Blog

  • Capex Optimization:  A strategy for growth, or defense?

    Capex Optimization: A strategy for growth, or defense?

    The battle is heating up and speeding up in virtually every market. Customers want the newest, latest, greatest handsets, products, and services.  But how long has this battle been heating up, really?  The answer is simple:  Since the 1980’s.  All that has continued to change are the tools used by the operators in the battle.  Let’s examine the latest tools being used in the Americas and understand how that impacts Capex.  The results may be surprising:

    In what is arguably the start of the latest rounds of “artillery”, T-Mobile launched free roaming to over 100 countries in 2013, and started attracting customers by the millions away from the likes of AT&T and Verizon.  After the immediate dust settled and the program was seen to actually be viable, AT&T responded with paying the early termination fees for converting subscribers from T-Mobile.  In the process, flat rate plans with expanded data benefited all of us, as T-Mobile and AT&T both offered non-contract based data allotment increases, for no cost (and in many cases, lower costs) to existing subscribers, to shore up their retention numbers.

    Verizon has taken a more conservative approach, saying they have the largest 4G network, which has caused AT&T to counter with having the fastest 4G network.  Not to be left behind, T-Mobile responded with offering to roll over unused data, and to unleash attractive unlimited plans via their recently acquired MetroPCS brand.

    All the while, Sprint, the last major national carrier in the mix, has been losing market share while “sprinting” to greatly expand their 4G network.  In the recent weeks they have jumped into the market with a very viable message, aimed directly at AT&T and Verizon, to cut subscriber bills in half…literally.  They even took out an ad in the most expensive slot in the world:  The American Super Bowl.  This ad was designed to “apologize” to AT&T and Verizon.

    And now the latest, and perhaps most interesting move, has been the international expansion of some operators into Latin American markets.  The model is simple:  Buy a Latin operator network.  Re-brand it to your internationally known name.  Offer local services that extend all the way into North America.  No roaming or interconnect, and all local calling.  This is a major threat to long-time incumbents in the Latin market, and it’s already happening. Three years ago I was asked what I thought the impact of 4G/LTE would be to the markets.  I made a quite possibly crazy prediction that 4G was going to upset the way we understand roaming and interconnect, simply due to the fact that data, VoIP, and the new products that were going to ride on femtocells and wifi / wimax were going to totally change the playing field.  Could it be that something similar is gathering momentum today?

    What is the common thread in all of these battles in the Americas market(s)?  Quite simply, the operator revenues are not growing, or are not growing at the pace to keep up with Capex spend.  Networks are being extended and evolved not to add revenue, but instead to sustain revenue.  Here’s an example:  In the last 24 months I have moved my entire family to 4G.  My bill decreased.  More data was added to my plan.  My bill again decreased.  I then expanded my home DSL to a 30x increase in speed.  My bill stayed flat.  All of this involved more network capacity and expansion in products and services.  But I was not further monetized…I was just retained.

    Capex optimization, if pursued for growth, could be considered a great goal and something to strive toward.  However, if Capex optimization is pursued to simply maintain your revenues (and market share), this should no longer be considered a goal, but instead a critical strategy for longer term survival.

    So ultimately, how do operators monetize networks?  Perhaps the question needs to be focused on monetizing customers – by turning attention toward strategies that get more share of wallet.  Operators should invest Capex into supporting behavioural shifts in their customers.   Mobile wallet, xBanking, xCommerce, etc, need to be provided as revenue-generating services by the operators, for those customers.  It’s no longer about getting money for network services…it’s now about getting money from supporting a behaviour facilitated by those network services.

  • The Pot of Gold at the End of the Network

    The Pot of Gold at the End of the Network

    Along with a thawing of the ground, March brought St Patrick’s day, a traditional Irish day of festivity in which everything Irish is celebrated. It’s also a great excuse to make green cookies and for the kids to dress up as leprechauns wearing shamrocks. In Irish mythology leprechauns are mischievous characters who love to play practical jokes, and keep a pot of gold hidden at the end of the rainbow. It takes a shrewd person to trick a leprechaun into giving up his gold. The search for the pot of gold at the end of the rainbow has become a popular way of describing the search for wealth and reward at the end of a journey.   In the world of network management there are rainbows everywhere, since networks are often full of stranded or underutilized assets at the far edges of the network.  Assets that are of great value, but hidden from view. The assets are hidden because they have been moved or not properly registered in inventory or Fixed Asset registers, and so they have become unusable since no one knows where they are.   The knock effects of this are felt throughout a service provider.

    Finance

    Don’t know the value of assets in the network so cannot provide accurate financial statements

    Marketing and Sales

    Don’t know what services the network can support or predict the cost will be for implementing new services

    Network Management

    Can’t manage the network optimally because assets cannot be re-purposed to augment network hotspots

    Order drop out from inconsistent and unreliable records

    These challenges not only affect the individual functional areas, but can result in open warfare between the groups. Network managers feel they must request ever bigger budgets to compensate for the extra demands being put on the network by new marketing initiatives, and finance fear they are being asked to throw money into a black hole with no possibility of understanding the return on investment. Without cross functional visibility of the companies network assets then suspicion and mistrust can develop between groups, which can cripple a company. Finance need to know if the assets they are purchasing are providing value to money, and marketing need to know if they can confidentially sell new services that will bring in extra revenue. Network managers want to know how they can provide the service required with ever tighter budgets.

    By utilizing automated network discovery network managers could re-build, or even create, an inventory that would give them a true picture of what was available in the network. A network discovery tool that could also understand how those assets were being utilized, which services were running on them, and how the network was connected together, could provide a way to optimally utilize every asset to provide a robust network for the least possible cost. When combined with an asset tracking and life cycle management tool such as Subex ROC AA then network discovery can give unprecedented level of visibility of where assets are located, how they are being used and what value they are bringing to the company.  ROC AA with network discovery can uncover the pot of gold hidden at the end of your network.

  • Spreadsheets and the Underwater Analyst

    Spreadsheets and the Underwater Analyst

    You’re an Analyst so you love data, right? Data is the oxygen of an organisation, but just as a living creature needs a heart and clean arteries to keep its oxygen infused blood flowing smoothly, an organisation also needs to maintain its systems and system interfaces to keep that data flowing smoothly and efficiently. As an analyst you will probably feel physical pain if your supply of data is cut off, and may even begin to experience panic attacks, but a good analyst will persevere in finding a cause of the blockage and find a way around it. That’s why we have spread sheets everywhere. Spread sheets are like virtual scuba tanks for an analyst, providing a personal supply of data to play around with in a world where the usual source is either unreliable to completely unavailable. What’s even worse is that the supply of data is generally under someone else’s control, which will often be your resident IT group. Need a report on Sales for a new product by region? Ask IT. Need the data on a daily instead of weekly basis? Better ask IT to change the extract. Need to know which customers are churning by a specific market segment? You guessed it.

    So you get a report to tell you everything about everything, stick it into a monster spread sheet and start to play. But then the data changes. It’s no longer relevant and you haven’t been able to get an update. You’re blind and the presentation is tomorrow morning! You are facing the same reality that countless organisations are facing across the globe, which is that data held in spread sheets and on laptops around the organisation starts turning stale as soon as it’s loaded, and that can lead to organisational paralysis. Despite the promise of flexibility and agility spread sheets can actually cause inflexibility, as functional silo’s become more divided and inter-functional processes break down.

    There must be a better way. If only the data was always to hand and you didn’t need to go to IT cap in hand to get a report that is obsolete before it’s delivered. If only you could get instant access to the data you need in an enterprise strength repository that automatically loads data 24/7, and then provides you with all the tools you need to transform, enrich, aggregate, correlate, forecast and generate beautiful charts to make sense of it all. Then imagine that the product that does all this is the core for a wide range of integrated solutions from billing to network management, asset assurance and cost management, and that you, or anyone else in the organisation, is now able to pull up to the minute analytics out from any those systems, as well as any other systems within your organisation, from one central portal. Then you would be looking at the Subex ROC, the powerhouse at the core of a comprehensive range of products that put control back in your hands.

  • The Importance of Peripheral Vision

    The Importance of Peripheral Vision

    The air is clear and fresh at 6000 feet, and I can see the snow covered roofs of the chalets in the valley below.  Just ahead a pristine white slope punctuated with a few hundred moguls’ presents a challenge for my knees and stamina, but also a whole lot of fun. From the top I pick my line, turn my skis to the edge, take a deep breath and push off.   My ski instructor has admonished me to keep my shoulders facing down the slope and not to run straight into the bumps, but go up the sides and pivot near the top such that I use the slope of the bump to control my speed. The first few turns go well but as the slope steepens so my speed increases I become focussed on one thing, which is just to stay in control. Then it happens. From out of nowhere another skier, even more out of control than me, is flying in from the right side on a collision course. My only course is to swerve to the left and straight into the nearly vertical face of big mogul I was hoping to avoid. The wipe out is messy and leaves me with one ski on and the other cheerfully bouncing away down the slope on its own.   As I stumble down the slope to retrieve my other ski I remember the other thing my ski instructor reminded me do, which was to always be mindful of my peripheral vision, since that how you avoid unpleasant surprises. It also made me think about the importance of peripheral vision in other areas of life. We typically think of peripheral vision as an ocular skill, but it’s also a great skill to develop when trying to steer a project or even an entire company through the bumps of market forces and competition.

    In their book ‘Peripheral Vision: Detecting the Weak Signals That Will Make or Break Your Company, Day and Schoemaker describe how successful companies often share one key characteristic, which is that they remain vigilant of the ‘weak signals’ that come from the edges of the organisation, and this allows them to be highly adaptive. It’s often the case that someone in an organisation knows about an issue that ‘blindsides’ a company long before it happens, but just didn’t have the right channels of communication to the person who needed to know. The problem isn’t lack of data, but lack of appropriate filtering to isolate the signals from the noise, and providing the channels through which that data can reach those strategic thinkers who are vigilant and can take action.  It’s not about what you know, but what you don’t know.

    Subex Ltd. developed the ROC, (Revenue Operations Centre), to not only sit at the centre of their suite of award winning products, but also to assimilate data ‘signals’ from all areas of a business to provide a high level view of those KPI which let executives know that things may not be going to plan. Through a combined process of ETL and data federation ROC provides a conduit through which those faint signals can be collected, amplified with advanced analytics, filtered, and then channelled in near real time to the right people.

    Executives need to ask the right questions. They need to ask why they didn’t know something was going to happen before it happened. To do that they need to improve their peripheral vision, keep vigilant and always be ready to act on the signals coming in from the edge of their business.

  • The threat of Signaling!

    The threat of Signaling!

    Signaling level risks, specially fraudulent accesses from connected SS7 networks, is one area which is making a lot of noise in the assurance and security functions of Telecom organizations today.
    The focus on the matter is such that most of the industry conferences talking about the current and next gen threats have a lot of matter being presented and shared on this topic – both from the operators and vendors alike.

    What is it ?
    The signaling level risks generally refer to SS7 (2G/3G) and Diameter (4G) level vulnerabilities (inherent or configuration based) which exposes operators to hacks/frauds through signaling control commands specially in roaming and interconnect scenarios. The scenario becomes more risky considering a normally configured SS7 infrastructure of an operator is accessible to any other operator in this world, either directly or through certain number of hops.
    Now, just consider a situation where a rogue operator exists or a group of hackers with a malicious intent have got access to SS7 signaling of any less-secure operator in this world.
    The losses due to signaling risks, while are still quite speculative, are expected to run in billions every year. Artificial inflation of traffic (specially A2P & P2A SMSes), Spamming, Spoofing, Refiling, profile modification, unlawful tracking, unethical disruptive activities from competition etc. are examples of some risks which have been found to be existing NOW with an estimated 100% infection rate.

    Why is it happening ?
    The SS7 signaling based vulnerabilities have been existing since very long, but have become part of news headlines recently due to certain revelations made by famous ethical hackers at certain high profile security conferences.
    Some industry pundits make a point, which most of my industry connections agree with, is that these risks exist mostly due to the fact that operators tend to create unreliable partnerships and configure unregulated access (like open GT access, acceptance of any signaling command etc.) which enables malicious parties to connect to operators networks and conduct fraudulent activities very easily.
    There have also been discussions around existence of services exploiting these signaling level vulnerabilities being offered in the grey markets through rougue hacking communities for a price.

    Can you eradicate these risks ?
    Ideal Solution: Operators need to sanitize their access configuration on SS7. Rethink, Reidentify, Reevaluate and Reconfigure the access levels.
    But this is really difficult or maybe nearly impossible to achieve due to some practical issues on the ground, such as:

    • Most of the SS7 networks were configured long time back – There is an expertise issue operators are facing wrt SS7 networks now which limits their capability in terms of reconfiguration of SS7 based networks
    • It is a time consuming activity, which, would also lead to a lot of efforts on re-testing connectivity with all the partners, attracting a lot of investment
    • It may lead to reconfiguration of the signaling level configuration at the network level, and in certain instances, would require network downtime – A complete NO-NO for a lot of players out there. Situation becomes even more problematic for countries where Telecom Networks are considered a National Infrastructure.
    • Lastly, not every operator will take up this activity for many different reasons including the reasons like operators not participating in the awareness meetings/conferences being organized around the world or even like some rogue operators participating in malicious activities deliberately.

    The problem becomes much more trickier from the fact that even one infected, unsecure or rogue operator in the world will continue to pose a threat to everyone else. And sanitizing each operator against these threats is a feat which is very unlikely to be achieved.

    It is now unanimously being accepted that SS7 signal based networks are here to stay (atleast 10 years in developed markets and 20-25 in developing or lesser developed countries) and even their vulnerabilities, which are expected to grow by huge amounts considering the limelight it has received recently.

    The bigger problem which has started giving sleepless nights to the fraud & security functions in operators moving towards 4G and setting up their networks over diameter protocol (provides 4G signaling framework) does not have native security standards inbuilt, but requires security mechanisms to be implemented on top, a practice always found susceptible to gaps). Also, the access methods are similar to SS7, so it exposes 4G networks to similar signaling risks as SS7.

    What can be done now ?
    For now, an approach of detection would be ideal until the industry identifies a way to plug these vulnerabilities around the world, which is definitely a few years away with a lot of research hours of investment.
    An approach of detecting malicious signaling requests in your network still has few complexities to manage:

    • High false positive rates – A lot of signaling requests appearing to be malicious come out as configuration issues from the partners. Hence, domain expertise is essential to filter out ‘needle from the haystack’.
    • Sheer size of signaling data to be analyzed – big data support is required.
    • Skill set – This activity will surely require a knowledge upscaling and may be difficult for the traditional teams like fraud and risk management to absorb. Even teams like security, with less focus on fraud domain know how, is expected to find it difficult to add this activity in their set of responsibilities.

    I feel industry partnerships with vendors, possessing both the domain knowledge, right skill set and technology built on big data platform is the way to go.

    These partnerships, considering no-one has a complete answer to this rampant problem of signaling vulnerabilities as of now, need to be built on solid vendor capabilities, while being both liberal and experimental to give room for exploration.

  • Revenue Assurance and LTE

    Revenue Assurance and LTE

    Emergence of LTE

    Through the last one decade when telecommunication globally evolved from 2.5G to 3.5G taking along the subscribers from a mere 56 Kbps to streaming of HD videos & music on your handset, data and content has evolved by giant leaps far faster than anyone predicted. The evolution not only provided a broad variety of services to the end users but also magnified the economics of content provision, VoIP services and eCommerce by leaps and bounds.

    A far cry from just using you mobile phone for voice and SMS, the thirst for data from the end users of today sends out a clear message that even the speeds offered by 3G networks fall short of the requirement. So much so that this evolution is slowly but steadily diminishing the traditional circuit switched voice traffic.

    The below stats geographically indicated illustrates the current data evolution:

     

    Risk Profiling

    The evolution of LTE differs not only from an end user product offer perspective but also from the point of network architecture. This makes LTE evolution very different from the 3G evolution wherein only a few components changed along with minor adjustments in xDR formats. These minor changes resulted in majority of the core RA practices to accommodate a 3G risk mitigating process with minor adjustments to already existing controls.

    However this would not be the case when it comes to LTE wherein majority of the network components are different with layers of complexity that originates from the perspective of how products are designed and offered.

    • Product Design

    When it comes to how RA facilitates product design in an LTE network we must take note of the fact that very few RA practices today have a functioning RA process that contributes to marketing campaign, product offer development and change management in a 2G / 3G / fixed line / broadband environment. The primary reason being that majority of the RA operations still concentrate towards leakage detection and not revenue enhancement.

    However in the case of LTE where subscribers have access to multitude of content and eCommerce in a market which is growing at a rate of 30% – 55% at any given geographical market coupled with thinning bottom lines, here RA processes for product design becomes far more important in the insights that can be generated through various multi-dimensional usage modeling.

    •  Order Management & Provisioning

    Unlike a 2G & 3G environment wherein the subscriber service configuration is spread across the order management system, HLR, IN and billing in an LTE scenario the scope of risk is drastically amplified due to the dynamic allotment of service elements in the PCRF as per a designated service plan.

    Herein any risk mitigation process begins with the analysis of services allocated at order management, subscriber’s historical usage and the subsequent policies that are dynamically enforced by the PCRF.

    • Rating and Billing

    LTE brings in complexities within each service plan wherein the rating differs across each and every data session initiated by a subscriber. For instance, if a subscriber is streaming a video / music and simultaneously texting through a popular messaging service the corresponding rating will also differ specific to the plan associated to a session; in this case video stream will be rated differently from the messaging service. Here again to add another layer of complexity, rating can also differ on the QoS guaranteed to an end user.

    Evolution of RA

    It becomes fairly clear that majority of the traditional controls that has been used for a 2G & 3G scenario cannot be reused for RA in LTE thereby paving the way for RA evolution along with the corresponding LTE evolution.

    One of the important takeaways in the evolution of RA is the importance of analytics for revenue reporting / projections through multi-dimensional data modelling which is a must in a LTE environment which thereby provides a multitude of insights on subscribers, products, network utilization and revenue generation.

  • The Re-Emergence of Convergence

    The Re-Emergence of Convergence

    Operators and global industry forums continue to wrestle with the question of whether or not to merge their fraud and security teams/work-groups to cope better with criminals who are breaking in through IP-based networks in order to derive profit for themselves (or their causes), or just to wreak havoc and disruption on their “enemies”.  Fraudsters are not just partaking in the traditional crimes of bypass fraud, roaming, Dial Through, AIT/PRS, Call Selling fraud etc., but also the exciting new stuff…. Phishing, malware, spoofing, DDoS, Trojans etc.

    One can be forgiven for thinking that fostering closer links between fraud and security domains is breaking new ground in terms of responding to the threats posed by 4G/LTE, NextGen, the continued growth of e/m-commerce and the proliferation of data passing over networks.   I guess it is a sign of my advancing years that I can’t help feeling that we have been here before…

    15 years ago, when I was prepping for an interview for my first job in the fraud management arena, I was listening open-mouthed as a fraud expert was explaining to me the finer points of PBX Hacking.  Thinking back, two things were very clear:-

    1. The Operator in the UK already had a merged fraud and security group (which they later separated out, then subsequently re-merged again, by the way).
    2. The main advice to combat PBX Hacking was prevention, not detection… and that meant security prevention. The operator was keen to tell its business customers that they needed to physically lock away their PBX equipment, protect their passwords, switch off unnecessary/vulnerable services such as DISA/Voicemail, carry out security awareness training for switchboard operators, support staff, suppliers, use barring at switch or extension level, keep PBX call logging records to see hacking attempts before they succeed, shred old copies of internal directories, vet their security/cleaning staff, etc. etc.   The FMS only stepped in when all the prevention activities failed and the PBX was breached.  By the time that happened, operators were already losing money directly, if they were responsible for the switch, or indirectly if their customers were liable.  Customers may have been unwittingly facilitating the fraud by their lack of security awareness etc. but even so, if a small business – used to paying perhaps $1000 a month for calls, suddenly gets a bill for $20000, they are going to fight it, refuse to pay it or be unable to pay it.  The indirect cost to the operator of customer complaints, disputes, potential court cases, damage to the brand, bad publicity, negotiated settlements, debt write-off and churn etc. can cost far more than the original bill.  It was a lose/lose situation… unless you were the fraudster.

    These days, with the emergence of 4G/LTE, IP-based Networks, perpetrators are still committing the same underlying crime for the same motives as before, but now they are breaking in through a host of different entry points, wearing better disguises, carrying bigger SWAG bags and using faster getaway vehicles.  In truth, many operators are struggling to keep up with the high number and seemingly unpredictable nature of these attacks.

    Security teams are traditionally very good at preventing access to networks, but they are not perfect.  The pace at which network elements, components, interfaces and transactions are increasing is making it impossible for all the preventative measures to be in-situ from day one.  Not to mention the surfeit of off-the shelf tools that fraudsters can use to break in to more and more lucrative areas of daily commerce.

    In practice, Prevention alone cannot succeed.  Detection, Analysis and Response are also essential elements of the fraud management cycle.

    Cycle

    So, my point is this…. security and fraud teams cannot operate in silos.  Security teams must continue to try and prevent malicious intrusion as much as possible.  That requires taking in a lot of real-time data from the access points, identifying the nature of the content and the data patterns and quickly blocking anything that looks dubious.  But when the intruder gets in (and they do in their numbers), that is when the fraud team can also play their part.

    Whilst the security team controls corporate IT networks, how well can they police the mobile workers and the homeworkers, the tablet users, the App Store/Android Users etc.?  And if you think that profiling subscribers was difficult historically, how much harder is it when you can’t even define what a subscriber is, let alone track their behaviour.  In the new world, the relationship between account holder, subscriber and product/service is not always obvious.  Also, the billing relationships for transactions can be mind-boggling.  Couple this with the speed at which these transactions are taking place and the value of services and content being passed across a proliferation of bearers, and you have a minefield to negotiate.

    This is where a good Fraud Management System can supplement an operator’s security tools.  An FMS must now be equipped to take in much larger volumes of data than before, in many different forms and process it much quicker.   Any reputable FMS vendor will now be offering solutions with large scale, flexible data handling tools (including probe / deep packet inspection events), internal/sales partner audit logs/feeds, inline service/transaction monitoring, exhaustive rules engines (real-time, in-line and statistical), subscriber grouping & profiling features, reference data including Hotlists/Blacklists, fraud and device “fingerprinting” capabilities, ID verification, alarm prioritisation and established, flexible workflows, with a range of analytics tools and visualisation features.  All these components – in the hands of an experienced and well-managed fraud operations outfit – will help to choke fraudsters and drive them out to look for easier targets.

    So, in summary, don’t let the security guys take all the strain at the prevention stage.  Share the data, share the knowledge and spread the load to the fraud team for a more comprehensive response.

    To get more information about Subex Fraud products please click here.

  • Mobile data offloading & Revenue Assurance

    Mobile data offloading & Revenue Assurance

    Emergence of mobile data offloading

    Though mobile data offloading is not new to the industry it is catching steam off late and that has made operators around the world take notice. The factors that are driving mobile data offloading is the ever growing smart phone market giving people the option of streaming any content of the internet right on to the palm of their hands.

    Surprisingly it is not “work on the move” that is making a large percentage of the populace download content through their smart phones extensively but the driving factor happens to be  streaming of video content from sites such as YouTube that ranks at the top of data usage .

    Key industries can’t afford to ignore the trend especially when recent industry research predicts that nearly 50-60% of the data would be offloaded by the year 2017 by either WiFi, WiMax or Small cells with WiFi being a major player over the latter two.

    Why offload with begin with?

    At a time when cellular operator costs are going up due to investments in 3G and 4G network evolution, WiFi still ranks at the top for data offloading primarily due to 3G/4G pricing, poor signal reception indoors and WiFi’s higher bandwidths offerings with little or no interference.

    The three factors put together are the leading cause for smart phone / tablet data usage being offloaded to a WiFi network.

    A simple iPad sales figures of 2012 provides a interesting insight into the fact that 9 out of 10 iPads are only WiFi show casing a interesting find that cellular data services has been given a miss at the highly sought iPad retail market itself

    “A little known fact is that contrary to popular belief a smart phone / tablet also uses lesser battery when connected to a WiFi network accounted due to the lower signal strength requirement.”

    The benefactors

    Apart from the end users who get excellent bandwidth, speed and zero interference reception; the businesses which provide broadband services to end users cash in by filling in the gaps between the cell towers, literally.

    A few OPCOs in the wireless business who also double up by providing broadband services in the form of ADSL or FOC loop back their users into their network business.

    How can RA help?

    Analytics, analytics, analytics!!!

    “The true potential of analytics is only limited by ones own imagination of what can be done with an array of data at your disposal”

    Here RA’s primary role comes in as a revenue enhancer or opportunity loss identifier and not as the more commonly known roles of “leakage identification”.

    From an RA perspective looping in key information of users such as the data usage pattern over cellular and WiFi and overlaying them over various dimensions of demographics, content, customer categorization and lifestyle components will provide an insight on potential cellular onload or offload opportunities which can be monetized by provision value add or add on services to potential users.

    From an operators perspective this insight can increase revenues especially in regions where a good smart phone markets show below par cellular data usage therein operators can increasing their service offerings to targeted localities and users in the form small cells, WiFi, or  WiMax.

  • Factors Complicating Assurance in 4G Environments

    Factors Complicating Assurance in 4G Environments

    GSMA has a vision for 2020 for Telecommunications Industry around connected living which focuses on main pillars which are expected to drive the industry forward, namely – Network 2020, Personal Data, Internet of Things and Digital Commerce.

    As per my view, the single most important take away from that vision is the rise of Telco 2.0.

    Telco 2.0 are those telecom operators which are expected to expand transformationally by taking risks to chase higher rewards in both known and as yet unknown new parts of the value chain. These are expected to be the most advanced & disruptive Telecom Operators.

    Telco-2.0

    The most important enabler of these, so called, Telco 2.0 operators would be the ‘platform’ which would allow them to explore & experiment with those unknowns and expand services while ensuring higher customer experience which will help them achieve that visionary status.

    One of such platforms is 4G, which riding on the inability of 3G-3.5G networks in delivering the required quality of service, has shown tremendous adoption rate within operators over the years.

    What has made 4G enabled networks so popular is its proven capability as an ideal platform for cross domain services convergence & all access technologies.

    A comparison between 4G LTE & HSPA (~3G) based network and service delivery capabilities can be seen below:

    consumer-content

    The bitmap above also provides a crude reasoning around lower adoption rate of certain services which were also rolled out over 3G enabled networks, but did not meet the consumer expectations around quality, reliability and price.

    4G based networks provide the ability to the operators to become the ‘Real’ converged service providers, which until 3G was more theory than practicality. Operators are now becoming OTT service providers including communication, social media, social network, content, advertisement etc., connected living enablers, enterprise enablers etc. which was, until now, being offered mostly by 3rd parties.

    With operator owning the converged service offerings (or at-least controlling some part of the service delivery like quality etc.), the increase in traffic over its pipes has shown potential of increase in direct revenues, that too proportionately.

    Factors influencing complexity in 4G environment

    Yes. 4G is great! But, not without the share of complexities it injects in the area of assurance (RA & Fraud) operations.

    The following variables are identified to be the main influencers with respect to complexity and uncertainty in 4G environments:

    New Network Elements

    4G introduces new set of network elements and O/BSS systems generally being customized in terms of design or implementation as per the operator raising concerns around interfacing, data availability or quality. This also points to increase in complexity & volume of RA & FM activities to be performed due to increased data sources and controls.

    Also, a lot of components in 4G implementations are still not COTS and provide different logging & access levels which raising concerns around capability around identification of internal frauds and external access attempts/brute force attacks.

    Parallel Networks

    Traditional networks including certain components adopted from 2G, 3G environment and running in parallel to enable backward compatibility and interconnection leads to further increase in risk, complexity and number of controls to be managed.

    Non Standard Implementations

    Some areas of 4G network, O/BSS systems and interface partnerships (operator, content providers etc.) are being implemented in customized non-standard fashion to enable interconnections (including roaming approach) and support complex products and service offerings (like VoLTE or VoLTE roaming etc.). The situation is more of an experiment and working towards developing a standard rather than following one.

    Lack of reference 4G RA & FM practices combined with custom implementations, RA & FM activities are expected to be driven by non standard data sets and frequencies until stability/maturity.

    Initially in 4G space, RA & FM practices may be exposed to the scenario of ‘Incident induced learning’ or ‘reactive RA & FM’.

    Higher Convergence

    Higher convergence of ‘core’ telecom operator provided services introduces more ‘direct’ risks to the operator and an increased need to manage RA & fraud risks introduced by the new services, which in an earlier setting, was a headache of the third party service provider.

    New Pricing Models

    Conversion to charging policies from minutes to bytes (sessions) and bytes to service subscription & access mixed with complex bundling packs & rate plans is expected to change the traditional mindset of conducting RA & FM, especially around charging, discounting, billing & invoicing.

    Disruptive roaming charging policies are also expected to be introduced which will change the perspective further.

    For session based charging policy, verification of policy implementation is also expected to impose its own set of challenges.

    Complex service offerings

    Telecom operators are going beyond their traditional service offerings (Apart from voice and data – TV / content / cloud etc.) and venturing into the modern areas revenue generation such as content, advertisements, connected living etc.

    Rich content (VoD, music, messgaging, magazines etc.) management & delivery to become the fulcrum 4G revenues. Also, with various channels of content delivery at hand, advertisement revenues will also play an important role for mature 4G operators

    But, service based subscriptions, validity & dynamic delivery along with innovative & complex content and partner agreements are expected to complicate the RA & FM activities like never before.

    Increase in transaction volumes

    4G subscriptions is expected to increase 3.5 folds to 1.3 billion and data traffic by 6 folds to 17 Exabytes by Dec 2018. Operators will be dealing with many fold increase in data per unit of earned Revenue.

    Considering revenues are tied to data sessions, transaction volume mgmt. for the purpose of RA & FM is expected to introduce a big challenges and would require advance data treatment, management & analysis techniques (e.g. Big data).

    Responsiveness & Scalability is expected to be one of the main talking points with respect to volume management

    Rapid Product & Services Launch

    New product, package and service launch across the breath of 4G enabled service platforms are expected to see a considerable rise in throughput due to shortened development, delivery & release cycle.

    The agility of RA & FM departments in terms of proactive assessment and risk readiness is expected to keep pace with the higher number of products, services and packages being launched at the breakneck speed across the breath of business offerings

    Margin Management & Revenue Enhancement

    With increased competition, Revenues are expected to be driven by high volumes and low margins and not high margins. Product performance measurement in terms of adoption and revenue generation against target will have to be carried out at much higher frequency.

    With RA having and access to all cost items, charging, payins/payouts, usage records, quality parameters and first visibility to trends and anomalies, margin management and revenue enhancement activities are expected to take center stage

    Skill set and technology within the team will have to be enhanced or absorbed to enable and handle increased cross functional interfacing , analytics and product management

    Lack of Skill Set

    Lack of mature reference 4G implementations is also expected to lead to lack of required skill set which is needed to manage and continuously improve the RA & FM operations. There will be focus on more laborious, reactive & risk prone approach of skill ‘creation’ rather than ‘absorption’

    Updated Network Access Authentication Methods

    Operators need risk readiness against newer authentication methods which are different for different services – ISIM, USIM, Single Sign On etc. Considering device authentication & security is in the hands of the manufacturer or the OS provider,  any security flaw is a direct risk to the subscriber base of the operator

    Also, 3rd party firmwares & apps are readily available for the assistance of hackers. This situation increases the device or OS takeover further.

    Increased UE & CPE Types

    Exponential increase in multi vendor UE & CPE types has increased user exposure to IP frauds like takeovers (Accounts or UE) enhanced by ‘easy’ service access methods such as ‘single sign on’ for single or multiple services.

    While user equipments are highly exposed to malicious Apps, URLs, Malwares etc., readily available custom firmware for Customer Premise Equipment are found to expose them to the same level of risks.

    To top it off, high profile sensitive customer information hacking cases by external sources are on the rise both against individual subscriber and enterprise networks, calling for much more robust, secure and continuously improving infrastructure and detection capabilities.

    Power user exploits

    Power users or technology aware users are expected to exploit any loopholes in the implementation of service access, newer pricing models etc. through the use of various complex techniques such as URL masking etc. to bypass charging and gain free access to services

    Spoofing or device configuration updates like MAC Address may also gain popularity to help divert charging to someone else in absence of adequate authentication and multi level device binding mechanisms

     

    Movement to 4G or a higher capability environment is inevitable.

    I believe, if traditional approach to manage RA & FM operations is continued as it is even for 4G environments, these functions are expected to attract steep investments to manage complexity factors mentioned above (including increase in network elements & O/BSS systems, data streams, data loads, controls, resourcing, technology requirements etc.).

    There is an immediate need of shifting from current mindset and adopting “Smart” & “Agile” RA & FM practices across the operational spectrum (of people, process, measurement, organization & technology) to contain costs and risks much more efficiently.

    Taking a cue from Game of Thrones – “Winter is coming! and this one will be long. God help us all if we’re not ready!”

  • Intelligent Alarm Qualification in a Fraud Management System

    Intelligent Alarm Qualification in a Fraud Management System

    Most leading rule-based Fraud Management Systems are based on a relatively simple process…. When an event (or series of events) occurs, the record associated with the event is processed in the FMS.  If the event breaks a rule in the FMS – perhaps because it is unusual for the customer, unusually long duration, unusually expensive or is one of a very high number of calls – an alarm is fired and that alarm is sent to the alarm page so that the fraud analyst can see it in their workstack and hopefully take prompt action to deal with the case.

    The reality of course is that, in many instances, the alarm is competing with perhaps hundreds or thousands of other alarms for the attention of the analyst.  So, which is the most important alarm in the stack?  Well, as we know, most FMS systems will have a scoring system so that the alarms with the highest score will appear at the top of the stack.

    Typically, when rules are built, they are given a score which reflects their “potential” severity, relative to other alarms.  Weird and wonderful algorithms are then used in the background to build a consolidated score for an alarm based on a combination of these various scores for each rule breach, bearing in mind that alarms usually comprise a combination of several rule breaches.

    So a $50 call to an Adult entertainment line may have breached all of the following rules, each having a score associated with that breach:-

    • High Value Call to a Premium Rate Service
    • Long Duration Call to a Premium Rate Service
    • High Value Call to ANY number
    • Out of Hours Call

    On the face of it, this seems a sensible solution.  However, there are three flaws with this methodology:-

    1. The scoring provided for a rule breach (alert) is arbitrarily/subjectively assigned at the time the rule is written
    2. Once the score is associated with the rule, it is unlikely it will be changed until a thorough rules review is conducted, which could be months/years later
    3. No consideration is given to the “actual” ruling that was subsequently assigned to the alarm.

    But what if the score could change dynamically based on the history of ACTUAL rulings made by analysts, rather than remaining static, based on the POTENTIAL severity of the situation.

    So, for example, if a particular set of rule breaches appear to be high risk but actually rarely result in a fraud, then surely over time, the score associated with that “event” should reduce.  Likewise, if a low score alarm always results in a fraud ruling, the score should automatically be enhanced the next time the system sees the same, or similar, behaviours.

    In other words, the system learns from experience over time.  The more alarms that analysts rule correctly, the more accurately the score reflects the likelihood of that alarm being fraudulent or not.  It won’t reduce the number of false alarms, but it will ensure that the alarms most likely to be fraudulent will appear at the top of the list and be dealt with quicker than those that are known to be less risky…. And that means losses due to fraud are reduced.

    Subex has been running this system for several years now.  It is known as Intelligent Alarm Qualification (IAQ) and – wherever it is deployed – the results have been excellent.  We have a benchmark which follows the Pareto Principle (the 80:20 Rule).  This means that customers who let IAQ score the alarms should find 80% of their fraud in the top 20% of their alarm stack.  The results in 95% of cases achieve this benchmark – and in the vast majority of cases, exceed it.

    Of course, it relies on the fact that analysts do rule alarms as FRAUD or NOT FRAUD regularly, and it also assumes that such rulings are usually correct.  But as long as that is happening, as it is in most operations, then it is Happy Days!

    To get more information about IAQ or to find out more about Subex Fraud products please click here.