Device Intelligence System
Device Intelligence System (DIS) allows you to analyze the technical context of sessions based on information about the device, network, location, and environment from which the user interacts.
The collected smart signals help identify configurations or patterns that may require a more detailed review.
What you can do
From Device Intelligence System, you can:
View the general activity recorded during a period.
Identify the smart signals detected most frequently.
Locate sessions using filters.
Access the details of a session.
Analyze device and connection information.
Review the events recorded during each operation.
View the activity recorded in the audit log.
Access the related identity, when available.
A smart signal provides context about the session, but by itself it does not confirm that fraud exists. Interpret it together with the rest of the available information.
How it is organized
Device Intelligence System is divided into three areas:
Dashboard, to view aggregated information.
Sessions, to locate a session.
Session detail, to analyze the information recorded during that session.
Dashboard
The Dashboard provides an overview of the activity recorded during the selected period.
Use it to identify changes in activity, view the most frequent smart signals, and decide which information you need to investigate in more detail.
View the main indicators
The indicators summarize the activity for the selected period:
Unique visitors.
Unique devices.
Smart signals detected.
When a comparison with the previous period is shown, use it to identify how activity has changed.
A variation does not necessarily imply a positive or negative trend. It should be interpreted according to the type of indicator and the context.
Change the period
Use the date selector to modify the analyzed range.
When you select a new period, the Dashboard indicators and blocks are updated with the corresponding data.
The selected range cannot exceed one year.
View the smart signals
The smart signals block shows the signals detected most frequently during the selected period.
Among others, signals related to the following may appear:
VPN use.
Incognito browsing.
Residential proxies.
Data center IP addresses.
Devices with a high volume of activity.
Development tools.
Bots.
Modified devices or devices with elevated privileges.
The signals are ordered according to their detection volume.
Select View all to view the full list when there are more results than are initially shown.
The Dashboard shows aggregated information. To investigate a specific case, locate the corresponding session from Sessions.
Sessions
Sessions shows the sessions recorded by Device Intelligence System.
Each row represents a session and provides access to all the information collected during its execution.
Filter sessions
Use the available filters to narrow the results by:
Date.
Country.
Environment.
Status.
When you apply multiple filters, the sessions must meet all the selected criteria.
If you select multiple values within the same filter, the sessions that match any of those values are shown.
View the list
Each row shows the main available data about a session, such as:
Session ID.
Associated user, when available.
Channel.
Date and time.
Status.
Some data may not appear if it was not received during the session or if the user was not identified.
Open a session
Select View session in the corresponding row to open the full detail.
If the applied filters return no results, modify or remove one of them to broaden the search.
Session detail
Session detail brings together all the information recorded during a session.
The header lets you identify the session and view its main data. The rest of the information is organized into tabs.
Select a tab to view another category of information. Changing tabs does not modify the session data.
Summary
Summary provides an overview of the session.
Use it as a starting point to understand the context before reviewing more specific information.
It may include:
Session ID.
Date and duration.
Associated user.
Channel and environment.
Main device information.
Main connection information.
Summary of the detected smart signals.
When there is an associated identity, select the available access to open its detail and view other sessions and related information.
Summary is a read-only view and does not allow you to modify the session status.
Alerts
Alerts shows the smart signals detected during the session.
For each signal, you can view its name, result, and the available contextual information.
View a smart signal
Select the information icon of a signal to open its detail.
The information shown helps you understand:
What condition the signal detects.
What result was recorded.
In what context it may occur.
Close the detail to return to the signal list.
Detecting a smart signal does not automatically change the session status.
Devices
Devices shows the technical information of the device used during the session.
Depending on the available data, it may include:
Device type.
Operating system and version.
Browser.
Device identifier or fingerprint.
Technical configuration.
Indicators related to device integrity.
Use this information to check whether the device shows any unusual condition or whether it matches other available records.
Devices is a read-only view. It does not allow you to modify or block the device.
Network & Location
Network & Location brings together the available information about the connection and the approximate location of the session.
It may include:
IP address.
Country, region, or city.
Network provider.
Connection type.
Use of VPN or proxy.
Other network-related smart signals.
Use this tab to contextualize where the interaction took place and check whether the connection presents conditions that require attention.
The location obtained from an IP address is approximate and may be affected by VPNs, proxies, or other network services.
Network & Location is a read-only view. It does not allow you to modify or block an IP address or a network.
Timeline
Timeline shows the events recorded during the session in chronological order.
When a session contains several operations, its events are grouped into separate blocks. This makes it possible to identify what happened within each operation without mixing their data.
View an operation
Review the header of each block to identify the corresponding operation.
Within the block, you can view the events, the smart signals, and the rest of the activity recorded during that operation.
Collapse or expand an operation
Select the control in the upper-right corner of the block to show or hide its content.
You can collapse the operations you do not need to review to reduce scrolling and focus on the relevant information.
Reconstruct the activity
Review the elements in chronological order to identify:
What events occurred.
When a smart signal was detected.
In which operation it was recorded.
What result each event had, when available.
Timeline is a read-only view. The recorded events cannot be modified.
Audit log
Audit log shows the actions performed on the session from the back office.
Each record may include:
Date and time.
User who performed the action.
Action.
Result.
Use this tab to review the traceability of the queries and actions performed by FIP users.
Audit log is a read-only view. Records cannot be edited or deleted.
Timeline shows what happened during the session. Audit log shows the actions performed afterward from the back office.
How to investigate a session
To analyze a session:
Start with Summary to understand its general context.
View the smart signals detected in Alerts.
Review the technical information in Devices.
Check the connection in Network & Location.
Use Timeline to reconstruct the order of events.
View Audit log to review the actions performed from the back office.
Access the related identity when you need to expand the context.
Do not base a conclusion solely on a smart signal.
Last updated