You started scraping prices on Wildberries or monitoring ads on Avito — and within minutes, requests begin returning a CAPTCHA or a 403 error. Most likely, the site is protected by the HUMAN Security system, which was previously known as PerimeterX. This is one of the most aggressive anti-bot systems in the world, and standard datacenter proxies are practically useless against it. In this article, we will analyze how this protection works and what actually helps to deal with it.
What is HUMAN Security (PerimeterX) and where is it found
HUMAN Security is an American company that specializes in protecting websites from bots, scrapers, and automated traffic. In 2022, it acquired PerimeterX — one of the most well-known anti-bot platforms — and now sells a combined solution under the HUMAN brand. However, in the professional community of scrapers and arbitrageurs, the name “PerimeterX” is still used synonymously with this protection.
The system is implemented on the website side in the form of a JavaScript snippet and a cloud traffic filter. The clients of HUMAN Security include major retailers, marketplaces, financial platforms, and media sites. If you work with any of the following areas, you have almost certainly encountered this system:
- Marketplace scraping — Ozon, Wildberries, Yandex.Market, and their foreign counterparts (Amazon, eBay, Shopify stores) actively use anti-bot protection.
- Competitor price monitoring — almost any large online store with dynamic pricing is protected from automated requests.
- Ticket and hotel aggregators — Booking, Aviasales, Ticketmaster, and their analogs primarily block bots.
- Advertising platforms — Facebook Ads, TikTok Ads, and Google Ads use their own detection systems, which partially overlap with the logic of HUMAN Security.
- Classified ads websites — Avito and its analogs protect pages from mass content scraping.
According to the company itself, HUMAN Security processes over 20 trillion requests per week and protects thousands of large resources worldwide. This means that encountering this system is not a rarity but a daily reality for anyone engaged in automated data collection or multi-accounting.
How the protection works: what exactly the system analyzes
To understand which proxies and tools help, it is necessary to delve into the logic of the protection itself. HUMAN Security does not just look at the IP address — it collects a whole “digital portrait” of the visitor and compares it with the benchmark behavior of a live person. Here’s what the system analyzes:
1. IP Address Reputation
The first and most obvious signal is the IP itself. The system checks it against dozens of databases: is it a datacenter IP, is it listed in spam lists, has it been used for attacks before, how many requests have already come from it. An IP from a datacenter (Amazon AWS, Hetzner, OVH, etc.) immediately raises suspicion — such addresses are not intended for residential internet use.
2. Behavioral Analysis (Behavioural Biometrics)
The HUMAN Security JavaScript snippet collects data on mouse movements, page scrolling, pauses between clicks, typing speed. A bot moves the cursor in a perfectly straight line or doesn’t move it at all — this instantly reveals automation. A live person always leaves “noise”: slight deviations, pauses, random movements.
3. Browser Fingerprint
The system takes a complete fingerprint of the browser: version, installed plugins, screen resolution, time zone, supported fonts, WebGL rendering, Canvas fingerprint, audio parameters. If you use Selenium or Puppeteer without additional settings, the browser is immediately recognized as automated — it lacks dozens of parameters typical for a real user.
4. HTTP Header Analysis
The order of headers, User-Agent values, the presence or absence of Accept-Language, Accept-Encoding, Sec-Fetch-* headers — all of this is analyzed and compared with benchmark profiles of real browsers. A mismatch in even a few parameters raises the “bot score” of the request.
5. Request Speed and Pattern
If 500 requests come from one IP in a minute — that’s a clear bot. But HUMAN Security can also recognize more subtle patterns: overly regular intervals between requests, identical navigation routes, absence of resource loading (CSS, images) that a real browser typically requests.
Key takeaway:
HUMAN Security makes blocking decisions based on a combination of signals, not a single parameter. This means that “fooling” it just by changing the IP is not enough — you need to work comprehensively: correct IP + realistic browser fingerprint + human-like behavior.
Why Datacenter Proxies Do Not Work Against HUMAN Security
Datacenter proxies are IP addresses rented from commercial datacenters (Hetzner, OVH, DigitalOcean, Amazon AWS, etc.). They are fast, cheap, and well-suited for tasks where website protection is weak or absent. However, against HUMAN Security, they are practically powerless for several reasons:
Instant ASN Identification. Each IP address belongs to a specific autonomous system (ASN). Datacenter ASNs (e.g., AS16276 — OVH, AS24940 — Hetzner) have long been listed in databases as “non-residential.” HUMAN Security checks the ASN first — and if the IP belongs to a datacenter, the bot score immediately skyrockets.
Mass “Burning” of Pools. Datacenter proxies are used by thousands of other users for similar tasks. If even one of them previously got banned from this IP — the reputation of the address is spoiled for everyone. Datacenter proxy pools “burn out” very quickly, especially on sites with serious protection.
Absence of an Address “Legend.” A real residential IP has a history: it is used by one user for months, visiting different sites, and has a pattern of activity. A datacenter IP has no such history — it appeared yesterday and immediately began making thousands of requests.
This does not mean that datacenter proxies are useless — for tasks without aggressive anti-bot protection (scraping open data, working with APIs, SEO monitoring of simple sites), they remain a fast and economical solution. But for sites with HUMAN Security, other tools are needed.
Which Proxies Actually Help: Comparison of Types
Two types of proxies work against HUMAN Security — residential and mobile. Let’s break down each in detail and compare them for specific tasks.
Residential Proxies
Residential proxies are IP addresses of real home users who voluntarily provided their devices to the pool. From the perspective of any website, such a request looks like an ordinary home user with a real provider (Rostelecom, MTS, Beeline, and their foreign counterparts). The ASN of such an IP belongs to an ISP (internet service provider), not a datacenter — this is a fundamental difference.
Residential proxies are well-suited for:
- Scraping marketplaces (Wildberries, Ozon, Amazon) in moderate volumes
- Competitor price monitoring — a few thousand requests per day
- Checking ad placements from different regions
- Working with social media accounts through anti-detect browsers
- Verifying ads on Avito and similar platforms
Mobile Proxies
Mobile proxies are IP addresses from mobile operators (4G/5G). They have a unique property: one mobile IP is used simultaneously by hundreds of real users because operators use NAT (Network Address Translation). This means that the site is “used” to seeing a huge flow of heterogeneous traffic from one mobile IP — and cannot block it without cutting off real customers.
Mobile proxies are the number one choice for:
- Farming and warming up Facebook Ads and TikTok Ads accounts
- Working with Instagram, TikTok through automation
- Tasks where maximum IP “trustworthiness” is needed
- Bypassing the most aggressive options of HUMAN Security protection
Below is a comparative table of three types of proxies concerning tasks with HUMAN Security:
| Parameter | Datacenter | Residential | Mobile |
|---|---|---|---|
| Bypassing HUMAN Security | ❌ Poor | ✅ Good | ✅✅ Excellent |
| Connection Speed | ⚡⚡⚡ High | ⚡⚡ Medium | ⚡⚡ Medium |
| IP Trustworthiness | Low | High | Maximum |
| Suitable for Facebook/TikTok Ads | ❌ No | ✅ Yes | ✅✅ Best choice |
| Marketplace Scraping | ⚠️ Only simple sites | ✅ Yes | ✅ Yes |
| Price per GB of Traffic | 💲 Low | 💲💲 Medium | 💲💲💲 Higher |
Anti-detect Browsers + Proxies: A Combination for SMM and Arbitrage
If you work with accounts on Facebook Ads, Instagram, TikTok, or manage multi-accounting for SMM agency clients — just proxies are not enough. HUMAN Security and similar systems on advertising platforms analyze not only the IP but also the entire browser fingerprint. This is where anti-detect browsers come into play.
An anti-detect browser creates a separate isolated profile with a unique fingerprint for each account: its own User-Agent, Canvas, WebGL, time zone, language settings, screen resolution. Combined with a quality proxy, each profile looks like a separate live user from a different device and IP.
Dolphin Anty
Popular among arbitrageurs working with Facebook Ads. Supports team collaboration and has a built-in proxy manager. To connect a proxy: open the profile → "Proxy" tab → select type (HTTP/SOCKS5) → enter host, port, username, and password. It is recommended to use residential or mobile proxies with rotation.
AdsPower
Well-suited for SMM agencies managing client accounts on Instagram and TikTok. Proxy setup is similar to Dolphin: create a profile → "Proxy" section → enter data → click "Check" to verify the connection. Important: the time zone and language of the browser must match the proxy's geolocation.
GoLogin and Multilogin
GoLogin is a more affordable option with a good base of free features. Multilogin is a professional solution for large teams with advanced fingerprint customization capabilities. Both support all types of proxies and allow the creation of hundreds of isolated profiles.
The rule “1 account = 1 proxy”:
Never use one proxy for multiple accounts simultaneously. If one account gets banned, the system will automatically mark the IP as suspicious — and all other accounts on that IP will be at risk. This is called chain-ban, and to prevent it, each profile needs its unique IP.
Proxy Setup for Scraping and Price Monitoring
If you are monitoring prices on Wildberries, Ozon, or Yandex.Market, the task is slightly different from multi-accounting: here, the volume of requests and speed are important, not the uniqueness of each profile. Let’s discuss the optimal approach.
Step 1. Choose Rotating Residential Proxies
For scraping marketplaces, rotating residential proxies are optimal — with each new request or at a specified interval (e.g., every 5-10 minutes), the IP automatically changes. This simulates the behavior of different users and prevents the system from accumulating statistics on one address.
Step 2. Set Delays Between Requests
Even with good proxies, you should not make requests every second. Recommended intervals for sites with HUMAN Security: 3-8 seconds between requests from one IP. If you are using rotation — you can go a bit faster, but still not instantaneously. Add random “noise” to the intervals: not exactly 5 seconds, but 4.2, then 6.7, then 3.9.
Step 3. Use Real User-Agents
In the settings of the scraper or ready-made monitoring tool, always specify the current User-Agent of real browsers. An outdated Chrome 89 in 2025 is a red flag for any anti-bot system. Use current versions: Chrome 124+, Firefox 125+.
Step 4. Consider Geolocation
For monitoring Russian marketplaces, use proxies with Russian IPs. Wildberries and Ozon may show different prices and assortments depending on the region — this is important to consider during setup. Ensure that the time zone and language of the browser match the selected geo.
Step 5. Test Proxies Before Launching
Before a large-scale launch, manually check several IPs from the pool: access the target site through them and ensure that the page loads without CAPTCHA and redirects. If 20-30% of IPs immediately trigger CAPTCHA — the pool is “burned out” and you need to change the provider or geo.
Checklist: How to Avoid Being Blocked by HUMAN Security
Let's compile everything into a practical checklist. Go through each item before launching any task where HUMAN Security may be encountered:
✅ Proxy Selection
- Use residential or mobile proxies (not datacenter)
- Proxies match the geo of the target site
- IP rotation is enabled (if the task is scraping)
- A separate IP is allocated for each account (if the task is multi-accounting)
✅ Browser Fingerprint
- Use an anti-detect browser (Dolphin Anty, AdsPower, GoLogin, Multilogin)
- Fingerprint is unique for each profile/account
- Time zone matches the geo of the proxy
- Browser language matches the geo of the proxy
- User-Agent is the current version of Chrome or Firefox
✅ On-Site Behavior
- Delays between requests — random, not even (3-8 seconds)
- No suspiciously high request frequency from one IP
- Session starts from the homepage, not directly from the target URL
- All page resources (CSS, images) are loaded, not just HTML
✅ Testing and Monitoring
- Proxies tested on the target site before large-scale launch
- Monitoring of successful and unsuccessful requests is set up
- In case of an increase in the percentage of blocks — immediate change of pool or type of proxy
- Accounts warmed up before active actions (for multi-accounting)
It is worth mentioning separately the warming up of accounts for arbitrageurs. A new Facebook Ads or TikTok Ads account that immediately starts running ads with a large budget is an anomaly from the platform's perspective. Even with good proxies and anti-detect, such an account will attract increased attention from the security system. Proper warming up: 3-7 days of activity (likes, views, small expenses), and only then — scaling.
Conclusion
HUMAN Security (PerimeterX) is a multi-layered system that analyzes dozens of parameters simultaneously: IP reputation, browser fingerprint, user behavior, and request patterns. It is impossible to bypass it “head-on” using datacenter proxies — the system sees them immediately. But this does not mean that the task is unachievable.
The working formula looks like this: quality proxy with a real IP + anti-detect browser with a unique fingerprint + human-like behavior. Each of these elements is important, and neglecting any of them reduces the chances of success.
For most tasks — scraping marketplaces, price monitoring, working with social media accounts — the optimal start will be residential proxies: they provide a good balance between IP trustworthiness, speed, and cost. If you are farming Facebook Ads or TikTok Ads accounts and need the highest level of trust — consider mobile proxies: their IP addresses have the highest reputation among all types and are least likely to get blocked even on the most protected platforms.
```