| Risk-signal layer | Users who need first-pass screening and prioritization | Risk scores, blocklists, shared-exit tags, and abnormal activity | It is easy to mistake it for the final verdict | Low | Best as an alert layer, weak as a final verdict |
| Network-role layer | Users who need to tell VPN, proxy, Tor, and ordinary hosting apart | ASN, prefixes, ports, service role, and sharing patterns | It needs integrated evidence and cannot rely on one field | Medium | Best as the main judgment layer |
| False-positive control layer | Users who worry about misclassifying edge platforms, public DNS, or enterprise networks | CDN/Anycast, ordinary cloud samples, broadband samples, and business context | The workflow is slower but cuts false positives sharply | Medium | Best as the final review layer |