> Can we have a spamhaus for ad fraud?
There are a lot of vendors in this space now, offering various kinds of "spamhaus"-type solutions. They're all crap because they operate blacklists of various kinds to keep their customers dependent.
The ideal scenario is for ad networks/SSPs to implement the anti-fraud technology themselves, however getting there from here is difficult: The first ad network to go clean will be at a significant (fiscal) disadvantage.
I'd like to get in touch with anyone ad network/SSP that wants to go first.
> lists of botnet infected IPs participating in ad fraud
This won't be enough.
A popular "audience extender" is to use an iframe containing your site as an ad tag, and run it on your display network. Unless you have been using an ad blocker for the last ten years (and maybe even then), it's very likely your IP address has been used in ad fraud.
> lists of offending/incompetent SSP blindly accepting forged requests
Google facilitates an enormous amount of ad fraud, but media buyers have to buy from Google because nobody else sells Google search ads (except, I suppose, the injection people...)
Yahoo purchased a company who was selling video ads that were muted using uncommon AS3 mixer controls.
I think a much shorter list would be the media suppliers that don't have ad fraud on them and don't facilitate ad fraud. You'll find such a list below.