voip fraud analysis

56
Simon Woodhead Managing Director [email protected] Simwood eSMS Limited https://www.simwood.com/ @simwoodesms Tel: 029 2120 2120 VoIP Fraud Analysis

Upload: simon-woodhead

Post on 20-Jun-2015

455 views

Category:

Technology


3 download

DESCRIPTION

Simon Woodhead, founder & CEO of Simwood, presenting the company's research and solutions to VoIP Fraud. Simwood is a UK based wholesale telecommunications provider. See https://www.simwood.com for more information or to get your copy of the full Simwood VoIP Fraud Analysis whitepaper, go to http://blog.simwood.com/2014/02/voip-fraud-analysis/

TRANSCRIPT

Page 1: VoIP Fraud Analysis

Simon Woodhead Managing Director

[email protected]

Simwood eSMS Limited https://www.simwood.com/@simwoodesmsTel: 029 2120 2120

VoIP Fraud Analysis

Page 2: VoIP Fraud Analysis

www.simwood.com

INTRODUCTION

Wholesale Voice (and fax!)

!UK Numbering

Termination UK PSTN Virtual Interconnect

Page 3: VoIP Fraud Analysis

www.simwood.com

INTRODUCTION

Page 4: VoIP Fraud Analysis

www.simwood.com

INTRODUCTION

https://www.simwood.com http://blog.simwood.com

Page 5: VoIP Fraud Analysis

www.simwood.com

TOLL FRAUD & DIAL THROUGH FRAUD

$46bn ( but essentially unlimited )

Page 6: VoIP Fraud Analysis

www.simwood.com

TOLL FRAUD & DIAL THROUGH FRAUD

Operator

Carrier

Wholesaler

Reseller

Retailer

Cost

Profit

Page 7: VoIP Fraud Analysis

www.simwood.com

TOLL FRAUD & DIAL THROUGH FRAUD

Loss

Carrier

Wholesaler

Reseller

Retailer

OperatorCost

Profit

Page 8: VoIP Fraud Analysis

www.simwood.com

TOLL FRAUD & DIAL THROUGH FRAUD

PRS Outpayment

Carrier

Wholesaler

Reseller

Retailer

OperatorCost

Profit

Outpayment

Page 9: VoIP Fraud Analysis

www.simwood.com

TOLL FRAUD & DIAL THROUGH FRAUD

PRS Outpayment

Loss

Carrier

Wholesaler

Reseller

Retailer

Profit to Fraudster

OperatorCost

Profit

Outpayment

Page 10: VoIP Fraud Analysis

www.simwood.com

COMMERCIAL PRESSURE

VOICE IS BECOMING A FEATURE, RATHER THAN A SERVICE

THE WISE MINIMISE RISK, RATHER THAN MAXIMISE THEORETICAL MARGIN

Billed Minute Revenue

Fraud Costs

Page 11: VoIP Fraud Analysis

www.simwood.com

SIMWOOD HONEYPOT

60 minutes in the Simwood Darknet on a Sunday afternoon

Page 12: VoIP Fraud Analysis

www.simwood.com

SIMWOOD HONEYPOT

http://mirror.simwood.com/honeypot

Page 13: VoIP Fraud Analysis

www.simwood.com

KEY INTRUSION METHODS

SIP Scan !

Stage 1: Reconnaissance

Page 14: VoIP Fraud Analysis

www.simwood.com

KEY INTRUSION METHODSSIP SCAN

OPTIONS sip:[email protected] SIP/2.0!Via: SIP/2.0/UDP XXX.XXX.XXX.XXX:5151;branch=z9hG4bK-4181329969;rport!Content-Length: 0!From: "sipvicious"<sip:[email protected]>; tag=6332303064323361313363340132…!Accept: application/sdp!User-Agent: friendly-scanner!To: "sipvicious"<sip:[email protected]>!Contact: sip:[email protected]:5151!CSeq: 1 OPTIONS!

Page 15: VoIP Fraud Analysis

www.simwood.com

KEY INTRUSION METHODSSIP SCAN

0

450

900

1,350

1,800

2011 2012 2013

Growth in reconnaissance traffic (events by year)

Page 16: VoIP Fraud Analysis

www.simwood.com

KEY INTRUSION METHODSSIP SCAN

Sources of reconnaissance traffic (12 months)

Other!165

UK!56

USA!529

Germany!644

Page 17: VoIP Fraud Analysis

www.simwood.com

KEY INTRUSION METHODSSIP SCAN

SIP Scan !

Stage 2: Scan

Page 18: VoIP Fraud Analysis

www.simwood.com

KEY INTRUSION METHODSSIP SCAN

REGISTER sip:XXX.XXX.XXX.XXX SIP/2.0!To: <sip:[email protected]>!From: <sip:[email protected]>;tag=ba255b19!Via: SIP/2.0/UDP XXX.XXX.XXX.XXX:11184;branch=z9hG4bK-d87543-1477;rport!Call-ID: 8f60483ce717142b!CSeq: 1 REGISTER!Contact: <sip:[email protected]:11184>!Expires: 3600!Max-Forwards: 70!Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, NOTIFY, MESSAGE, SUBSCRIBE…!User-Agent: eyeBeam release 3006o stamp 17551!Content-Length: 0!

Page 19: VoIP Fraud Analysis

www.simwood.com

KEY INTRUSION METHODSSIP SCAN

Growth in scan traffic (events by year)

0

17,500,000

35,000,000

52,500,000

70,000,000

2011 2012 2013

7,206,750

21,855,874

66,991,700

Page 20: VoIP Fraud Analysis

www.simwood.com

KEY INTRUSION METHODSSIP SCAN

Sources of scan traffic (12 months)

Republic of Korea!569,708

Thailand!2,135,810

Anonymous Proxy!2,453,447UK!

2,944,596

USA!6,194,621

Germany!47,803,899

Page 21: VoIP Fraud Analysis

www.simwood.com

KEY INTRUSION METHODS

Targeted Exploit

Page 22: VoIP Fraud Analysis

www.simwood.com

KEY INTRUSION METHODS

Auto-provisioning

Page 23: VoIP Fraud Analysis

www.simwood.com

TRAFFICINVITE sip:[email protected] SIP/2.0!To: 000XXXXXXXXXXXX<sip:[email protected]>!From: 1000<sip:[email protected]>;tag=1ba25ae7!Via: SIP/2.0/UDP XXX.XXX.XXX.XXX:5070;branch=z9hG4bK-50489a18;rport!Call-ID: 50489a186c9c2ff6adacfcc8edb55af1!CSeq: 1 INVITE!Contact: <sip:[email protected]:5070>!Max-Forwards: 70!Allow: INVITE, ACK, CANCEL, BYE.!User-Agent: sipcli/v1.8!Content-Type: application/sdp!Content-Length: 281!!v=0!o=sipcli-Session 12278792 2114349621 IN IP4 XXX.XXX.XXX.XXX!s=sipcli!c=IN IP4 XXX.XXX.XXX.XXX!t=0 0!m=audio 5072 RTP/AVP 0 101!a=fmtp:101 0-15!a=rtpmap:0 PCMU/8000!a=rtpmap:101 telephone-event/8000!a=sendrecv.

Page 24: VoIP Fraud Analysis

www.simwood.com

TRAFFIC

Growth in call traffic (events by year)

0

17,500

35,000

52,500

70,000

2011 2012 20133,035

17,241

63,353

Page 25: VoIP Fraud Analysis

www.simwood.com

TRAFFIC

Sources of call traffic (12 months)

Germany!2,146Netherlands!

2,739

France!2,864

UK!3,193

Europe!4,213

USA!12,322

Palestine!28,795

Page 26: VoIP Fraud Analysis

www.simwood.com

TRAFFIC

Test Traffic

Page 27: VoIP Fraud Analysis

www.simwood.com

TRAFFIC

Location of test numbers (12 months)

Rest of World!2,140Palestine!

1,341

USA!2,461

UK!7,588

Israel!36,971

Page 28: VoIP Fraud Analysis

www.simwood.com

TRAFFIC

25% of test traffic from 2 numbers

50% from the top 10

Page 29: VoIP Fraud Analysis

www.simwood.com

TRAFFIC

Mostly ordinary ‘landline’ numbers

Page 30: VoIP Fraud Analysis

www.simwood.com

TRAFFIC

Absent from commercial

feeds

Page 31: VoIP Fraud Analysis

www.simwood.com

TRAFFIC

Reminder: This is Test Traffic

Page 32: VoIP Fraud Analysis

www.simwood.com

TRAFFIC

The visible attack hasn’t yet

started

Page 33: VoIP Fraud Analysis

www.simwood.com

TRAFFIC

Live DTF Traffic

Page 34: VoIP Fraud Analysis

www.simwood.com

SOLUTIONS

No-Cost Solutions

Page 35: VoIP Fraud Analysis

www.simwood.com

SOLUTIONS

Bill frequently, monitor

continuously

Page 36: VoIP Fraud Analysis

www.simwood.com

SOLUTIONS

Buy with prepayment

( Where they can kill calls in progress when credit exhausted! )

Page 37: VoIP Fraud Analysis

www.simwood.com

SOLUTIONS

Use a carrier with real-time billing &

CDRs

Page 38: VoIP Fraud Analysis

www.simwood.com

SOLUTIONS

Use honeypot data http://mirror.simwood.com/honeypot

Page 39: VoIP Fraud Analysis

www.simwood.com

SOLUTIONS

99.79% of 64m intrusions use the user agent “friendly-scanner”

Page 40: VoIP Fraud Analysis

www.simwood.com

SOLUTIONS

Use TLS ( Or at least TCP )

Page 41: VoIP Fraud Analysis

www.simwood.com

SOLUTIONS

Avoid auto-provisioning

( Or at least filter by user agent, rate limit and log! )

Page 42: VoIP Fraud Analysis

www.simwood.com

SOLUTIONS

Monitor & control off-net

Page 43: VoIP Fraud Analysis

www.simwood.com

SOLUTIONSMONITOR & CONTROL OFF-NET

Example 1: Value of calls in

progress

Page 44: VoIP Fraud Analysis

www.simwood.comwww.simwood.com

SOLUTIONSMONITOR & CONTROL OFF-NET

Page 45: VoIP Fraud Analysis

www.simwood.com

SOLUTIONSMONITOR & CONTROL OFF-NET

Max cost per call

Page 46: VoIP Fraud Analysis

www.simwood.com

SOLUTIONSMONITOR & CONTROL OFF-NET

Custom ACL

Page 47: VoIP Fraud Analysis

www.simwood.com

SOLUTIONSMONITOR & CONTROL OFF-NET

Channel limits Overall, international, per destination number & known-hotspots

Page 48: VoIP Fraud Analysis

www.simwood.com

SOLUTIONSMONITOR & CONTROL OFF-NET

Rate limits Overall, international, per destination number & known-hotspots

Page 49: VoIP Fraud Analysis

www.simwood.com

SOLUTIONSMONITOR & CONTROL OFF-NET

Automated alerts

Page 50: VoIP Fraud Analysis

www.simwood.com

SOLUTIONSMONITOR & CONTROL OFF-NET

API control

Page 51: VoIP Fraud Analysis

www.simwood.com

SOLUTIONSMONITOR & CONTROL OFF-NET

All above features are available through

the Simwood API today

Page 52: VoIP Fraud Analysis

www.simwood.com

DOES IT SCALE?

300,000 operations per

second can’t be wrong!

Page 53: VoIP Fraud Analysis

www.simwood.com

FINAL THOUGHTS

Fraud is the number 1 risk to VoIP businesses.

Page 54: VoIP Fraud Analysis

www.simwood.com

FINAL THOUGHTS

Manage risk not margin. Voice is

becoming a feature not a service.

Page 55: VoIP Fraud Analysis

www.simwood.com

FINAL THOUGHTS

Let a competent carrier take the

strain.

Page 56: VoIP Fraud Analysis

www.simwood.com

KEEP IN TOUCH

http://blog.simwood.com @simwoodesms

Hardcopy in foyer

https://simwood.com/kamailio