Geo Anomaly Checks
Last updated
This page lists the trigger conditions and scores of the four geo anomaly checks and explains how impossible travel is calculated.
Four Checks
| Flag | Condition | Score |
|---|---|---|
geo_high_risk |
History contains a country code listed in HighRiskCountry |
ScoreGeoHighRisk (30) |
geo_hopping |
More than 4 distinct countries within the last hour | ScoreGeoHopping (15) |
geo_frequent_switching |
Within the last hour, >= 4 cities, >= 5 records, and more than 4 city switches between adjacent records |
ScoreGeoFrequentSwitch (20) |
rapid_geo_change |
The two newest records are under an hour apart and the implied speed is > 800 km/h, or the move is > 500 km within 30 minutes |
ScoreGeoRapidChange (25) |
geo_high_risk currently never fires because of a field mismatch; see Known Issues.
Impossible Travel
Distance uses the haversine formula with an Earth radius of 6371 km, and speed is distance divided by the time gap. 800 km/h is roughly airliner cruising speed, which normal movement never exceeds, while VPN node switches and rotating proxy pools do.
| Example | Distance | Gap | Result |
|---|---|---|---|
| Taipei → Tokyo | about 2,100 km | 10 minutes | Fires (both the speed and 30-minute rules hold) |
| Taipei → Taichung | about 140 km | 20 minutes | Does not fire (420 km/h) |
| Taipei → Tokyo | about 2,100 km | 3 hours | Not compared (over one hour) |
For enabling GeoLite2, location caching, and history storage, see Geo Detection.