SlideShare a Scribd company logo
1 of 56
Download to read offline
Simon Woodhead
Managing Director

simon.woodhead@simwood.com
Simwood eSMS Limited
https://www.simwood.com/

@simwoodesms

Tel: 029 2120 2120
VoIP Fraud
Analysis
www.simwood.com
INTRODUCTION
Wholesale Voice
(and fax!)
!
UK Numbering
Termination
UK PSTN Virtual Interconnect
www.simwood.com
INTRODUCTION
www.simwood.com
INTRODUCTION
https://www.simwood.com
http://blog.simwood.com
www.simwood.com
TOLL FRAUD & DIAL THROUGH FRAUD
$46bn
( but essentially unlimited )
www.simwood.com
TOLL FRAUD & DIAL THROUGH FRAUD
Operator
Carrier
Wholesaler
Reseller
Retailer
Cost
Profit
www.simwood.com
TOLL FRAUD & DIAL THROUGH FRAUD
Loss
Carrier
Wholesaler
Reseller
Retailer
Operator
Cost
Profit
www.simwood.com
TOLL FRAUD & DIAL THROUGH FRAUD
PRS Outpayment
Carrier
Wholesaler
Reseller
Retailer
Operator
Cost
Profit
Outpayment
www.simwood.com
TOLL FRAUD & DIAL THROUGH FRAUD
PRS Outpayment
Loss
Carrier
Wholesaler
Reseller
Retailer
Profit to Fraudster
Operator
Cost
Profit
Outpayment
www.simwood.com
COMMERCIAL PRESSURE
VOICE IS BECOMING A FEATURE, 

RATHER THAN A SERVICE
THE WISE MINIMISE RISK, 

RATHER THAN MAXIMISE THEORETICAL MARGIN
Billed Minute
Revenue
Fraud
Costs
www.simwood.com
SIMWOOD HONEYPOT
60 minutes in the Simwood Darknet on a Sunday afternoon
www.simwood.com
SIMWOOD HONEYPOT
http://mirror.simwood.com/honeypot
www.simwood.com
KEY INTRUSION METHODS
SIP Scan
!
Stage 1:
Reconnaissance
www.simwood.com
KEY INTRUSION METHODS

SIP SCAN
OPTIONS sip:100@XXX.XXX.XXX.XXX SIP/2.0!
Via: SIP/2.0/UDP XXX.XXX.XXX.XXX:5151;branch=z9hG4bK-4181329969;rport!
Content-Length: 0!
From: "sipvicious"<sip:100@1.1.1.1>; tag=6332303064323361313363340132…!
Accept: application/sdp!
User-Agent: friendly-scanner!
To: "sipvicious"<sip:100@1.1.1.1>!
Contact: sip:100@XXX.XXX.XXX.XXX:5151!
CSeq: 1 OPTIONS!
www.simwood.com
KEY INTRUSION METHODS

SIP SCAN
0
450
900
1,350
1,800
2011 2012 2013
Growth in reconnaissance traffic (events by year)
www.simwood.com
KEY INTRUSION METHODS

SIP SCAN
Sources of reconnaissance traffic (12 months)
Other!
165
UK!
56
USA!
529
Germany!
644
www.simwood.com
KEY INTRUSION METHODS

SIP SCAN
SIP Scan
!
Stage 2:
Scan
www.simwood.com
KEY INTRUSION METHODS

SIP SCAN
REGISTER sip:XXX.XXX.XXX.XXX SIP/2.0!
To: <sip:1002@XXX.XXX.XXX.XXX>!
From: <sip:1002@XXX.XXX.XXX.XXX>;tag=ba255b19!
Via: SIP/2.0/UDP XXX.XXX.XXX.XXX:11184;branch=z9hG4bK-d87543-1477;rport!
Call-ID: 8f60483ce717142b!
CSeq: 1 REGISTER!
Contact: <sip:1002@XXX.XXX.XXX.XXX:11184>!
Expires: 3600!
Max-Forwards: 70!
Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, NOTIFY, MESSAGE, SUBSCRIBE…!
User-Agent: eyeBeam release 3006o stamp 17551!
Content-Length: 0!
www.simwood.com
KEY INTRUSION METHODS

SIP SCAN
Growth in scan traffic (events by year)
0
17,500,000
35,000,000
52,500,000
70,000,000
2011 2012 2013
7,206,750
21,855,874
66,991,700
www.simwood.com
KEY INTRUSION METHODS

SIP SCAN
Sources of scan traffic (12 months)
Republic of Korea!
569,708
Thailand!
2,135,810
Anonymous Proxy!
2,453,447
UK!
2,944,596
USA!
6,194,621
Germany!
47,803,899
www.simwood.com
KEY INTRUSION METHODS
Targeted Exploit
www.simwood.com
KEY INTRUSION METHODS
Auto-
provisioning
www.simwood.com
TRAFFIC
INVITE sip:000XXXXXXXXXXXX@XXX.XXX.XXX.XXX SIP/2.0!
To: 000XXXXXXXXXXXX<sip:000XXXXXXXXXXXX@XXX.XXX.XXX.XXX>!
From: 1000<sip:1000@XXX.XXX.XXX.XXX>;tag=1ba25ae7!
Via: SIP/2.0/UDP XXX.XXX.XXX.XXX:5070;branch=z9hG4bK-50489a18;rport!
Call-ID: 50489a186c9c2ff6adacfcc8edb55af1!
CSeq: 1 INVITE!
Contact: <sip:1000@XXX.XXX.XXX.XXX:5070>!
Max-Forwards: 70!
Allow: INVITE, ACK, CANCEL, BYE.!
User-Agent: sipcli/v1.8!
Content-Type: application/sdp!
Content-Length: 281!
!
v=0!
o=sipcli-Session 12278792 2114349621 IN IP4 XXX.XXX.XXX.XXX!
s=sipcli!
c=IN IP4 XXX.XXX.XXX.XXX!
t=0 0!
m=audio 5072 RTP/AVP 0 101!
a=fmtp:101 0-15!
a=rtpmap:0 PCMU/8000!
a=rtpmap:101 telephone-event/8000!
a=sendrecv.
www.simwood.com
TRAFFIC
Growth in call traffic (events by year)
0
17,500
35,000
52,500
70,000
2011 2012 2013
3,035
17,241
63,353
www.simwood.com
TRAFFIC
Sources of call traffic (12 months)
Germany!
2,146Netherlands!
2,739
France!
2,864
UK!
3,193
Europe!
4,213
USA!
12,322
Palestine!
28,795
www.simwood.com
TRAFFIC
Test Traffic
www.simwood.com
TRAFFIC
Location of test numbers (12 months)
Rest of World!
2,140Palestine!
1,341
USA!
2,461
UK!
7,588
Israel!
36,971
www.simwood.com
TRAFFIC
25%
of test traffic from 2 numbers

50%
from the top 10
www.simwood.com
TRAFFIC
Mostly ordinary
‘landline’
numbers
www.simwood.com
TRAFFIC
Absent from
commercial
feeds
www.simwood.com
TRAFFIC
Reminder:
This is Test Traffic
www.simwood.com
TRAFFIC
The visible
attack hasn’t yet
started
www.simwood.com
TRAFFIC
Live DTF Traffic
www.simwood.com
SOLUTIONS
No-Cost
Solutions
www.simwood.com
SOLUTIONS
Bill frequently,
monitor
continuously
www.simwood.com
SOLUTIONS
Buy with
prepayment
( Where they can kill calls in progress when credit exhausted! )
www.simwood.com
SOLUTIONS
Use a carrier with
real-time billing &
CDRs
www.simwood.com
SOLUTIONS
Use honeypot data
http://mirror.simwood.com/honeypot
www.simwood.com
SOLUTIONS
99.79% of 64m intrusions
use the user agent
“friendly-scanner”
www.simwood.com
SOLUTIONS
Use TLS
( Or at least TCP )
www.simwood.com
SOLUTIONS
Avoid auto-
provisioning
( Or at least filter by user agent, rate limit and log! )
www.simwood.com
SOLUTIONS
Monitor & control
off-net
www.simwood.com
SOLUTIONS

MONITOR & CONTROL OFF-NET
Example 1:
Value of calls in
progress
www.simwood.comwww.simwood.com
SOLUTIONS

MONITOR & CONTROL OFF-NET
www.simwood.com
SOLUTIONS

MONITOR & CONTROL OFF-NET
Max cost per call
www.simwood.com
SOLUTIONS

MONITOR & CONTROL OFF-NET
Custom ACL
www.simwood.com
SOLUTIONS

MONITOR & CONTROL OFF-NET
Channel limits
Overall, international, per destination number & known-hotspots
www.simwood.com
SOLUTIONS

MONITOR & CONTROL OFF-NET
Rate limits
Overall, international, per destination number & known-hotspots
www.simwood.com
SOLUTIONS

MONITOR & CONTROL OFF-NET
Automated alerts
www.simwood.com
SOLUTIONS

MONITOR & CONTROL OFF-NET
API control
www.simwood.com
SOLUTIONS

MONITOR & CONTROL OFF-NET
All above features
are available through
the Simwood API 

today
www.simwood.com
DOES IT SCALE?
300,000
operations per
second can’t be
wrong!
www.simwood.com
FINAL THOUGHTS
Fraud is the
number 1 risk to
VoIP businesses.
www.simwood.com
FINAL THOUGHTS
Manage risk not
margin. Voice is
becoming a feature
not a service.
www.simwood.com
FINAL THOUGHTS
Let a competent
carrier take the
strain.
www.simwood.com
KEEP IN TOUCH
http://blog.simwood.com
@simwoodesms

Hardcopy in foyer

https://simwood.com/kamailio

More Related Content

Similar to VoIP Fraud Analysis

VoIP and the Telcos - Is there a life after death?
VoIP and the Telcos - Is there a life after death?VoIP and the Telcos - Is there a life after death?
VoIP and the Telcos - Is there a life after death?
webhostingguy
 
FITSHOW_Future_THINK_BIG_PRES_2017 V5 (002)
FITSHOW_Future_THINK_BIG_PRES_2017 V5 (002)FITSHOW_Future_THINK_BIG_PRES_2017 V5 (002)
FITSHOW_Future_THINK_BIG_PRES_2017 V5 (002)
Matthew Glover
 
My work as a telecommunications headend tech Powerpoint presentation 3
My work as a telecommunications headend tech Powerpoint presentation 3My work as a telecommunications headend tech Powerpoint presentation 3
My work as a telecommunications headend tech Powerpoint presentation 3
Mark Keefer
 
SummitPhoneDS072914HR(1)
SummitPhoneDS072914HR(1)SummitPhoneDS072914HR(1)
SummitPhoneDS072914HR(1)
Robert H. Dow
 

Similar to VoIP Fraud Analysis (20)

VoIP and the Telcos - Is there a life after death?
VoIP and the Telcos - Is there a life after death?VoIP and the Telcos - Is there a life after death?
VoIP and the Telcos - Is there a life after death?
 
Simcon3 2020, Are We There Yet? Alan Quayle
Simcon3 2020, Are We There Yet? Alan QuayleSimcon3 2020, Are We There Yet? Alan Quayle
Simcon3 2020, Are We There Yet? Alan Quayle
 
Smarter SIP Trunks: 6 Ways You Can Save Time and Get More Features
Smarter SIP Trunks: 6 Ways You Can Save Time and Get More FeaturesSmarter SIP Trunks: 6 Ways You Can Save Time and Get More Features
Smarter SIP Trunks: 6 Ways You Can Save Time and Get More Features
 
SIP in action Itexpo West
SIP in action Itexpo WestSIP in action Itexpo West
SIP in action Itexpo West
 
Twilio Signal 2016 Build Your Own Cloud Enterprise VoIP
Twilio Signal 2016 Build Your Own Cloud Enterprise VoIPTwilio Signal 2016 Build Your Own Cloud Enterprise VoIP
Twilio Signal 2016 Build Your Own Cloud Enterprise VoIP
 
Ringtone Sample Agreement Deal
Ringtone Sample Agreement DealRingtone Sample Agreement Deal
Ringtone Sample Agreement Deal
 
Epak - Company presentation 2015
Epak - Company presentation 2015Epak - Company presentation 2015
Epak - Company presentation 2015
 
Wind river
Wind riverWind river
Wind river
 
Intel Satellite Broadband Spain V6
Intel Satellite  Broadband Spain V6Intel Satellite  Broadband Spain V6
Intel Satellite Broadband Spain V6
 
IoT for Smarter Health Care
IoT for Smarter Health CareIoT for Smarter Health Care
IoT for Smarter Health Care
 
Andrew A7PDF-RPC
Andrew A7PDF-RPCAndrew A7PDF-RPC
Andrew A7PDF-RPC
 
Sip Trunking Getting It Right The 1st Time
Sip Trunking   Getting It Right The 1st TimeSip Trunking   Getting It Right The 1st Time
Sip Trunking Getting It Right The 1st Time
 
Andrew E15Z01P19
Andrew E15Z01P19Andrew E15Z01P19
Andrew E15Z01P19
 
Andrew E15Z09P94
Andrew E15Z09P94Andrew E15Z09P94
Andrew E15Z09P94
 
FITSHOW_Future_THINK_BIG_PRES_2017 V5 (002)
FITSHOW_Future_THINK_BIG_PRES_2017 V5 (002)FITSHOW_Future_THINK_BIG_PRES_2017 V5 (002)
FITSHOW_Future_THINK_BIG_PRES_2017 V5 (002)
 
TeleVerus Business Opportunity
TeleVerus Business OpportunityTeleVerus Business Opportunity
TeleVerus Business Opportunity
 
My work as a telecommunications headend tech Powerpoint presentation 3
My work as a telecommunications headend tech Powerpoint presentation 3My work as a telecommunications headend tech Powerpoint presentation 3
My work as a telecommunications headend tech Powerpoint presentation 3
 
VoIP Solutions - Century IT Services
VoIP Solutions - Century IT ServicesVoIP Solutions - Century IT Services
VoIP Solutions - Century IT Services
 
Amiko
AmikoAmiko
Amiko
 
SummitPhoneDS072914HR(1)
SummitPhoneDS072914HR(1)SummitPhoneDS072914HR(1)
SummitPhoneDS072914HR(1)
 

Recently uploaded

Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
Earley Information Science
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
giselly40
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 

Recently uploaded (20)

A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 

VoIP Fraud Analysis