Updated Date: 07/07/2026
Customizing Automatic Transaction default settings
Customize the Automatic Transaction default settings if you want to change one or more of the automatic transaction alert scores or modify settings that determine if a transaction is bot-originated.
-
On the Main tab, click Security > Fraud Protection Service > Anti-Fraud Profiles.
The Anti-Fraud Profiles screen opens.
-
From the list of profiles, select the relevant profile.
The Anti-Fraud Profile Properties screen opens.
-
In the Anti-Fraud Configuration area, click URL List.
The URL List opens.
-
Click the URL or view on which you want to customize Automatic Transactions default settings (or click Add URL or Add View if you want to define a new URL or view with Automatic Transactions detection).
The URL Properties (or View Properties) screen opens.
-
In the URL Configuration (or View Configuration) area, select Automatic Transactions.
The Automatic Transactions configuration options appear.
-
Ensure that the Enabled check box for Automatic Transactions is selected.
-
Click Advanced.
The Automatic Transactions advanced settings are listed.
-
For Bot Score, type a number to add to the total risk score of the anti-fraud profile if the system determines that the client is a bot and not human.
-
For Suspected Bot Score, type a number to add to the total risk score of the anti-fraud profile if the system suspects (but has not verified) that the client is a bot and not human.
-
For Minimum Mouse Movements, type the minimum number of mouse movements needed (per page load) for the system to consider the transaction to be of human origin.
-
For Button User Interactions, type the minimum number of times the mouse should be placed on the Submit button on a web form for the system to consider the transaction to be of human origin.
Note: If the mouse moves over the Submit button and then moves away, the count returns to 0.
-
For Score (for Minimum Mouse Movements and Button User Interactions), type a number to add to the total risk score if mouse movements or button user interactions are determined to be bot-originated.
-
For Page Read Time (sec), type the minimum number of seconds needed from when a web form opens to when the Submit button is clicked. The default is 2 seconds.
-
For Score (for Page Read Time), type a number to add to the total risk score of the anti-fraud profile if the time between when a web form opens and the Submit button is clicked is less than the number of seconds assigned for Page Read Time.
-
For Tampered Cookie Score, type a number to add to the total risk score of the anti-fraud profile if the system detects that the Transactions Data cookie was removed.
-
For Data Manipulation Score, type a number to add to the total risk score of the anti-fraud profile if the system detects data manipulation in one of the following situations:
- If the HTTP request sent or received by the URL is URL-encoded and one or more parameters have the Check Data Manipulation attribute, the BIG-IP system checks for a difference between the actual value of a parameter and the expected value of a parameter sent when a user clicks a web form’s Submit button. If a difference is detected the score entered here is added to the total risk score of the anti-fraud profile, for each parameter marked with Check Data Manipulation.
- If the HTTP request is not URL-encoded and Check AJAX Payload for Data Manipulation is enabled, the BIG-IP system checks for a difference between the actual value of the Ajax payload sent by the client’s browser and the expected value of the Ajax payload. If a difference is detected, the score entered here is added to the total risk score of the anti-fraud profile.
-
For Data Manipulation Maximum Score, type a number to limit the total combined score that can be added to an alert score when the BIG-IP system detects that data manipulation occurred on two or more parameters.
For example, if you set Data Manipulation Score to 20 and the value here is 50, if the system detects data manipulation on 3 parameters a value of 50 is added to the alert score instead of 60 (which is the actual combined value).
Note: Data Manipulation Maximum Score is only relevant if the HTTP parameters are in query string or form format and two or more URL parameters have the Check Data Manipulationattribute.
-
For Minimum Score to Send Alert, type a number for the minimum total score required to send an alert to the FPS Dashboard.
-
Click Save.
The changes you made to the Automatic Transactions settings are saved.