All articles Network & IP

IP Velocity and Churn: Measuring How Fast an Identity Moves Across Networks

A normal customer might use three or four IP addresses in a week: home Wi-Fi, the office, their phone on cellular. A device that touches forty unrelated IPs across a dozen ASNs in an hour is not a customer, it is a proxy pool or an automation script.

IP velocity and churn measure exactly this: how fast an identity moves between addresses, and how many distinct addresses it accumulates. Together they turn the chaos of modern networking into a clean, quantifiable fraud signal, but only if you measure them against a stable identity and interpret them with an understanding of legitimate movement.

Defining the two measures

  • IP velocity is the rate of change: distinct IP transitions per unit of time for one identity. A user who switches networks twice a day has low velocity; a client hopping IPs every request has extreme velocity.
  • IP churn is the accumulated breadth: the count of distinct IPs an identity touches over a window (an hour, a day, a week). Low churn is normal; explosive churn is a proxy tell.

Neither means anything without an anchor. Measured per IP they are undefined. Measured per account they are blind to attackers who spread across accounts. Measured per device, keyed on a stable visitorId, they become sharp.

Why churn exposes proxies and automation

Every network-evasion tool inflates these numbers:

  1. Rotating proxies deliberately maximize churn, a fresh exit IP per request drives both velocity and churn to extremes.
  2. VPN and proxy chains produce jumps across unrelated hosting ASNs that a single physical user could never traverse.
  3. Emulator and device farms cycle connectivity and proxies to fake many users, spiking churn on a small number of underlying devices.
  4. Credential-stuffing kits rotate networks between attempts to dodge rate limits, leaving a churn fingerprint even when each individual IP looks clean.

The common thread: all of them break the natural continuity of a real user’s network, and churn is how you see the break.

Measuring it correctly

Anchor churn on a stable device identity and layer in network context. Prynt provides a persistent visitorId plus ASN and datacenter classification on every event, so you can compute churn per device and weight it by whether the jumps cross unrelated networks. A device that spans dozens of hosting ASNs in minutes scores very differently from one that drifts between a home ISP and a mobile carrier. See how the network signals attach ASN context to every visitorId so churn reflects real network distance, not raw IP count.

Build the signal like this:

  • Per-visitorId distinct-IP counts over rolling windows (1 hour, 1 day, 7 days).
  • Cross-ASN weighting. Count a jump between unrelated ASNs as far heavier than a jump within one carrier’s address space. Ten IPs in one ISP is nothing; ten IPs across ten hosting providers is everything.
  • Geographic spread. Factor how far apart the IPs geolocate, discounting mobile carriers where roaming is expected.
  • Velocity thresholds by ASN type. Allow higher natural churn for mobile ASNs and tighter limits for fixed broadband.

Choosing the right windows

Churn is only as good as the time windows you compute it over. Too short and normal network switching looks alarming; too long and a slow, patient attacker blends into a week of legitimate movement. Run several windows in parallel, an hour, a day, and a week, and score them together. Sudden bursts show up in the short windows, while low-and-slow proxy abuse accumulates in the long ones. Establish per-ASN-type baselines for each window so you know what normal looks like for mobile versus broadband, then alert on deviations from that baseline rather than fixed universal thresholds that will always misjudge one network type or another.

Avoiding false positives on real movement

Legitimate users do churn, and you must not punish it:

  • Mobile roaming produces frequent, related IP changes within a carrier. Discount churn inside a single mobile ASN.
  • Wi-Fi-to-cellular handoffs create bursts of change during a commute. Widen tolerances for known mobile networks.
  • Travelers and VPN-using privacy folks legitimately span geographies. Use churn as a score input, not an automatic block, and combine it with other signals before acting.

The distinction that separates fraud from life is coherence. Real movement stays within related networks and plausible geography. Proxy-driven churn scatters across unrelated ASNs with impossible velocity. Measuring churn per device, weighted by network distance, captures that difference precisely.

IP churn is one of the few network signals that gets stronger as attackers try harder to hide, because evasion itself generates the pattern. Anchor it on a stable device identity and it becomes one of the most reliable proxy and automation detectors in your stack.

Compute per-device IP churn on your own traffic and see the attackers separate from the roamers. Start free on the pricing page and add velocity scoring to your rules.

Try it free

Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.

Keep reading