This site uses cookies and other technologies that let us and the companies we work with collect information about your device and usage of the site to enable functionality, analytics, and advertising. See our Cookie Notice for details.
Residential Proxy Detection: The IP Is Clean, the Session Is Not
A residential proxy routes an attacker's request through an IP address an ISP assigned to somebody's home. Your reputation checks see a consumer ISP, a consumer ASN, and no blocklist match, because all of that is true. cside reads the session instead: device signals that survive IP rotation, behavioural signals weighted above any network signal, and a model-scored proxy verdict rather than a list lookup. For location and age-compliance use cases, see VPN Detection.
Where residential proxy IPs actually come from
01
Informed opt-in
Someone knowingly installs bandwidth-sharing software and is paid or rewarded for it. This lane can be legitimate when the disclosure, security controls, and acceptable-use enforcement are real. Not every residential proxy is a botnet.
02
An SDK bundled into a free app
A developer embeds a proxy SDK in a mobile, desktop, VPN, or streaming app, and the user's connection starts carrying somebody else's traffic. Disclosure ranges from clear to buried to absent. On a smart TV the consent screen is text navigated with a remote control.
03
Compromised before it was unboxed
An inexpensive connected device ships with backdoored software or fetches it during setup, so the owner never agreed to anything. FBI advisories tie compromised streaming boxes and other cheap connected hardware to the BADBOX 2.0 botnet and the residential proxy services that resell access to them.
04
Malware after purchase
Attackers infect routers, phones, computers, and IoT devices and install relay software, turning a household into an exit node. Lumen's Black Lotus Labs found AVrecon on more than 70,000 small-office and home routers, resold as a residential proxy service.
WITH CSIDE
Flag proxied sessions from device and behavioural signals, so rotating to a fresh household IP does not reset the risk
Score proxy and VPN use with a machine-learning model rather than depending on a static blocklist
Link repeat abuse to one device across many exit IPs, emails, and accounts
Catch the anti-detect browsers and headless frameworks that usually sit behind a residential exit node
Feed a real-time session verdict into your existing signup, login, checkout, and fraud stack
The node is somebody's living room
No, not literally your toaster. But the FBI's own advisory lists digital picture frames, TV streaming devices, smartphones, tablets, and routers as consumer hardware whose ISP-assigned addresses get used to route other people's traffic. These devices are attractive because they are always powered, always connected, rarely updated, and nobody is watching them.
01
Routers and broadband gateways
The largest category by a distance. Academic profiling of proxy hosts found roughly two thirds were routers, gateways, or wireless access points.
02
Smart TVs and streaming boxes
Always on, always on fast Wi-Fi, and unattended. Named in FBI advisories and central to the BADBOX 2.0 findings.
03
Digital picture frames
Named by the FBI as a device category that can be compromised and used as a proxy node. Researchers found vulnerabilities and automatic malware delivery in one widely sold frame platform; the vendor has since published fixes.
04
IP cameras and DVRs
Cheap, internet-exposed, and seldom patched. Security cameras show up repeatedly in router-and-IoT proxy botnets.
05
Phones and tablets
Usually enrolled through an SDK inside a free app rather than through compromise, which is why the traffic looks entirely ordinary.
06
Windows PCs
Enrolled by malware loaders bundled with cracked software. Proof that not all proxy supply is IoT.
How cside detects a proxied session
01
Network enrichment, then a model
Every session is enriched with IP, geo, and ASN context, then scored by a machine-learning model that returns a proxy and VPN probability. A blocklist is only a fallback, not the mechanism.
02
A device fingerprint that outlives the IP
cside encodes 90-plus browser and device signals into a compact fingerprint. Hardware-rooted signals carry the most weight and network signals the least, by design, so changing the exit IP barely moves the identity.
03
Behaviour weighted above the network
Pointer movement, click cadence, scroll pattern, trusted-event ratio, and automation hooks are the highest-weighted signals cside collects. A rented IP does nothing to make a scripted session look human.
04
One device, many households
Sessions are clustered by fingerprint distance, so a single device appearing behind dozens of unrelated residential addresses stands out as exactly what it is.
Why IP reputation cannot see this
The exit IP is a real consumer address with no history of abuse. Reputation has nothing to fire on.
Approach
cside
IP reputation & blocklists
What is judged
The session: device, behaviour, and network together
The address the request arrived from
Clean residential IP
Flagged by the device and behaviour behind it
Passes, there is nothing to match
IP rotation
Fingerprint persists across exit nodes
Every rotation looks like a new visitor
Proxy verdict
Model-scored probability per session
Membership of a list that is always behind
Previously unseen networks
Scored on behaviour, no prior sighting needed
Invisible until someone catalogues them
Repeat abuse
One device linked across accounts and addresses
No link once the IP changes
Response
Allow, step up, or block per session via SDK
Blunt block, with collateral damage to real households
What this changes
01
Blocking a residential IP punishes the household that owns it, who is usually a victim rather than the attacker.
02
Because the fingerprint survives rotation, one operator running hundreds of exit nodes still resolves to a small number of devices.
03
A proxy signal is rarely the whole verdict. It matters most combined with device reuse, automation, and velocity on the same session.
04
Proxy signals share the first-party layer used by fingerprinting, bot detection, and account-takeover, so it is one script and one source of truth.
Sources reviewed 29 July 2026: FBI public service announcements on residential proxy networks and connected devices, and Lumen Black Lotus Labs' AVrecon and ngioweb reporting. Device categories and targeted-model lists change quickly, and a model appearing on a research list does not mean every unit of it is compromised.
FAQ
Questions, answered
01 What is a residential proxy?
A residential proxy is an intermediary that routes someone's request through an IP address that an internet service provider assigned to a home or small business. The destination site sees the household's public address rather than the network of the person actually making the request. The device doing the relaying is called an exit node, and its owner is usually a different person entirely from the proxy customer.
02 Can cside detect residential proxies if the IP has a clean reputation?
Yes, because the IP is not what cside judges. A residential exit IP is genuinely clean, so reputation checks pass by design. cside scores the session instead: an ASN-and-geo-enriched model verdict on proxy and VPN use, a device fingerprint built from more than ninety browser and device signals, and behavioural signals that are weighted higher than any network signal. Rotating to a fresh household address does not change the device or the behaviour.
03 Does this rely on a list of known proxy IP addresses?
Not primarily. cside keeps a static IP list as a fallback, but the working mechanism is a machine-learning model that returns a proxy and VPN probability per session, combined with device and behavioural evidence. That is what lets it flag exit nodes that have never appeared on any list, which matters because residential proxy pools are enrolled and rotated continuously.
04 Can cside tell me which device in the home relayed the request?
No, and it does not try to. cside determines that a session is proxied and how risky it is. It does not identify the specific appliance in somebody's house, name the proxy provider, or attribute the traffic to the device owner, who in the compromised lanes is a victim rather than a participant.
05 Are all residential proxies malicious?
No. Some networks are built from people who knowingly opted in and are compensated for it, and there are legitimate uses such as localised site testing and ad verification. Others enrol devices through buried terms, bundled SDKs, or outright malware. The FBI's own advisory lists consenting schemes and compromise in the same set of supply routes, and a single provider can carry both. That is why cside scores a session's risk rather than treating every proxied request as an attack.
06 How is cside deployed?
cside deploys as a single first-party script tag. There is no proxy, no reverse proxy, no CDN dependency, and no DNS change, and cside does not sit in front of your traffic. Session signals start flowing as soon as the script is live, and you can route the verdict into your existing signup, login, checkout, and fraud stack.