{"id":1206,"date":"2015-02-17T11:05:48","date_gmt":"2015-02-17T05:20:48","guid":{"rendered":"https:\/\/www.subex.com\/blog\/?p=1206"},"modified":"2015-02-17T11:05:48","modified_gmt":"2015-02-17T05:20:48","slug":"re-emergence-convergence","status":"publish","type":"post","link":"https:\/\/dev.enki.studio\/test\/?p=1206","title":{"rendered":"The Re-Emergence of Convergence"},"content":{"rendered":"<p>Operators and global industry forums continue to wrestle with the question of whether or not to merge their fraud and security teams\/work-groups to cope better with criminals who are breaking in through IP-based networks in order to derive profit for themselves (or their causes), or just to wreak havoc and disruption on their \u201cenemies\u201d.\u00a0 Fraudsters are not just partaking in the traditional crimes of bypass fraud, roaming, Dial Through, AIT\/PRS, Call Selling fraud etc., but also the exciting new stuff\u2026. Phishing, malware, spoofing, DDoS, Trojans etc.<\/p>\n<p>One can be forgiven for thinking that fostering closer links between fraud and security domains is breaking new ground in terms of responding to the threats posed by 4G\/LTE, NextGen, the continued growth of e\/m-commerce and the proliferation of data passing over networks. \u00a0\u00a0I guess it is a sign of my advancing years that I can\u2019t help feeling that we have been here before\u2026<\/p>\n<p>15 years ago, when I was prepping for an interview for my first job in the fraud management arena, I was listening open-mouthed as a fraud expert was explaining to me the finer points of PBX Hacking.\u00a0 Thinking back, two things were very clear:-<\/p>\n<ol>\n<li>The Operator in the UK already had a merged fraud and security group (which they later separated out, then subsequently re-merged again, by the way).<\/li>\n<li>The main advice to combat PBX Hacking was prevention, not detection\u2026 and that meant security prevention. The operator was keen to tell its business customers that they needed to physically lock away their PBX equipment, protect their passwords, switch off unnecessary\/vulnerable services such as DISA\/Voicemail, carry out security awareness training for switchboard operators, support staff, suppliers, use barring at switch or extension level, keep PBX call logging records to see hacking attempts before they succeed, shred old copies of internal directories, vet their security\/cleaning staff, etc. etc.\u00a0 \u00a0The FMS only stepped in when all the prevention activities failed and the PBX was breached.\u00a0 By the time that happened, operators were already losing money directly, if they were responsible for the switch, or indirectly if their customers were liable.\u00a0 Customers may have been unwittingly facilitating the fraud by their lack of security awareness etc. but even so, if a small business &#8211; used to paying perhaps $1000 a month for calls, suddenly gets a bill for $20000, they are going to fight it, refuse to pay it or be unable to pay it.\u00a0 The indirect cost to the operator of customer complaints, disputes, potential court cases, damage to the brand, bad publicity, negotiated settlements, debt write-off and churn etc. can cost far more than the original bill.\u00a0 It was a lose\/lose situation\u2026 unless you were the fraudster.<\/li>\n<\/ol>\n<p>These days, with the emergence of 4G\/LTE, IP-based Networks, perpetrators are still committing the same underlying crime for the same motives as before, but now they are breaking in through a host of different entry points, wearing better disguises, carrying bigger SWAG bags and using faster getaway vehicles.\u00a0 In truth, many operators are struggling to keep up with the high number and seemingly unpredictable nature of these attacks.<\/p>\n<p>Security teams are traditionally very good at preventing access to networks, but they are not perfect.\u00a0 The pace at which network elements, components, interfaces and transactions are increasing is making it impossible for all the preventative measures to be in-situ from day one.\u00a0 Not to mention the surfeit of off-the shelf tools that fraudsters can use to break in to more and more lucrative areas of daily commerce.<\/p>\n<p>In practice, Prevention alone cannot succeed.\u00a0 Detection, Analysis and Response are also essential elements of the fraud management cycle.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full img-responsive\" src=\"https:\/\/dev.enki.studio\/test\/wp-content\/uploads\/2015\/02\/Cycle.jpg\" alt=\"Cycle\" width=\"430\" height=\"250\" \/><\/p>\n<p>So, my point is this\u2026. security and fraud teams cannot operate in silos.\u00a0 Security teams must continue to try and prevent malicious intrusion as much as possible.\u00a0 That requires taking in a lot of real-time data from the access points, identifying the nature of the content and the data patterns and quickly blocking anything that looks dubious.\u00a0 But when the intruder gets in (and they do in their numbers), that is when the fraud team can also play their part.<\/p>\n<p>Whilst the security team controls corporate IT networks, how well can they police the mobile workers and the homeworkers, the tablet users, the App Store\/Android Users etc.?\u00a0 And if you think that profiling subscribers was difficult historically, how much harder is it when you can\u2019t even define what a subscriber is, let alone track their behaviour.\u00a0 In the new world, the relationship between account holder, subscriber and product\/service is not always obvious.\u00a0 Also, the billing relationships for transactions can be mind-boggling.\u00a0 Couple this with the speed at which these transactions are taking place and the value of services and content being passed across a proliferation of bearers, and you have a minefield to negotiate.<\/p>\n<p>This is where a good Fraud Management System can supplement an operator\u2019s security tools.\u00a0 An FMS must now be equipped to take in much larger volumes of data than before, in many different forms and process it much quicker.\u00a0\u00a0 Any reputable FMS vendor will now be offering solutions with large scale, flexible data handling tools (including probe \/ deep packet inspection events), internal\/sales partner audit logs\/feeds, inline service\/transaction monitoring, exhaustive rules engines (real-time, in-line and statistical), subscriber grouping &amp; profiling features, reference data including Hotlists\/Blacklists, fraud and device \u201cfingerprinting\u201d capabilities, ID verification, alarm prioritisation and established, flexible workflows, with a range of analytics tools and visualisation features.\u00a0 All these components &#8211; in the hands of an experienced and well-managed fraud operations outfit \u2013 will help to choke fraudsters and drive them out to look for easier targets.<\/p>\n<p>So, in summary, don\u2019t let the security guys take all the strain at the prevention stage.\u00a0 Share the data, share the knowledge and spread the load to the fraud team for a more comprehensive response.<\/p>\n<p>To get more information about Subex Fraud products please click <a href=\"https:\/\/dev.enki.studio\/test\/roc-fraud-management\/\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Operators and global industry forums continue to wrestle with the question of whether or not to merge their fraud and security teams\/work-groups to cope better with criminals who are breaking in through IP-based networks in order to derive profit for themselves (or their causes), or just to wreak havoc and disruption on their \u201cenemies\u201d.\u00a0 Fraudsters [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":1208,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[28,5],"tags":[74,26,27,29,120,60,105,69,108],"class_list":["post-1206","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fraud-management","category-general","tag-business-intelligence","tag-bypass-fraud","tag-fraud","tag-fraud-management","tag-insight","tag-internal-fraud","tag-risk-management","tag-security","tag-wholesale-fraud"],"acf":[],"_links":{"self":[{"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=\/wp\/v2\/posts\/1206","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1206"}],"version-history":[{"count":0,"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=\/wp\/v2\/posts\/1206\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=\/wp\/v2\/media\/1208"}],"wp:attachment":[{"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1206"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1206"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dev.enki.studio\/test\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1206"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}