DETECTION ENGINEERING

Browser bot detection: make the blind spots part of the test

Separate missing collection from a missed detection. Test browser signals, consent, fresh sessions and recovery without claiming universal bot coverage.

By Blokk.Bot · Published

Follow the evidence before judging the detector

A test runner can attempt eight visits while the application receives no useful events. The store may redirect to a password page, consent may prevent collection, or the client may never execute JavaScript. Calling that result a detection failure skips the question of whether the detector received anything it could assess.

Record distinct stages: navigation attempted, page loaded, observation accepted, assessment produced and expected finding present. Add policy and execution results only when the scenario actually exercises them. This makes a failed test actionable: an access problem needs a different fix from an accepted event that the detector handled incorrectly.

Start with a signal whose meaning is narrow

The W3C WebDriver interface defines a browser automation flag. It lets cooperating browsers disclose WebDriver control; it does not state why the browser is automated or whether the activity is unwanted. An ordinary test suite can produce this signal, so a matching finding should describe automation evidence without inventing intent.

Blokk can retain a reported WebDriver signal when its browser observation reaches the service. That gives a useful positive control. The report is still supplied by the browser and is not tamper-proof. A missing assertion does not certify a human visitor, and a present assertion does not identify an AI model or agent provider.

Exercise missing and concealed evidence separately

Use an HTTP-only client to test the no-JavaScript boundary, and a separate scripted browser without the ordinary automation signal to test reliance on that signal. The first may never supply browser telemetry. The second may supply accepted observations without the expected automation finding. Report those different outcomes explicitly.

Repeat a permitted browsing task in fresh browser contexts as another control. Do not automatically join those sessions into a single attacker because their sequence looks similar. A fixture can establish that the runner coordinated them; the production detector may have no trustworthy evidence of shared identity.

A consent-denied scenario should not be scored as unwanted automation merely because its evidence is missing. Test withdrawal after an initially permitted visit as well. Confirm which later observations are absent, rather than assuming a consent choice persisted just because the test clicked a button.

For recovery, interrupt only the collector connection in an isolated test and then restore it. Check accepted receipts, retries and any delayed observations. An old event arriving after recovery should not become evidence of a fast new cart burst. In Blokk’s current account policy, timing eligibility is distinct from whether an event can be retained for monitoring.

Use the result to choose the next improvement

Blokk Bot Test separates traffic, collection, detection and enforcement results. Our private test plan includes bounded fresh-context, concealed-traversal, consent-withdrawal and collection-recovery probes. Scripted actors do not use a live AI model. They test the chosen behaviour; they do not represent every shopping agent or establish accuracy on genuine customers.

Prioritise gaps against the action your product is intended to protect. Missing browser evidence might require a separate trusted server integration, rather than another browser heuristic. Unverified checkout execution needs a controlled checkout experiment. Keep unsupported surfaces and unknown outcomes in the report, so a green browser scenario cannot silently stand in for an untested protection claim.

Sources and further reading

Connect protection to your application.

Explore the API and SDK workflow, then tell us which action you want to protect. We’ll help you plan the integration.

Explore the API integration Ask about setup

Keep reading

All articles