Skip to main content
Residential Proxy Detection

Residential Proxy Detection: The IP Is Clean, the Session Is Not

A residential proxy routes an attacker's request through an IP address an ISP assigned to somebody's home. Your reputation checks see a consumer ISP, a consumer ASN, and no blocklist match, because all of that is true. cside reads the session instead: device signals that survive IP rotation, behavioural signals weighted above any network signal, and a model-scored proxy verdict rather than a list lookup. For location and age-compliance use cases, see VPN Detection.

Where residential proxy IPs actually come from
  • 01

    Informed opt-in

    Someone knowingly installs bandwidth-sharing software and is paid or rewarded for it. This lane can be legitimate when the disclosure, security controls, and acceptable-use enforcement are real. Not every residential proxy is a botnet.

  • 02

    An SDK bundled into a free app

    A developer embeds a proxy SDK in a mobile, desktop, VPN, or streaming app, and the user's connection starts carrying somebody else's traffic. Disclosure ranges from clear to buried to absent. On a smart TV the consent screen is text navigated with a remote control.

  • 03

    Compromised before it was unboxed

    An inexpensive connected device ships with backdoored software or fetches it during setup, so the owner never agreed to anything. FBI advisories tie compromised streaming boxes and other cheap connected hardware to the BADBOX 2.0 botnet and the residential proxy services that resell access to them.

  • 04

    Malware after purchase

    Attackers infect routers, phones, computers, and IoT devices and install relay software, turning a household into an exit node. Lumen's Black Lotus Labs found AVrecon on more than 70,000 small-office and home routers, resold as a residential proxy service.

WITH CSIDE
  • Flag proxied sessions from device and behavioural signals, so rotating to a fresh household IP does not reset the risk
  • Score proxy and VPN use with a machine-learning model rather than depending on a static blocklist
  • Link repeat abuse to one device across many exit IPs, emails, and accounts
  • Catch the anti-detect browsers and headless frameworks that usually sit behind a residential exit node
  • Feed a real-time session verdict into your existing signup, login, checkout, and fraud stack

The node is somebody's living room

No, not literally your toaster. But the FBI's own advisory lists digital picture frames, TV streaming devices, smartphones, tablets, and routers as consumer hardware whose ISP-assigned addresses get used to route other people's traffic. These devices are attractive because they are always powered, always connected, rarely updated, and nobody is watching them.

01

Routers and broadband gateways

The largest category by a distance. Academic profiling of proxy hosts found roughly two thirds were routers, gateways, or wireless access points.

02

Smart TVs and streaming boxes

Always on, always on fast Wi-Fi, and unattended. Named in FBI advisories and central to the BADBOX 2.0 findings.

03

Digital picture frames

Named by the FBI as a device category that can be compromised and used as a proxy node. Researchers found vulnerabilities and automatic malware delivery in one widely sold frame platform; the vendor has since published fixes.

04

IP cameras and DVRs

Cheap, internet-exposed, and seldom patched. Security cameras show up repeatedly in router-and-IoT proxy botnets.

05

Phones and tablets

Usually enrolled through an SDK inside a free app rather than through compromise, which is why the traffic looks entirely ordinary.

06

Windows PCs

Enrolled by malware loaders bundled with cracked software. Proof that not all proxy supply is IoT.

How cside detects a proxied session

01

Network enrichment, then a model

Every session is enriched with IP, geo, and ASN context, then scored by a machine-learning model that returns a proxy and VPN probability. A blocklist is only a fallback, not the mechanism.

02

A device fingerprint that outlives the IP

cside encodes 90-plus browser and device signals into a compact fingerprint. Hardware-rooted signals carry the most weight and network signals the least, by design, so changing the exit IP barely moves the identity.

03

Behaviour weighted above the network

Pointer movement, click cadence, scroll pattern, trusted-event ratio, and automation hooks are the highest-weighted signals cside collects. A rented IP does nothing to make a scripted session look human.

04

One device, many households

Sessions are clustered by fingerprint distance, so a single device appearing behind dozens of unrelated residential addresses stands out as exactly what it is.

Why IP reputation cannot see this

The exit IP is a real consumer address with no history of abuse. Reputation has nothing to fire on.

Approach
cside
IP reputation & blocklists
What is judged The session: device, behaviour, and network together The address the request arrived from
Clean residential IP Flagged by the device and behaviour behind it Passes, there is nothing to match
IP rotation Fingerprint persists across exit nodes Every rotation looks like a new visitor
Proxy verdict Model-scored probability per session Membership of a list that is always behind
Previously unseen networks Scored on behaviour, no prior sighting needed Invisible until someone catalogues them
Repeat abuse One device linked across accounts and addresses No link once the IP changes
Response Allow, step up, or block per session via SDK Blunt block, with collateral damage to real households

What this changes

01

Blocking a residential IP punishes the household that owns it, who is usually a victim rather than the attacker.

02

Because the fingerprint survives rotation, one operator running hundreds of exit nodes still resolves to a small number of devices.

03

A proxy signal is rarely the whole verdict. It matters most combined with device reuse, automation, and velocity on the same session.

04

Proxy signals share the first-party layer used by fingerprinting, bot detection, and account-takeover, so it is one script and one source of truth.

Sources reviewed 29 July 2026: FBI public service announcements on residential proxy networks and connected devices, and Lumen Black Lotus Labs' AVrecon and ngioweb reporting. Device categories and targeted-model lists change quickly, and a model appearing on a research list does not mean every unit of it is compromised.

FAQ

Questions, answered

01 What is a residential proxy?

A residential proxy is an intermediary that routes someone's request through an IP address that an internet service provider assigned to a home or small business. The destination site sees the household's public address rather than the network of the person actually making the request. The device doing the relaying is called an exit node, and its owner is usually a different person entirely from the proxy customer.

02 Can cside detect residential proxies if the IP has a clean reputation?

Yes, because the IP is not what cside judges. A residential exit IP is genuinely clean, so reputation checks pass by design. cside scores the session instead: an ASN-and-geo-enriched model verdict on proxy and VPN use, a device fingerprint built from more than ninety browser and device signals, and behavioural signals that are weighted higher than any network signal. Rotating to a fresh household address does not change the device or the behaviour.

03 Does this rely on a list of known proxy IP addresses?

Not primarily. cside keeps a static IP list as a fallback, but the working mechanism is a machine-learning model that returns a proxy and VPN probability per session, combined with device and behavioural evidence. That is what lets it flag exit nodes that have never appeared on any list, which matters because residential proxy pools are enrolled and rotated continuously.

04 Can cside tell me which device in the home relayed the request?

No, and it does not try to. cside determines that a session is proxied and how risky it is. It does not identify the specific appliance in somebody's house, name the proxy provider, or attribute the traffic to the device owner, who in the compromised lanes is a victim rather than a participant.

05 Are all residential proxies malicious?

No. Some networks are built from people who knowingly opted in and are compensated for it, and there are legitimate uses such as localised site testing and ad verification. Others enrol devices through buried terms, bundled SDKs, or outright malware. The FBI's own advisory lists consenting schemes and compromise in the same set of supply routes, and a single provider can carry both. That is why cside scores a session's risk rather than treating every proxied request as an attack.

06 How is cside deployed?

cside deploys as a single first-party script tag. There is no proxy, no reverse proxy, no CDN dependency, and no DNS change, and cside does not sit in front of your traffic. Session signals start flowing as soon as the script is live, and you can route the verdict into your existing signup, login, checkout, and fraud stack.

Didn't find what you were looking for?

Book a demo
Residential Proxy Detection

The IP is clean. The session is not.

First-party browser signals across real visitor sessions. Deploys via a single script tag.

Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead