Service providers have long recognised that Voice over Internet Protocol (VoIP) services can be exposed to a variety of potentially fraudulent situations.
There are some inherent vulnerabilities that hackers could exploit, namely three way calls and call transfers. In this case, hackers can inject call signals into the network and essentially hijack calls. This then leads to significant non-billable revenue for service providers.
The reason that these vulnerabilities occur is that it’s a relatively simple procedure for anyone who understands VoIP to modify the setup of existing calls. This is because commands associated with VoIP technology are often sent unencrypted and without authorisation for each command.
As a result, legitimate calls can be hijacked or essentially “modified” to either add additional parties into an already established call, for example in a three way call (or bridge) or of more significance, transfer an existing call from one recipient to another. This may well be a long distance call or a call to a premium number. Again, these seem like legitimate initial calls to a service provider, but where the subsequent hijacking is masked from the service provider and so significant revenue is then lost.
To combat this, an obvious route for the service provider to go down is to encrypt the commands and signalling across their networks. The problem here though is that such encryption incurs additional cost. Furthermore, it can also mean a performance burden on the service provider, along with the associated end user equipment.
An alternative, less intrusive means to prevent fraud is to introduce active VoIP policy controls in front of the Call Session Control Function (CSCF). This gateway solution can block or challenge call control messages for authenticity before passing them along to the CSCF.
In order for the latter option to be a success, it’s essential for the service policy gateways to be able to adapt their methods to constantly evolving techniques and security threats. Otherwise these policy controls can become outflanked by new scams.
By using analytical reporting tools, service assurance vendors can provide the type of intelligence required to adapt or reconfigure the policy gateway. These analytical tools can be used to identify patters or traffic peaks within the records, for example relating to call volume and duration, both to and from specific numbers, by processing VoIP-related call records extracted directly from the network. In terms of detection, the answer really lies in being able to identify non-standard behaviour.
The techniques used for this are a bit like the Deep Packet Inspection (DPI) techniques that are utilised today, primarily to determine broadband or data content, even where the payload is encrypted. By first analysing the packets and determining, in this case, non-standard behaviour between specific locations or addresses, an anomalous pattern or a fraudulent call can be identified.
Detecting such activity early gives service providers the opportunity to configure their gateways accordingly, allowing them to effectively minimise the impact of fraud scenarios, as well as the related revenue loss.