Category: Fraud Management

  • Why Telcos could never overcome Simbox Fraud since a decade Now

    Why Telcos could never overcome Simbox Fraud since a decade Now

    Simbox, Bypass Fraud/ Or Interconnect bypass Fraud has been one of the fastest growing Fraud Types In recent few years.  As per 2017 Global Fraud Loss Survey by CFCA, Global Fraud Loss Estimate stands at $29.2 Billion (USD) annually which is 1.27% of global telecom revenues.

    global bypass

    Source CFCA Survey Results

    Simbox Fraud / Bypass Fraud has been a significant fraud issue for more than a decade now. CFCA survey results across 2009 till 2017 clearly shows an increase of more than 100%  in Bypass fraud since 2013. In this blog, we shall discuss about factors that has contributed to this continuous increase in Bypass Fraud and reasons, operators have not been able to effectively mitigate Bypass Fraud.

    Factors for continuous Increase in Bypass / Simbox Fraud:

    • Reduced barrier for entry

    Buying and operating SIMBoxs has never been easier with online stores, e-commerce websites,courses, forums and instant support availability.  This has led to an increased spread of VOIP based startups and subsequent increase in bypass fraud. VOIP based calling apps have also made customer acquisition easy by making them  easily available on  AppStore for Android & IOS users. For instance, a recent news from India covered the similar trend wherein those who wanted to make international calls from Gulf countries has to download an app called ‘dial to India’ Once this app is downloaded, they get a password for monthly subscriptions. The person sitting abroad will just dial the number in India, the call will bypass the VSNL gate and will directly route through the SIM box and will get connected from there. Read More

    Few more such examples as below:

    Illegal phone exchanges thriving on SIM boxes

    VOIP exchanges used by ISI busted in Andhra Pradesh, India

    • Competitive Landscape

    Reduced margins on international traffic has resulted in wholesale traffic being mixed with internal traffic. Wholesale providers have also been increasingly offering non-CLI based options which could potentially end up in Grey routes. This fierce competition had led to increase in bypass traffic particularly in countries with higher landing costs.

    Reasons Operators have not been able to effectively mitigate Bypass Fraud:

    • Advancement in Sim-server Technology

    Simbox have evolved from being a simple single box setup to a complex modular architecture. This architecture allows fraudsters to maintain all the simcards in a single place and using Antenna modules and multiplexers, fraudsters are able to distribute their operations in the market. In fact, Latest Simservers also comes with inbuilt anti-fraud detection solutions allowing fraudsters to  distribute his operations in multiple locations. This makes fraud detection very complex as fraud management teams have to device multiple strategies to beat fraudsters at their game.

    • Regulatory Changes

    Regulatory changes in certain markets have fueled increase in traffic for Bypass. Recent changes of regulations in European Union has also resulted in traffic with E.U been heavily being differentiated in price from traffic outside E.U thereby causing significant increase in Bypass traffic.

    • Raising Concerns in Simcard Sales

    Increased pressure to maintain sales and activation of new connections have resulted in dealers colluding with Bypass fraudsters. Bypass operations requires lot of sims to be activated in bulk and lack of effective subscriber acquisition controls have led to fraudsters taking advantage of it.

    Fraud Management teams further have an uphill task in the Bypass fraud space as new technologies such as virtual sim’s would only increase the impacts on bypass of international traffic. It is hence important that they adopt a comprehensive fraud detection methodology to fight simbox frauds.

  • Device Journey Management: the next frontier for Device Assurance

    Device Journey Management: the next frontier for Device Assurance

    In recent years operators have scaled their thinking into hundreds of millions – but not in terms of data volumes, but instead in the numbers of devices now utilizing their networks.  Smart handsets have led the charge of devices, followed (and soon to be surpassed) by IoT devices, and an army of small cells that will serve to densify the upcoming 5G network rollouts around the world.

    Why are these devices capturing more and more operator attention?  With over 1.5 billion smart phones shipped from manufacturers in 2017, the amount of investment by telecom operators just in this device category alone amounts to approximately 20% of their overall operational budget.  However, each year tens of millions of dollars of this opex are being written off as losses by operators due to issues with logistics (forward and reverse), fraud, and process misalignments; device journey oversight doesn’t exist as a discipline today.

    Subex has invested almost two years researching this domain, including talking with operators of all sizes around the world.  What we have found is an expanding set of exploitable gaps that current systems and practices are incapable of closing.  Points of risk exist across internal processes, channel partners, distribution and supply chain, and various other areas leading to (and sometimes even originating from) the end consumers.  These risk points accumulate losses for operators that range between $500K USD to over $10M USD per month, per operator, depending on size of the operator.

    The device growth area today is not only in smart handsets, but also in a wide array of small cells, sensors, and various other categories.  With already significant gaps existing in oversight, this new breed of devices puts an even greater risk on operating budgets.  Under current estimates, deployed IoT devices alone in the next 5 years will exceed 200 billion units, dwarfing the handset counts worldwide.  Can losses be sustained, or even ignored, at these levels?

    Subex will be speaking about a comprehensive strategy and methodology for Device Journey Management during a presentation at the CFCA Winter Conference in Las Vegas on February 6th, 2018.  We will also be at the Mobile World Congress in Barcelona later in February where we look forward to speaking with operators encountering the same problems.

  • Key is to ask the ‘right questions’

    Key is to ask the ‘right questions’

    “In school, we’re rewarded for having the answer, not for asking a good question”

    This quote from Richard Saul Wurman rightly describes how a normal human mind, as part of it’s social development process, adapts to the guidelines of “finding the answers”, rather than exploring the possibilities of asking the “right questions”.

    And this mindset also reflects in our place of work. We are humanly tailored to explore satisfaction in having answers to all the questions. And in the process of being ‘answer ready’, we tend to become left brain heavy than the right. We become target driven and focus less and less on fresh set of questions which could challenge us further to drive improvement and innovation.

    Fraud Management ‘function’ is no different. Being a ‘revenue protection’ function in a large ‘organization’ it is expected to act similar to a small, but important organ in human body.
    Like hormone levels of an organ, health of an FM function is also measured in terms of subjective financial targets – either monthly, quarterly or yearly. And the corrective action starts when the achievements are found to be ‘less than optimum’.

    But, as an experienced doctor would say – It’s the lifestyle you need to keep in check and not hormone levels to remain healthy!
    Constant self-assessing questions such as – “Am I eating right ?”, “Am I sleeping right ?”, “Am I sitting right ?”, “Am I exercising right ?” etc. go a long way in guaranteeing you a healthy life. Periodic check-ups then becomes a method to confirm your good health rather than just means to detect illness or deficiencies.

    Keeping healthy is a continuous process – be it human body or fraud management. It is actually a practice, than just a function.
    And to setup a continuously improving fraud practice in your organization it is essential to keep asking relevant & timely questions across the following 8 pillars of this practice:

    • Influence
    • Organization
    • People
    • Process
    • Tools
    • Knowledge Management
    • Coverage
    • Continuous Improvement

    While the questions could be an organization, risk or region specific, I personally always start with the following:

    Influence:

    • Is our FM function on a driver seat or secondary role and working as a support function ?
    • How should we enhance the influence of our FM function ?
    • How do we keep showcasing enhanced value from FM function ?
    • How do we extend our internal & external interfacing and make the existing interfacing stronger ?

    Organization:

    • How do we ensure fraud awareness keeps pace with the upgrading business dynamics ?
    • How do we enhance internal & external collaboration with FM function ?
    • How do we get higher return of investment from FM function ?
    • How to further reduce the fraud impact on the bottom line ?
    • How to make our fraud management practice more proactive ?

    People:

    • Is resource acquisition better or resource development ?
    • How do we safeguard ourselves from attrition ?
    • Is our team structure agile enough while following industry standards ?
    • Do we have all the required roles and are the responsibilities clearly defined ?
    • Are we right, under or over staffed ?

    Process:

    • Are my processes effective and easily exercisable ?
    • Are my processes future ready ?
    • Are my processes agile enough to adapt to any changes with acceptable TAT ?
    • Are we adopting and implementing industry best practices ?
    • What parts of my processes can be automated ?

    Tools:

    • Is the Fraud Management tool adapted to my business environment ?
    • How do I ensure that the FM tool is fed accurate, complete and timely data ?
    • Are my fraud controls effective & efficient ? How do I reduce false positives ?
    • How do I ensure 100% automated fraud risk coverage ?
    • What capabilities do we need to acquire on tool front to be future ready ?
    • Are we ready against enormous data surge likely to be seen over next few years ? How do we benefit from it ?
    • Are we constantly learning from the industry in terms of fraud detection & prevention methods ?

    Knowledge Management:

    • Is there sufficient attention on upgrading to the required skill sets ?
    • How do we enhance resource competency & knowledge against current & future services ?
    • Is our team keeping pace with constant fraud mutations ?
    • Is our team using the tools effectively & efficiently ?
    • Is our team knowledgeable and comfortable with processes ?
    • What are the top 5 areas of learning for the whole fraud function ?

    Coverage:

    • Are we aware of all the fraud risks we are exposed to ? What is our current coverage levels ?
    • Do we know the gaps in terms of fraud risks coverage ? How can we improve ?
    • What is our strategy to become compliant to fraud risks introduced by new products and services ?
    • Are we ready for fast converging cross industry environment and the risks it introduces ?
    • What is our stand on customer and partner only risks ? How relevant they are for our business ? Is our current stand obsolete ?

    Continuous Improvement:

    • What is our performance management strategy ?
    • Do we have effective KPIs ? Are these business relevant ?
    • How can we improve the fraud function’s effectiveness & maturity continuously ?
    • What metrics should I use to measure health of the overall FM function ?
    • Are we conducting sufficient & periodic RCA & decision analysis ?
    • How do we gather accumulated wisdom & actionable intelligence for improvement ?

    Each of these questions can be a healthy point of discussion within your organization.
    While these may give you a first hand view of health of your current fraud practice, more importantly, it may also open doors for a much detailed open table introspective sessions, enabling you to come up with much better & effective questions.

    Remember, the key to remain healthy is to keep asking the ‘right’ questions.

    As Albert Einstein rightly said – “If I had an hour to solve a problem and my life depended on the solution, I would spend the first 55 minutes determining the proper question to ask, for once I know the proper question, I could solve the problem in less than five minutes.”

  • The threat of Signaling!

    The threat of Signaling!

    Signaling level risks, specially fraudulent accesses from connected SS7 networks, is one area which is making a lot of noise in the assurance and security functions of Telecom organizations today.
    The focus on the matter is such that most of the industry conferences talking about the current and next gen threats have a lot of matter being presented and shared on this topic – both from the operators and vendors alike.

    What is it ?
    The signaling level risks generally refer to SS7 (2G/3G) and Diameter (4G) level vulnerabilities (inherent or configuration based) which exposes operators to hacks/frauds through signaling control commands specially in roaming and interconnect scenarios. The scenario becomes more risky considering a normally configured SS7 infrastructure of an operator is accessible to any other operator in this world, either directly or through certain number of hops.
    Now, just consider a situation where a rogue operator exists or a group of hackers with a malicious intent have got access to SS7 signaling of any less-secure operator in this world.
    The losses due to signaling risks, while are still quite speculative, are expected to run in billions every year. Artificial inflation of traffic (specially A2P & P2A SMSes), Spamming, Spoofing, Refiling, profile modification, unlawful tracking, unethical disruptive activities from competition etc. are examples of some risks which have been found to be existing NOW with an estimated 100% infection rate.

    Why is it happening ?
    The SS7 signaling based vulnerabilities have been existing since very long, but have become part of news headlines recently due to certain revelations made by famous ethical hackers at certain high profile security conferences.
    Some industry pundits make a point, which most of my industry connections agree with, is that these risks exist mostly due to the fact that operators tend to create unreliable partnerships and configure unregulated access (like open GT access, acceptance of any signaling command etc.) which enables malicious parties to connect to operators networks and conduct fraudulent activities very easily.
    There have also been discussions around existence of services exploiting these signaling level vulnerabilities being offered in the grey markets through rougue hacking communities for a price.

    Can you eradicate these risks ?
    Ideal Solution: Operators need to sanitize their access configuration on SS7. Rethink, Reidentify, Reevaluate and Reconfigure the access levels.
    But this is really difficult or maybe nearly impossible to achieve due to some practical issues on the ground, such as:

    • Most of the SS7 networks were configured long time back – There is an expertise issue operators are facing wrt SS7 networks now which limits their capability in terms of reconfiguration of SS7 based networks
    • It is a time consuming activity, which, would also lead to a lot of efforts on re-testing connectivity with all the partners, attracting a lot of investment
    • It may lead to reconfiguration of the signaling level configuration at the network level, and in certain instances, would require network downtime – A complete NO-NO for a lot of players out there. Situation becomes even more problematic for countries where Telecom Networks are considered a National Infrastructure.
    • Lastly, not every operator will take up this activity for many different reasons including the reasons like operators not participating in the awareness meetings/conferences being organized around the world or even like some rogue operators participating in malicious activities deliberately.

    The problem becomes much more trickier from the fact that even one infected, unsecure or rogue operator in the world will continue to pose a threat to everyone else. And sanitizing each operator against these threats is a feat which is very unlikely to be achieved.

    It is now unanimously being accepted that SS7 signal based networks are here to stay (atleast 10 years in developed markets and 20-25 in developing or lesser developed countries) and even their vulnerabilities, which are expected to grow by huge amounts considering the limelight it has received recently.

    The bigger problem which has started giving sleepless nights to the fraud & security functions in operators moving towards 4G and setting up their networks over diameter protocol (provides 4G signaling framework) does not have native security standards inbuilt, but requires security mechanisms to be implemented on top, a practice always found susceptible to gaps). Also, the access methods are similar to SS7, so it exposes 4G networks to similar signaling risks as SS7.

    What can be done now ?
    For now, an approach of detection would be ideal until the industry identifies a way to plug these vulnerabilities around the world, which is definitely a few years away with a lot of research hours of investment.
    An approach of detecting malicious signaling requests in your network still has few complexities to manage:

    • High false positive rates – A lot of signaling requests appearing to be malicious come out as configuration issues from the partners. Hence, domain expertise is essential to filter out ‘needle from the haystack’.
    • Sheer size of signaling data to be analyzed – big data support is required.
    • Skill set – This activity will surely require a knowledge upscaling and may be difficult for the traditional teams like fraud and risk management to absorb. Even teams like security, with less focus on fraud domain know how, is expected to find it difficult to add this activity in their set of responsibilities.

    I feel industry partnerships with vendors, possessing both the domain knowledge, right skill set and technology built on big data platform is the way to go.

    These partnerships, considering no-one has a complete answer to this rampant problem of signaling vulnerabilities as of now, need to be built on solid vendor capabilities, while being both liberal and experimental to give room for exploration.

  • The Re-Emergence of Convergence

    The Re-Emergence of Convergence

    Operators and global industry forums continue to wrestle with the question of whether or not to merge their fraud and security teams/work-groups to cope better with criminals who are breaking in through IP-based networks in order to derive profit for themselves (or their causes), or just to wreak havoc and disruption on their “enemies”.  Fraudsters are not just partaking in the traditional crimes of bypass fraud, roaming, Dial Through, AIT/PRS, Call Selling fraud etc., but also the exciting new stuff…. Phishing, malware, spoofing, DDoS, Trojans etc.

    One can be forgiven for thinking that fostering closer links between fraud and security domains is breaking new ground in terms of responding to the threats posed by 4G/LTE, NextGen, the continued growth of e/m-commerce and the proliferation of data passing over networks.   I guess it is a sign of my advancing years that I can’t help feeling that we have been here before…

    15 years ago, when I was prepping for an interview for my first job in the fraud management arena, I was listening open-mouthed as a fraud expert was explaining to me the finer points of PBX Hacking.  Thinking back, two things were very clear:-

    1. The Operator in the UK already had a merged fraud and security group (which they later separated out, then subsequently re-merged again, by the way).
    2. The main advice to combat PBX Hacking was prevention, not detection… and that meant security prevention. The operator was keen to tell its business customers that they needed to physically lock away their PBX equipment, protect their passwords, switch off unnecessary/vulnerable services such as DISA/Voicemail, carry out security awareness training for switchboard operators, support staff, suppliers, use barring at switch or extension level, keep PBX call logging records to see hacking attempts before they succeed, shred old copies of internal directories, vet their security/cleaning staff, etc. etc.   The FMS only stepped in when all the prevention activities failed and the PBX was breached.  By the time that happened, operators were already losing money directly, if they were responsible for the switch, or indirectly if their customers were liable.  Customers may have been unwittingly facilitating the fraud by their lack of security awareness etc. but even so, if a small business – used to paying perhaps $1000 a month for calls, suddenly gets a bill for $20000, they are going to fight it, refuse to pay it or be unable to pay it.  The indirect cost to the operator of customer complaints, disputes, potential court cases, damage to the brand, bad publicity, negotiated settlements, debt write-off and churn etc. can cost far more than the original bill.  It was a lose/lose situation… unless you were the fraudster.

    These days, with the emergence of 4G/LTE, IP-based Networks, perpetrators are still committing the same underlying crime for the same motives as before, but now they are breaking in through a host of different entry points, wearing better disguises, carrying bigger SWAG bags and using faster getaway vehicles.  In truth, many operators are struggling to keep up with the high number and seemingly unpredictable nature of these attacks.

    Security teams are traditionally very good at preventing access to networks, but they are not perfect.  The pace at which network elements, components, interfaces and transactions are increasing is making it impossible for all the preventative measures to be in-situ from day one.  Not to mention the surfeit of off-the shelf tools that fraudsters can use to break in to more and more lucrative areas of daily commerce.

    In practice, Prevention alone cannot succeed.  Detection, Analysis and Response are also essential elements of the fraud management cycle.

    Cycle

    So, my point is this…. security and fraud teams cannot operate in silos.  Security teams must continue to try and prevent malicious intrusion as much as possible.  That requires taking in a lot of real-time data from the access points, identifying the nature of the content and the data patterns and quickly blocking anything that looks dubious.  But when the intruder gets in (and they do in their numbers), that is when the fraud team can also play their part.

    Whilst the security team controls corporate IT networks, how well can they police the mobile workers and the homeworkers, the tablet users, the App Store/Android Users etc.?  And if you think that profiling subscribers was difficult historically, how much harder is it when you can’t even define what a subscriber is, let alone track their behaviour.  In the new world, the relationship between account holder, subscriber and product/service is not always obvious.  Also, the billing relationships for transactions can be mind-boggling.  Couple this with the speed at which these transactions are taking place and the value of services and content being passed across a proliferation of bearers, and you have a minefield to negotiate.

    This is where a good Fraud Management System can supplement an operator’s security tools.  An FMS must now be equipped to take in much larger volumes of data than before, in many different forms and process it much quicker.   Any reputable FMS vendor will now be offering solutions with large scale, flexible data handling tools (including probe / deep packet inspection events), internal/sales partner audit logs/feeds, inline service/transaction monitoring, exhaustive rules engines (real-time, in-line and statistical), subscriber grouping & profiling features, reference data including Hotlists/Blacklists, fraud and device “fingerprinting” capabilities, ID verification, alarm prioritisation and established, flexible workflows, with a range of analytics tools and visualisation features.  All these components – in the hands of an experienced and well-managed fraud operations outfit – will help to choke fraudsters and drive them out to look for easier targets.

    So, in summary, don’t let the security guys take all the strain at the prevention stage.  Share the data, share the knowledge and spread the load to the fraud team for a more comprehensive response.

    To get more information about Subex Fraud products please click here.

  • Factors Complicating Assurance in 4G Environments

    Factors Complicating Assurance in 4G Environments

    GSMA has a vision for 2020 for Telecommunications Industry around connected living which focuses on main pillars which are expected to drive the industry forward, namely – Network 2020, Personal Data, Internet of Things and Digital Commerce.

    As per my view, the single most important take away from that vision is the rise of Telco 2.0.

    Telco 2.0 are those telecom operators which are expected to expand transformationally by taking risks to chase higher rewards in both known and as yet unknown new parts of the value chain. These are expected to be the most advanced & disruptive Telecom Operators.

    Telco-2.0

    The most important enabler of these, so called, Telco 2.0 operators would be the ‘platform’ which would allow them to explore & experiment with those unknowns and expand services while ensuring higher customer experience which will help them achieve that visionary status.

    One of such platforms is 4G, which riding on the inability of 3G-3.5G networks in delivering the required quality of service, has shown tremendous adoption rate within operators over the years.

    What has made 4G enabled networks so popular is its proven capability as an ideal platform for cross domain services convergence & all access technologies.

    A comparison between 4G LTE & HSPA (~3G) based network and service delivery capabilities can be seen below:

    consumer-content

    The bitmap above also provides a crude reasoning around lower adoption rate of certain services which were also rolled out over 3G enabled networks, but did not meet the consumer expectations around quality, reliability and price.

    4G based networks provide the ability to the operators to become the ‘Real’ converged service providers, which until 3G was more theory than practicality. Operators are now becoming OTT service providers including communication, social media, social network, content, advertisement etc., connected living enablers, enterprise enablers etc. which was, until now, being offered mostly by 3rd parties.

    With operator owning the converged service offerings (or at-least controlling some part of the service delivery like quality etc.), the increase in traffic over its pipes has shown potential of increase in direct revenues, that too proportionately.

    Factors influencing complexity in 4G environment

    Yes. 4G is great! But, not without the share of complexities it injects in the area of assurance (RA & Fraud) operations.

    The following variables are identified to be the main influencers with respect to complexity and uncertainty in 4G environments:

    New Network Elements

    4G introduces new set of network elements and O/BSS systems generally being customized in terms of design or implementation as per the operator raising concerns around interfacing, data availability or quality. This also points to increase in complexity & volume of RA & FM activities to be performed due to increased data sources and controls.

    Also, a lot of components in 4G implementations are still not COTS and provide different logging & access levels which raising concerns around capability around identification of internal frauds and external access attempts/brute force attacks.

    Parallel Networks

    Traditional networks including certain components adopted from 2G, 3G environment and running in parallel to enable backward compatibility and interconnection leads to further increase in risk, complexity and number of controls to be managed.

    Non Standard Implementations

    Some areas of 4G network, O/BSS systems and interface partnerships (operator, content providers etc.) are being implemented in customized non-standard fashion to enable interconnections (including roaming approach) and support complex products and service offerings (like VoLTE or VoLTE roaming etc.). The situation is more of an experiment and working towards developing a standard rather than following one.

    Lack of reference 4G RA & FM practices combined with custom implementations, RA & FM activities are expected to be driven by non standard data sets and frequencies until stability/maturity.

    Initially in 4G space, RA & FM practices may be exposed to the scenario of ‘Incident induced learning’ or ‘reactive RA & FM’.

    Higher Convergence

    Higher convergence of ‘core’ telecom operator provided services introduces more ‘direct’ risks to the operator and an increased need to manage RA & fraud risks introduced by the new services, which in an earlier setting, was a headache of the third party service provider.

    New Pricing Models

    Conversion to charging policies from minutes to bytes (sessions) and bytes to service subscription & access mixed with complex bundling packs & rate plans is expected to change the traditional mindset of conducting RA & FM, especially around charging, discounting, billing & invoicing.

    Disruptive roaming charging policies are also expected to be introduced which will change the perspective further.

    For session based charging policy, verification of policy implementation is also expected to impose its own set of challenges.

    Complex service offerings

    Telecom operators are going beyond their traditional service offerings (Apart from voice and data – TV / content / cloud etc.) and venturing into the modern areas revenue generation such as content, advertisements, connected living etc.

    Rich content (VoD, music, messgaging, magazines etc.) management & delivery to become the fulcrum 4G revenues. Also, with various channels of content delivery at hand, advertisement revenues will also play an important role for mature 4G operators

    But, service based subscriptions, validity & dynamic delivery along with innovative & complex content and partner agreements are expected to complicate the RA & FM activities like never before.

    Increase in transaction volumes

    4G subscriptions is expected to increase 3.5 folds to 1.3 billion and data traffic by 6 folds to 17 Exabytes by Dec 2018. Operators will be dealing with many fold increase in data per unit of earned Revenue.

    Considering revenues are tied to data sessions, transaction volume mgmt. for the purpose of RA & FM is expected to introduce a big challenges and would require advance data treatment, management & analysis techniques (e.g. Big data).

    Responsiveness & Scalability is expected to be one of the main talking points with respect to volume management

    Rapid Product & Services Launch

    New product, package and service launch across the breath of 4G enabled service platforms are expected to see a considerable rise in throughput due to shortened development, delivery & release cycle.

    The agility of RA & FM departments in terms of proactive assessment and risk readiness is expected to keep pace with the higher number of products, services and packages being launched at the breakneck speed across the breath of business offerings

    Margin Management & Revenue Enhancement

    With increased competition, Revenues are expected to be driven by high volumes and low margins and not high margins. Product performance measurement in terms of adoption and revenue generation against target will have to be carried out at much higher frequency.

    With RA having and access to all cost items, charging, payins/payouts, usage records, quality parameters and first visibility to trends and anomalies, margin management and revenue enhancement activities are expected to take center stage

    Skill set and technology within the team will have to be enhanced or absorbed to enable and handle increased cross functional interfacing , analytics and product management

    Lack of Skill Set

    Lack of mature reference 4G implementations is also expected to lead to lack of required skill set which is needed to manage and continuously improve the RA & FM operations. There will be focus on more laborious, reactive & risk prone approach of skill ‘creation’ rather than ‘absorption’

    Updated Network Access Authentication Methods

    Operators need risk readiness against newer authentication methods which are different for different services – ISIM, USIM, Single Sign On etc. Considering device authentication & security is in the hands of the manufacturer or the OS provider,  any security flaw is a direct risk to the subscriber base of the operator

    Also, 3rd party firmwares & apps are readily available for the assistance of hackers. This situation increases the device or OS takeover further.

    Increased UE & CPE Types

    Exponential increase in multi vendor UE & CPE types has increased user exposure to IP frauds like takeovers (Accounts or UE) enhanced by ‘easy’ service access methods such as ‘single sign on’ for single or multiple services.

    While user equipments are highly exposed to malicious Apps, URLs, Malwares etc., readily available custom firmware for Customer Premise Equipment are found to expose them to the same level of risks.

    To top it off, high profile sensitive customer information hacking cases by external sources are on the rise both against individual subscriber and enterprise networks, calling for much more robust, secure and continuously improving infrastructure and detection capabilities.

    Power user exploits

    Power users or technology aware users are expected to exploit any loopholes in the implementation of service access, newer pricing models etc. through the use of various complex techniques such as URL masking etc. to bypass charging and gain free access to services

    Spoofing or device configuration updates like MAC Address may also gain popularity to help divert charging to someone else in absence of adequate authentication and multi level device binding mechanisms

     

    Movement to 4G or a higher capability environment is inevitable.

    I believe, if traditional approach to manage RA & FM operations is continued as it is even for 4G environments, these functions are expected to attract steep investments to manage complexity factors mentioned above (including increase in network elements & O/BSS systems, data streams, data loads, controls, resourcing, technology requirements etc.).

    There is an immediate need of shifting from current mindset and adopting “Smart” & “Agile” RA & FM practices across the operational spectrum (of people, process, measurement, organization & technology) to contain costs and risks much more efficiently.

    Taking a cue from Game of Thrones – “Winter is coming! and this one will be long. God help us all if we’re not ready!”

  • Intelligent Alarm Qualification in a Fraud Management System

    Intelligent Alarm Qualification in a Fraud Management System

    Most leading rule-based Fraud Management Systems are based on a relatively simple process…. When an event (or series of events) occurs, the record associated with the event is processed in the FMS.  If the event breaks a rule in the FMS – perhaps because it is unusual for the customer, unusually long duration, unusually expensive or is one of a very high number of calls – an alarm is fired and that alarm is sent to the alarm page so that the fraud analyst can see it in their workstack and hopefully take prompt action to deal with the case.

    The reality of course is that, in many instances, the alarm is competing with perhaps hundreds or thousands of other alarms for the attention of the analyst.  So, which is the most important alarm in the stack?  Well, as we know, most FMS systems will have a scoring system so that the alarms with the highest score will appear at the top of the stack.

    Typically, when rules are built, they are given a score which reflects their “potential” severity, relative to other alarms.  Weird and wonderful algorithms are then used in the background to build a consolidated score for an alarm based on a combination of these various scores for each rule breach, bearing in mind that alarms usually comprise a combination of several rule breaches.

    So a $50 call to an Adult entertainment line may have breached all of the following rules, each having a score associated with that breach:-

    • High Value Call to a Premium Rate Service
    • Long Duration Call to a Premium Rate Service
    • High Value Call to ANY number
    • Out of Hours Call

    On the face of it, this seems a sensible solution.  However, there are three flaws with this methodology:-

    1. The scoring provided for a rule breach (alert) is arbitrarily/subjectively assigned at the time the rule is written
    2. Once the score is associated with the rule, it is unlikely it will be changed until a thorough rules review is conducted, which could be months/years later
    3. No consideration is given to the “actual” ruling that was subsequently assigned to the alarm.

    But what if the score could change dynamically based on the history of ACTUAL rulings made by analysts, rather than remaining static, based on the POTENTIAL severity of the situation.

    So, for example, if a particular set of rule breaches appear to be high risk but actually rarely result in a fraud, then surely over time, the score associated with that “event” should reduce.  Likewise, if a low score alarm always results in a fraud ruling, the score should automatically be enhanced the next time the system sees the same, or similar, behaviours.

    In other words, the system learns from experience over time.  The more alarms that analysts rule correctly, the more accurately the score reflects the likelihood of that alarm being fraudulent or not.  It won’t reduce the number of false alarms, but it will ensure that the alarms most likely to be fraudulent will appear at the top of the list and be dealt with quicker than those that are known to be less risky…. And that means losses due to fraud are reduced.

    Subex has been running this system for several years now.  It is known as Intelligent Alarm Qualification (IAQ) and – wherever it is deployed – the results have been excellent.  We have a benchmark which follows the Pareto Principle (the 80:20 Rule).  This means that customers who let IAQ score the alarms should find 80% of their fraud in the top 20% of their alarm stack.  The results in 95% of cases achieve this benchmark – and in the vast majority of cases, exceed it.

    Of course, it relies on the fact that analysts do rule alarms as FRAUD or NOT FRAUD regularly, and it also assumes that such rulings are usually correct.  But as long as that is happening, as it is in most operations, then it is Happy Days!

    To get more information about IAQ or to find out more about Subex Fraud products please click here.

  • There’s No Business Like “Know” Business!!

    There’s No Business Like “Know” Business!!

    People of a certain “vintage” will remember well the speech by former US Secretary of Defence, Donald Rumsfeld when questioned on the lack of evidence linking the Iraqi government with the supply of chemical weapons to terrorists. For many of us it took a second hearing to fully appreciate the difference between our “known knowns” and our “known unknowns”, and if you are anything like me then the concept of ‘unknown unknowns’ – well that took a little bit longer!

    The speech has been the source of much discussion through the years and the basic principle has been applied to many situations and domains, including Fraud Management.  However, one of the most interesting parts of the speech has largely been overlooked in all of the focus on the “knowns” and “unknowns”. In responding to the question Rumsfeld’s first sentence was;
    “Reports that say that something hasn’t happened are always interesting to me”.

    Fraud management, as with most other operational functions, is largely focused on something happening, whether that is in relation to configuring rules in the Fraud Management System or in working out the effectiveness of your business function (people &  process). The emergence of certain fraud types through the years has started us on the track of reaping the benefits from looking at things that have not happened as a detection method but for many organizations the principle has not been fully embraced.

    Most organizations are now looking into more detailed analytics, but within these analytics programs, how much emphasis is put on things that didn’t happen?  Additionally, in a dynamic environment such as Telecoms Fraud Management even what we “think” we know (“known knowns”) may be rapidly out-dated or superseded.

    In the “Big Data” era things are likely to be even more challenging for Fraud Professionals as the haystack just got a lot bigger, so even trying to keep on top of what we think we know is going to be a challenge. To start trying to uncover our “Known Unknowns” and “Unknown unknowns”,  – that will take INSIGHT.

    To get more information about Subex Insight please click here.

  • Hindsight – the Superpower everybody possesses?

    Hindsight – the Superpower everybody possesses?

    As a child, I dreamed of having a superpower. Invisibility, flying, incredible strength, teleporting – any would have been just fine, I wasn’t choosy! Unfortunately it didn’t take too long for me to realise I was not ‘on the list’ so I went to work for BT instead and started on the road to a career in Fraud Management!

    Over 25 years later it suddenly became clear to me, as I watched events unfold in Brazil over the last two weeks, that I may have been wrong all along.  In fact I DID have a superpower. I was, in fact, “Hindsight Man”! Unfortunately my hindsight powers did seem to have limitations in that they only worked in connection with the performance of the England Football (Soccer) team – but you have to start somewhere! However, once I realised I may possess this power I quickly noticed that nearly everyone else I came into contact with also seemed to be blessed with this ability – and it is always completely accurate (20:20), right? A pretty useful Superpower for a fraud professional then!

    Before investing in the cape and mask, I decided to do some further research on the subject of Hindsight.  So, what is hindsight?  It is defined as ‘the ability to understand, after something has happened, what should have been done or what caused the event’. As I delved deeper, I realised that I, as with many others, am most likely suffering from something psychologists call Hindsight Bias…. also known as the ‘Knew-it-all-along effect’.

    It appears we humans have a tendency to suggest predictability even in events where there is little or no evidence to support the prediction prior to the event. Unfortunately, it gets worse….even where some evidence may be present in order to validate our ‘Hindsight’ we may change our recollections to support newly provided information. The level of memory distortion this involves is not just affected by whether there is a positive or negative outcome, but also the severity of the negative outcome. Dangerous Stuff!

    So it looks like I may not possess the power of hindsight after all and looking at it from a Fraud Management perspective that may be a good thing. Hindsight, as we have seen, can be based on no factual evidence and, even where there is some basis in fact, is prone to a significant number of external factors that can have a hugely negative impact on our assessment/judgement.

    No, it’s clear to me now, to be a better fraud professional I don’t need Hindsight – I need Insight!

    Read about Subex Insight here.

  • Diamond is the New Triangle

    Diamond is the New Triangle

    More money has been stolen at the tip of a pen than at point of a gun. It is the people behind the pen who committed the fraud than the pen itself. Hence for those who are fighting fraud, it is worth spending time in understanding why people are committing it.

    Everyone who has exposure to fraud is very well aware of the Cressey’s hypothesis on why people commit fraud – Perceived opportunity, Pressure and Rationalization. These three attributes over the years make up what is widely known as Fraud Triangle.

    However; critics have often cited that fraud triangle, being from fraudster’s perspective, has defined two attributes (pressure and rationalization) that are generally non observable. Thus it fails to explain why fraud was committed when perpetrator have traits of pathological fraudsters. This shortcoming can be overcome by taking fraudsters assessment of capability in to account. Not only does the fraudster have environmental or situational factors for committing fraud but also they must have the necessary abilities and traits to recognize and make it a reality. Everyone may not have this capability in a given situation. Many of the traits that make an individual capable of committing fraud can be derived from the individual’s personality itself.

    The personality traits that makes a personal capable of committing fraud can be attributed to his position or function in the organization, his level of intelligence, his arrogance, persuasive & deceptive nature, and Immunity to stress.  The fraudster’s specific position or function within the organization along with his ability to recognize and exploit the weakness of internal controls allows him to visualize opportunities that are otherwise unnoticed. The fraudster’s egoistic nature often makes him believe that he is beyond the surveillance of checks and balances. The fraudster often will be able to persuade others to commit fraud or at bare minimum to turn a blind-eye. The fraudster will be good in concealing his inner stress and often lie convincingly in order to maintain a consistent story.

    Thus capability provides with more measurable traits for detecting possible frauds. Therefore it is important that assessing capability and addressing them at early stage are made as part of the fraud fighting charter for organizations.