* Risk level or score.
* Contextual session information.

When there is an associated identity, you can access it from the available link.

BDS does not modify the identity status.

***

## Summary

Summary offers a quick reading of the session before you go deeper into the rest of the sections.

<figure><img src="/files/fe120a16548157d66b1c1a9a7d9375c0230354eb" alt=""><figcaption></figcaption></figure>

It may include indicators such as:

* Risk level or score.
* Number of alerts.
* Duration.
* Channel or platform.
* Device.
* Location.
* Result or response recorded during the session.

Use Summary to determine which areas you need to investigate next.

{% hint style="info" %}
The Summary indicators summarize the available information. Check the specific sections to understand the context of each result.
{% endhint %}

***

## Alerts

Alerts gathers the alerts generated during the session.

<figure><img src="/files/79e81df82200b70a127e66e7ab4c42519a61f145" alt=""><figcaption></figcaption></figure>

Each alert may include:

* Type.
* Risk level.
* When it was detected.
* Screen or point in the journey where it appeared.
* Additional information when available.

### Interpret an alert

An alert points to a condition that requires additional context.

Based on the information obtained, BDS can identify situations related to:

* Suspicious behavior.
* Patterns compatible with account takeover.
* Unknown devices.
* Device anomalies.
* Network anomalies.
* Malware.
* Location manipulation.
* Other risky conditions detected during the session.

Do not interpret an alert based only on its name or severity.

Review:

* The related evidence.
* Biometrics.
* Device.
* Network & Location.
* Analytics.
* Timeline.

***

## Biometrics

Biometrics shows the analysis of the behavior observed during the interaction.

Behavioral biometrics analyzes **how a person interacts**, not their physical characteristics.

It can use browsing, typing, touch interaction, or other available behaviors to identify deviations from a baseline.

<figure><img src="/files/486e01bfb438999920248694e2c83e2977258680" alt=""><figcaption></figcaption></figure>

### Behaviour score

Behaviour score summarises the result of the behavioural analysis of the session.

Use it as an indicator within the evidence set.

Do not interpret it in isolation.

### Baseline maturity

Baseline maturity indicates the level of information available to build a reference of expected behaviour.

A more mature reference makes it possible to contextualise the observed differences in new sessions more effectively.

When there is still little information, interpret anomalies with greater caution.

### Behaviour anomaly

Behaviour anomaly summarises the degree of deviation detected from the reference behaviour.

An anomaly indicates that the observed pattern differs from what was expected, but it does not by itself confirm that fraud is taking place.

### Behavioural signals

Depending on the environment and the available information, signals related to the following may appear:

* Suspicious behavior.
* Anomalous navigation.
* Anomalous typing.
* Anomalous touch interaction.
* Session speed.
* Automation.
* Device sharing.
* Remote access.
* Screen sharing.
* Active calls.
* Malware.

***

## Device

Device shows information about the device used during the session.

<figure><img src="/files/2c3e924d052a9b2dd5aece5869b7d47d4bc584b1" alt=""><figcaption></figcaption></figure>

It may include:

* Device type.
* Brand and model.
* Operating system.
* System version.
* Browser.
* Available identifiers.
* Application information.
* Relevant state or technical context.

Use this information to check whether the device is consistent with the available behaviour and history.

***

## Network & Location

Network & Location shows the network and location context of the session.

<figure><img src="/files/55859a331dca82b2ba7371fa25fcf2627a0a2866" alt=""><figcaption></figcaption></figure>

It may include:

* IP address.
* ISP.
* ASN.
* Network type.
* Country.
* Region or city.
* Approximate location.
* Coordinates, when available.
* Indicators related to VPN, proxy, or Tor.
* Other detected network anomalies.

### Compare the location

Use the location together with:

* Session history.
* Location obtained from the network.
* The information reported by the device.
* Smart signals.
* Speed anomalies.

Differences between multiple sources can provide context for the investigation.

{% hint style="info" %}
Location can have different levels of precision. A difference between locations does not necessarily imply manipulation.
{% endhint %}

***

## Telephony

Telephony shows the telephony information available during mobile sessions.

<figure><img src="/files/58034997f5799016829528871d1d0c72d3b58751" alt=""><figcaption></figcaption></figure>

This section may not appear or may contain less data when the device, operating system, or permissions do not allow it to be obtained.

### Available information

It may include information related to:

* Carrier.
* SIM country.
* SIM status.
* Mobile network.
* Mobile Country Code (MCC).
* Mobile Network Code (MNC).
* Cell information.
* Call-related status, when available.

Use this data to identify possible inconsistencies between the SIM, the network, the location, and the rest of the device context.

### Data not available

The absence of information may be due to:

* Operating system restrictions.
* Device permissions.
* No SIM.
* Unsupported platform.
* Information that could not be obtained during the session.

Do not automatically interpret unavailable data as an anomaly.

***

## Analytics

Analytics shows metrics on how the interaction unfolded during the session.

These metrics help explain why BDS has identified a certain anomaly or behaviour.

<figure><img src="/files/59f8537ef6e3896a7dae4364f58aedb5234870ad" alt=""><figcaption></figcaption></figure>

### Navigation speed

Shows the speed at which the person moves through the Flow.

A speed significantly different from the expected behaviour may require more context.

### Form completion time

Shows the time spent completing forms or specific parts of the process.

Interpret it together with the screen complexity and other interaction metrics.

### Corrections and deletes

Shows the corrections or deletions made while information is being entered.

It can help contextualise the session's typing patterns.

### Focus changes

Shows the focus changes recorded during the interaction.

Depending on the platform, they may be related to changes between fields, tabs, applications, or other surfaces.

### Copy and paste events

Shows the copy and paste events detected during the session.

Use them as additional context when analysing how the information was entered.

### Mouse trajectory

When available, analyse the mouse movement pattern.

It can help distinguish certain human and automated interaction patterns.

### Device orientation

On compatible devices, it shows information related to recorded orientation changes.

This metric may not be applicable in certain environments.

### Screen transitions

Shows how changes occur between the different screens in the journey.

See Timeline when you need to relate these transitions to a specific moment in the session.

### Behaviour confidence

Indicates the level of confidence available for interpreting the behavioural analysis.

Use it to contextualise the rest of the metrics and results.

{% hint style="info" %}
No Analytics metric by itself confirms fraudulent activity. Interpret the behaviour, alerts, and technical context together.
{% endhint %}

***

## Timeline

Timeline reconstructs the events recorded during the session chronologically.

<figure><img src="/files/baf12d898db1055a3e00aa22573405e9a5a4d8e5" alt=""><figcaption></figcaption></figure>

Use it to understand:

* What happened.
* In what order.
* When an alert occurred.
* Which screen was active.
* When an anomaly appeared.
* What response occurred afterwards.

### Navigate Timeline

The events appear sorted by date and time.

Each event may include:

* Name or type.
* Timestamp.
* Screen or location within the journey.
* Result.
* Related signal or alert.
* Additional available information.

Use Timeline to relate the evidence from the different sections and reconstruct the full sequence.

***

## Audit log

Audit log shows the traceability available for the session and for the actions performed on it from the Backoffice.

The information is read-only.

It may include:

* Action.
* User who performed it.
* Date and time.
* Affected item.
* Additional information where applicable.

Audit log helps distinguish between:

* What happened during the session.
* The actions performed later from the Backoffice.

{% hint style="info" %}
Timeline explains what happened during the session. Audit log shows the traceability of the actions recorded on that information.
{% endhint %}

***

## How to investigate a session

{% hint style="info" icon="note" %}
To investigate a session with BDS:

1. Use **Dashboard** to identify activity or signals that require attention.
2. Review **Risk over time** to detect changes in risk progression.
3. View **Smart signals** to identify the most frequent conditions.
4. Review **Risk alerts** and **Decision flags** to understand what was detected and how the system responded.
5. Use **Geolocation** and **Session map** when location is relevant.
6. View **Network threats** to contextualise the origin of the connections.
7. Use **Sessions** to locate the session you want to investigate.
8. Check in **Summary** its main indicators.
9. View **Alerts** to identify the detected conditions.
10. Review **Biometrics** to understand the observed behaviour.
11. Analyse **Device** and **Network & Location** to contextualise the technical environment.
12. View **Telephony** when relevant mobile information is available.
13. Use **Analytics** to delve deeper into the interaction metrics.
14. Review **Timeline** to reconstruct the full sequence.
15. View **Audit log** when you need to know the subsequent traceability.
    {% endhint %}

Avoid basing a conclusion solely on a score, an alert, or a Smart signal. The investigation should be supported by all available information.
