IPQS
Golang Database Reader

About the Golang Database Reader

The Golang database reader allows your Golang application to use the on-premise IPQS IP reputation database and make informed decisions about IP addresses.

Installation

Install the Golang database reader by running the following command:

go get -u github.com/IPQualityScore/GoIPQSDBReader

Usage

The following example shows how you can use the Golang database reader in your application to determine if an IP address is a proxy:

Note

Each database only holds either IPv4 or IPv6 data. Therefore, you may need two instances of the reader available depending on your use case.

...
ip := "8.8.0.0";

reader, err := GoIPQSDBReader.Open("IPQualityScore-Reputation-IPV4-Database.ipqs");
if(err != nil){
    panic(err);
}

record, err := reader.Fetch(ip); // Returns a IPQSRecord struct. See further documentation below.
if(err != nil){
    panic(err);
}

if(record.IsProxy){
    fmt.Println(ip + " is a proxy!");
}
...

IPQSRecord Struct Fields

Some of these fields may be unavailable depending on which database file you receive. If the field in question is unavailable in your database, it will default to Golang's default value for that type.

Field Type Description
record.IsProxy bool Is this IP address suspected to be a proxy? (SOCKS, Elite, Anonymous, VPN, Tor, etc.)
record.IsVPN bool Is this IP suspected of being a VPN connection? This can include data center ranges which can become active VPNs at any time. The "proxy" status will always be true when this value is true.
record.IsTOR bool Is this IP suspected of being a TOR connection? This can include previously active TOR nodes and exits which can become active TOR exits at any time. The "proxy" status will always be true when this value is true.
record.IsCrawler bool Is this IP associated with a confirmed crawler from any of the following search engines: Baidu, Google, Bing, Yahoo, Yandex, Sogou, Exabot, DuckDuckGo, Facebook, Twitter, Pinterest, Naver, UptimeRobot, AppleBot, ArchiveBot, CoccocBot, YisouBot, PetalBot, ByteDance, or MailRU.
record.IsBot bool Indicates if bots or non-human traffic has recently used this IP address to engage in automated fraudulent behavior. Provides stronger confidence that the IP address is suspicious.
record.RecentAbuse bool This value will indicate if there has been any recently verified abuse across our network for this IP address. Abuse could be a confirmed chargeback, compromised device, fake app install, or similar malicious behavior within the past few days.
record.IsBlacklisted bool This value will indicate if the IP has been blocklisted by multiple third-party agencies for spam, abuse or fraud.
record.IsPrivate bool This value will indicate if the IP is a private, non-routable IP address.
record.IsMobile bool This value will indicate if the IP is likely owned by a mobile carrier.
record.HasOpenPorts bool This value will indicate if the IP has recently had open (listening) ports.
record.IsHostingProvider bool This value will indicate if the IP is likely owned by a hosting provider or is leased to a hosting company.
record.ActiveVPN bool Identifies active VPN connections used by popular VPN services and private VPN servers.
record.ActiveTOR bool Identifies active TOR exits on the TOR network.
record.PublicAccessPoint bool Indicates if this IP is likely to be a public access point such as a coffee shop, college or library.
record.ConnectionType.Raw int A numerical representation for the suspected type of connection for this IP address. It is generally recommended you call the ToString() function listed below instead of using this value, but it is available as an option.
record.ConnectionType.ToString() int A string representation for the suspected type of connection for this IP address. (Residential, Mobile, Corporate, Data Center, Education or Unknown)
record.AbuseVelocity.Raw int How frequently the IP address is engaging in abuse across the IPQS threat network. Can be used in combination with the Fraud Score to identify bad behavior. It is generally recommended you call the ToString() function listed below instead of using this value, but it is available as an option.
record.AbuseVelocity.ToString() int How frequently the IP address is engaging in abuse across the IPQS threat network. Values can be "high", "medium", "low", or "none".
record.Country string Two character country code of IP address or "N/A" if unknown.
record.City string City of IP address if available or "N/A" if unknown.
record.ISP string ISP if one is known. Otherwise "N/A".
record.Organization string Organization if one is known. Can be parent company or sub company of the listed ISP. Otherwise "N/A".
record.ASN int Autonomous System Number if one is known. Zero if nonexistent.
record.Timezone string Timezone of IP address if available or "N/A" if unknown.
record.Latitude float32 Latitude of IP address if available or 0.00 if unknown.
record.Longitude float32 Longitude of IP address if available or 0.00 if unknown.
record.FraudScore map[int]int A map containing multiple possible fraud scores. The key is the "strictness level" of the query and can be 0, 1 or 2. Some databases may contain 1 entry, others all 3. It is recommended that you use the lowest strictness for Fraud Scoring. Increasing this value will expand the tests we perform. Levels 2+ have a higher risk of false-positives.

record.ConnectionType.Raw fields

# Enum Description
1 Residential IP
2 Mobile IP
3 Corporate IP
4 Data Center IP
5 Educational IP

record.AbuseVelocity.Raw fields

# Enum Description
0 No Recent Abuse
1 Low Recent Abuse IP
2 Medium Recent Abuse IP
3 High Recent Abuse IP

Update

If you already have the Golang database reader installed, you can update it by running:

go get -u github.com/IPQualityScore/GoIPQSDBReader

Ready to eliminate fraud?

Start fighting fraud now with 1,000 Free Lookups!

We're happy to answer any questions or concerns.

Chat with our fraud detection experts any day of the week.

Call us at: (800) 713-2618