Caller ID Spoofing Good and Bad
|
|
|
- Anne Nicholson
- 10 years ago
- Views:
Transcription
1 ITU Workshop on Caller ID Spoofing (Geneva, Switzerland, 2 June 2014) Caller ID Spoofing Good and Bad Freddie McBride Numbering & Networks European Communications Office [email protected] Follow us on Geneva, Switzerland, 2 June 2014
2 About CEPT/ECC Geneva, Switzerland, 2 June
3 Contents Definition of Caller ID spoofing History of CLI and erosion of trust in CLI Case Study: Experience from Ireland Lessons Learned Useful references Introduction of ongoing work stream within ECC/WG NaN on Evolution in CLI Decoupling of rights of use of numbers from service provision Geneva, Switzerland, 2 June
4 Caller ID Spoofing is bad! Wiki Definition: Caller ID spoofing is the practice of causing the telephone network to indicate to the receiver of a call that the originator of the call is a station other than the true originating station. For example, a Caller ID display might display a phone number different from that of the telephone from which the call was placed The term is commonly used to describe situations in which the motivation is considered malicious. Important Policy Consideration ITU Policy initiatives to tackle spoofing should be cognisant of the fact that scenarios exist where the motivation may not be malicious. Geneva, Switzerland, 2 June
5 Some history CLI was historically an important and trusted identifier CLI set by originating operator and trusted by transit and terminating operators. As intelligence moved from the network to the terminal, user-generated CLI became possible and the trust in CLI began to decrease Use of Internet for VoIP services further eroded that trust Geneva, Switzerland, 2 June
6 Experience from Ireland Online PC Doctor scam Professionally organised scam To make its offer seem more genuine, its website listed an Irish number which people can also call Aim was to target unsuspecting, vulnerable groups Irish numbers auto-dialled by call centre application. When call answered called party connected to call centre agent Agent proceeded to tell called party that they have a virus on their PC. Called party asked to open up Event Viewer on PC Geneva, Switzerland, 2 June
7 Event Viewer Geneva, Switzerland, 2 June
8 Experience from Ireland-cont d The agent used a free tool called Log-MeIn which gives remote access to the PC quoted to fix problem (which was to clear the event viewer log!). User asked for credit card details No rogue antivirus, keyloggers or Trojan Horse programmes installed A very basic scam essentially its just social engineering.but the numbering played a crucial role. The victims trusted the Irish Geographic number presented as CLI How did the scammers get Irish geographic numbers? Geneva, Switzerland, 2 June
9 Numbering Resources Used Major VoIP operator had a secondary allocation of Geographic Numbers from an Authorised Operator in Ireland To get such a number the Irish National Numbering Conventions require that a user have a registered address within the Minimum Numbering Area (MNA) When signing up the address given is not validated it is merely an assertion by the user that they have an address in the MNA Online PC Doctor used this VoIP service to target its unsuspecting victims Crucially, when law enforcement authorities had difficulty in tracking down the perpetrators and bringing them to justice, the Numbering Conventions were sufficient to instruct the operators concerned to cease services on the numbers concerned. The VoIP operator and the Number Range assignee both co-operated without question However, it was then quite easy to start again with a new number and indeed valid addresses were provided for these new subscriptions in the Dublin area (usually commercial properties for sale) Geneva, Switzerland, 2 June
10 Some Lessons Learned Outside of numbering, jurisdiction a huge problem in tackling these scams Awareness campaigns promoting customer vigilance most effective way of stopping scams Of course, there will always be some victims before awareness campaigns are effective Co-operation between national and international carriers is essential. The originating operator is the gatekeeper A harmonised international solution (i.e. ITU policy measure) could help Technical solutions required to validate originating numbers particularly for VoIP calls would also help ITU-T SG2 should take note of IETF STIR work in this regard Geneva, Switzerland, 2 June
11 References (European Context) Some ECC deliverables which could also be useful inputs to inform any future policy initiative by the ITU ECC REPORT Increasing Trust in Calling Line Identification and Originating Identification ECC RECOMMENDATION 11/02 - Calling Line Identification and Originating Identification Geneva, Switzerland, 2 June
12 Evolution in CLI Usage: Decoupling End User Rights to use Numbers from Service Provision Current work stream for Project Team Number Portability Focus on different scenarios where numbers used as CLI for services not directly associated with that number. Some examples Seperate inbound and outbound services for call centres, SIM Stickers for long distance calls. Many of these services are legitimate and usually have regulator consent on a case-by-case basis. Report at an early stage. Next meeting in June 14. The Report, when ready for consultation, can be sent to ITU-T SG2 for information Geneva, Switzerland, 2 June
13 Thank You! Freddie McBride, Numbering & Networks European Communications Office Follow us on Geneva, Switzerland, 2 June
Bad Ads Trend Alert: Shining a Light on Tech Support Advertising Scams. May 2014. TrustInAds.org. Keeping people safe from bad online ads
Bad Ads Trend Alert: Shining a Light on Tech Support Advertising Scams May 2014 TrustInAds.org Keeping people safe from bad online ads OVERVIEW Today, even the most tech savvy individuals can find themselves
Information Notice. Guidelines for VoIP Service Providers on the treatment of consumers
Information Notice Guidelines for VoIP Service Providers on the treatment of consumers Document No: 05/50 Date: 05 July 2005 An Coimisiún um Rialáil Cumarsáide Commission for Communications Regulation
Telecommunication Origin Identification. Jie Zhang Vice chair, ITU-T SG2 [email protected]
ITU Workshop on Origin Identification and Alternative Calling Procedures (Geneva, Switzerland, 19-20(AM) 2012) Telecommunication Origin Identification Jie Zhang Vice chair, ITU-T SG2 [email protected] Main
Database to support inter-psap communications in Europe CEPT/ECC Feasibility Study. Freddie McBride, European Communications Office
Database to support inter- communications in Europe CEPT/ECC Feasibility Study Freddie McBride, European Communications Office EENA Members Workshop Brussels, 19-20 October 2015 CEPT/ECC/WG NaN Organisation
Promoting Network Security (A Service Provider Perspective)
Promoting Network Security (A Service Provider Perspective) Prevention is the Foundation H S Gupta DGM (Technical) Data Networks, BSNL [email protected] DNW, BSNL 1 Agenda Importance of Network Security
UMHLABUYALINGANA MUNICIPALITY FIREWALL MANAGEMENT POLICY
UMHLABUYALINGANA MUNICIPALITY FIREWALL MANAGEMENT POLICY Firewall Management Policy Approval and Version Control Approval Process: Position or Meeting Number: Date: Originator: Recommended by Director
NICC ND 1016 V<2.1.1> (2010-05)
NICC Document Requirements on Communications Providers in relation to Customer Line Identification display services and other related services Michael Faraday House, Six Dials Way, Stevenage SG1 2AY Tel.:
Internet Security Protecting Your Business. Hayden Johnston & Rik Perry WYSCOM
Internet Security Protecting Your Business Hayden Johnston & Rik Perry WYSCOM Introduction Protecting Your Network Securing Your Information Standards & Best Practices Tools & Options Into The Future Creating
White paper. Phishing, Vishing and Smishing: Old Threats Present New Risks
White paper Phishing, Vishing and Smishing: Old Threats Present New Risks How much do you really know about phishing, vishing and smishing? Phishing, vishing, and smishing are not new threats. They have
PBX Fraud Educational Information for PBX Customers
PBX Fraud Educational Information for PBX Customers Telephone Hackers Hit Where It Hurts: Your Wallet Telephone hacking is unauthorized or fraudulent activities that can affect your telephone system, and
WEB ATTACKS AND COUNTERMEASURES
WEB ATTACKS AND COUNTERMEASURES February 2008 The Government of the Hong Kong Special Administrative Region The contents of this document remain the property of, and may not be reproduced in whole or in
http://www.bankonline.com/checking PHISHING & PHARMING Helping Consumers Avoid Internet Fraud Federal Reserve Bank of Boston
http://www.bankonline.com/checking http://www.bankonline.com/checking http://www.bankonline.com/checking PHISHING & PHARMING Helping Consumers Avoid Internet Fraud Federal Reserve Bank of Boston http://www.bankonline.com
E-BUSINESS THREATS AND SOLUTIONS
E-BUSINESS THREATS AND SOLUTIONS E-BUSINESS THREATS AND SOLUTIONS E-business has forever revolutionized the way business is done. Retail has now a long way from the days of physical transactions that were
Avaya Unified Communications Can Reduce Cell Phone Expenses
WHITE PAPER Avaya Unified Communications Can Reduce Cell Phone Expenses June 2008 Table of Contents Introduction... 1 Section 1: Reduce Inbound Minutes... 1 Section 2: Reduce Outbound Minutes... 2 Section
SIP Trunk Configuration Guide. using
SIP Trunk Configuration Guide using www.cbeyond.net 1-877-441-9783 The information contained in this document is specific to setting up SIP connections between Vertical SBX IP 320 and Cbeyond. If you require
Emerging threats for the healthcare industry: The BYOD. By Luca Sambucci www.deepsecurity.us
Emerging threats for the healthcare industry: The BYOD Revolution By Luca Sambucci www.deepsecurity.us Copyright 2013 Emerging threats for the healthcare industry: The BYOD REVOLUTION Copyright 2013 Luca
Internet Banking Attacks. Karel Miko, CISA DCIT, a.s. (Prague, Czech Republic) [email protected]
Internet Banking Attacks Karel Miko, CISA DCIT, a.s. (Prague, Czech Republic) [email protected] Contents Agenda Internet banking today The most common attack vectors The possible countermeasures What protection
Effective Methods to Detect Current Security Threats
terreactive AG. Swiss Cyber Storm 2015. Effective Methods to Detect Current Security Threats Enrico Petrov Director Managed Security Services terreactive October 21 st, 2015 terreactive Background. About
PROPOSAL 20. Resolution 130 of Marrakesh on the role of ITU in information and communication network security
PROPOSAL 20 Resolution 130 of Marrakesh on the role of ITU in information and network security Submitted by the following Member States: Germany (Federal Republic of), Austria, Belarus (Republic of), Bulgaria
NEW JERSEY STATE POLICE EXAMPLES OF CRIMINAL INTENT
Appendix A to 11-02-P1-NJOIT NJ OFFICE OF INFORMATION TECHNOLOGY P.O. Box 212 www.nj.gov/it/ps/ 300 Riverview Plaza Trenton, NJ 08625-0212 NEW JERSEY STATE POLICE EXAMPLES OF CRIMINAL INTENT The Intent
Remote Deposit Quick Start Guide
Treasury Management Fraud Prevention How to Protect Your Business Remote Deposit Quick Start Guide What s Inside We re committed to the safety of your company s financial information. We want to make you
nexvortex VOIP DISASTER RECOVERY BUSINESS SOLUTION
nexvortex VOIP DISASTER RECOVERY BUSINESS SOLUTION Terry Prime Chief Technology Officer February 2007 Copyright 2007 Introduction The telephone service is a strategic component of any business or government
Dr. David Turahi Director for IT&IMS - MOICT Uganda
Dr. David Turahi Director for IT&IMS - MOICT Uganda A smart phone is a mobile phone offering advanced capabilities beyond a typical mobile phone, often with computer like functionality. There is no industry
Effective Methods to Detect Current Security Threats
terreactive AG. Swiss Cyber Storm 2015. Effective Methods to Detect Current Security Threats Taking your IT security to the next level, you have to consider a paradigm shift. In the past companies mostly
Cybercrime : Malaysia. By DSP MahfuzBin Dato Ab. Majid Royal Malaysia Police
Cybercrime : Malaysia By DSP MahfuzBin Dato Ab. Majid Royal Malaysia Police ICT Development The ICT development within this region has been rapid since more than 3 decades ago. With the launching of the
Firewalls, Tunnels, and Network Intrusion Detection
Firewalls, Tunnels, and Network Intrusion Detection 1 Part 1: Firewall as a Technique to create a virtual security wall separating your organization from the wild west of the public internet 2 1 Firewalls
Protecting your business from fraud
Protecting your business from fraud KEY TAKEAWAYS > Understand the most common types of fraud and how to identify them. > What to do if you uncover fraudulent activity or suspect you are a victim of fraud.
INSIDE. Mitigating Online Fraud: Customer Confidence, Brand Protection, and Loss Minimization. Symantec Online Fraud Management
Symantec Online Fraud Management WHITE PAPER Mitigating Online Fraud: Customer Confidence, Brand Protection, and Loss Minimization INSIDE New online threats Impacts on customer trust and brand confidence
Learn to protect yourself from Identity Theft. First National Bank can help.
Learn to protect yourself from Identity Theft. First National Bank can help. Your identity is one of the most valuable things you own. It s important to keep your identity from being stolen by someone
ADMINISTRATION COMPUTER NETWORK
ADMINISTRATION COMPUTER NETWORK School Administrative Computer Network The Cumberland School operates a network of computers specifically for administrative purposes in the school. This network is electronically
Conditions for ICT Partner Solutions Service Schedule for BT Cloud Unified Communications
Conditions for ICT Partner Solutions Service Schedule for BT Cloud 1. Provision of Service The Service will be provided by BT to the Customer using BT s Supplier. For the avoidance of doubt no contractual
1. For each of the 25 questions, multiply each question response risk value (1-5) by the number of times it was chosen by the survey takers.
Employee Security Awareness Survey Trenton Bond [email protected] Admin - Version 1.3 Security Awareness One of the most significant security risks that organizations and corporations face today is
IPv6 SECURITY. May 2011. The Government of the Hong Kong Special Administrative Region
IPv6 SECURITY May 2011 The Government of the Hong Kong Special Administrative Region The contents of this document remain the property of, and may not be reproduced in whole or in part without the express
Shield Your Business - Combat Phishing Attacks. A Phishnix White Paper
A Phishnix White Paper Shield Your Business - Combat Phishing Attacks Aujas Information Risk Services 19925 Steven s Creek Blvd, Suite 100, Cupertino, CA 95014-2358 Phone: 1.855.PHISHNX Fax : +1 408 973
VOICE OVER IP SECURITY
VOICE OVER IP SECURITY February 2008 The Government of the Hong Kong Special Administrative Region The contents of this document remain the property of, and may not be reproduced in whole or in part without
TESTIMONY OF HENNING SCHULZRINNE Levi Professor of Computer Science and Electrical Engineering Columbia University SENATE AGING COMMITTEE
TESTIMONY OF HENNING SCHULZRINNE Levi Professor of Computer Science and Electrical Engineering Columbia University SENATE AGING COMMITTEE Ringing Off the Hook: Examining the Proliferation of Unwanted Calls
10 Quick Tips to Mobile Security
10 Quick Tips to Mobile Security 10 Quick Tips to Mobile Security contents 03 Introduction 05 Mobile Threats and Consequences 06 Important Mobile Statistics 07 Top 10 Mobile Safety Tips 19 Resources 22
How To Behave At A School
THE LONG EATON SCHOOL ICT Security Policy Rules, expectations and advice for students APPROVED BY GOVERNORS: Student ICT Policy Introduction Educational establishments are using computer facilities more
location of optional horizontal pic Corporate and Investment Banking Business Online Information Security
location of optional horizontal pic Corporate and Investment Banking Business Online Information Security Business Online Information Security Risk reduction: Ensuring your sensitive information is secure
TeleZapper. Frequently Asked Questions...
TeleZapper Frequently Asked Questions... * I've been contacted by a telemarketing company claiming to represent the TeleZapper. The caller was very persistent and even asked for my bank account information.
Keynote. Professor Russ Davis Chairperson IC4MF & Work Shop Coordinator for Coordinator for Technology, Innovation and Exploitation.
Keynote Professor Russ Davis Chairperson IC4MF & Work Shop Coordinator for Coordinator for Technology, Innovation and Exploitation 6 & 7 Nov 2013 So many of us now don t just work online but live part
ECC WG NaN Green Paper
Long Term Evolution in Numbering, Naming and Addressing 2012 2022 This ECC WG NaN Green Paper was approved by the Working Group Numbering and Networks (WG NaN) at its meeting in Stockholm, Sweden, 21-22
DDoS-blocker: Detection and Blocking of Distributed Denial of Service Attack
DDoS-blocker: Detection and Blocking of Distributed Denial of Service Attack Sugih Jamin EECS Department University of Michigan [email protected] Internet Design Goals Key design goals of Internet protocols:
Online Security Awareness - UAE Exchange - Foreign Exchange Send Money UAE Exchange
The responsibility of safeguarding your personal information starts with you. Your information is critical and it must be protected from unauthorised disclosure, modification or destruction. Here we are
Could you spot a scammer?
Could you spot a scammer? Keeping you safe and secure Fraud can affect anyone whatever your background, age or experience And attempts can come in all shapes and sizes over the phone, on the internet or
UK Interconnect White Paper
UK Interconnect White Paper 460 Management Management Management Management 460 Management Management Management Management AI073 AI067 UK Interconnect White Paper Introduction The UK will probably have
Targeted attacks: Tools and techniques
Targeted attacks: Tools and techniques Performing «red-team» penetration tests Lessons learned Presented on 17/03/2014 For JSSI OSSIR 2014 By Renaud Feil Agenda Objective: Present tools techniques that
Network Security. Protective and Dependable. 52 Network Security. UTM Content Security Gateway CS-2000
Network Security Protective and Dependable With the growth of the Internet threats, network security becomes the fundamental concerns of family network and enterprise network. To enhance your business
BCS IT User Syllabus IT Security for Users Level 2. Version 1.0
BCS IT User Syllabus IT for Users Level 2 Version 1.0 June 2009 ITS2.1 System Performance ITS2.1.1 Unwanted messages ITS2.1.2 Malicious ITS2.1.1.1 ITS2.1.1.2 ITS2.1.2.1 ITS2.1.2.2 ITS2.1.2.3 ITS2.1.2.4
Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training - Session One
Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training - Session One End User Security, IS Control Evaluation & Self- Assessment Information Security Trends and Countermeasures
Common Cyber Threats. Common cyber threats include:
Common Cyber Threats: and Common Cyber Threats... 2 Phishing and Spear Phishing... 3... 3... 4 Malicious Code... 5... 5... 5 Weak and Default Passwords... 6... 6... 6 Unpatched or Outdated Software Vulnerabilities...
Security Engineering Part III Network Security. Intruders, Malware, Firewalls, and IDSs
Security Engineering Part III Network Security Intruders, Malware, Firewalls, and IDSs Juan E. Tapiador [email protected] Department of Computer Science, UC3M Security Engineering 4th year BSc in Computer
Cyber Security. Securing Your Mobile and Online Banking Transactions
Cyber Security Securing Your Mobile and Online Banking Transactions For additional copies or to download this document, please visit: http://msisac.cisecurity.org/resources/guides 2014 Center for Internet
4/20/2015. Fraud Watch Campaign. AARP is Fighting for You. AARP is Fighting for You. Campaign Tactics. AARP can help you Spot & Report Fraud
AARP can help you Spot & Report Fraud Fraud Fighter Call Center: Talk to a volunteer trained in how to spot and report fraud. Call the Fraud Fighter Call Center at (877) 908-3360 Fraud Watch Campaign What
1. Any email requesting personal information, or asking you to verify an account, is usually a scam... even if it looks authentic.
Your identity is one of the most valuable things you own. It s important to keep your identity from being stolen by someone who can potentially harm your good name and financial well-being. Identity theft
Standards for VoIP in the Enterprise
Standards for VoIP in the Enterprise By: John Elwell ([email protected]) Rue du Rhône 114- CH-1204 Geneva - T: +41 22 849 6000 - F: +41 22 849 6001 - www.ecma-international.org Traditional Enterprise
2. From a control perspective, the PRIMARY objective of classifying information assets is to:
MIS5206 Week 13 Your Name Date 1. When conducting a penetration test of an organization's internal network, which of the following approaches would BEST enable the conductor of the test to remain undetected
ATINER's Conference Paper Series COM2013-0428. The Use of Honeytokens in Database Security
Athens Institute for Education and Research ATINER ATINER's Conference Paper Series COM2013-0428 The Use of Honeytokens in Database Security Penny Ross Senior Lecturer University of Portsmouth UK Amanda
Policy. London School of Economics & Political Science. Application Control. Jethro Perkins Information Security Manager IMT
London School of Economics & Political Science IMT Policy Application Control Jethro Perkins Information Security Manager Summary This document outlines IMT s application control policy, as endorsed by
CONTACT DATABASES IN MICROSOFT OUTLOOK
CONTACT DATABASES IN MICROSOFT OUTLOOK September 2007 A Davton Consulting Whitepaper Microsoft Outlook has become the standard desktop tool for managing business email. This paper shows how Microsoft Outlook
DPS HOSTED SOLUTIONS
DPS HOSTED SOLUTIONS DPS SOFTWARE 288 SOUTHBURY ROAD ENFIELD MIDDLESEX EN1 1TR DATE: OCTOBER 2009 DPS Software 2009 1 INDEX DPS HOSTED SOLUTIONS 1 INTRODUCTION 3 DPS HOSTING OVERVIEW 4 WHAT HAPPENS IF
Berwick Academy Policy on E Safety
Berwick Academy Policy on E Safety Overview The purpose of this document is to describe the rules and guidance associated with E Safety and the procedures to be followed in the event of an E Safety incident
Parlay i60 - Application
Parlay i60 ISDN Access Multiplexer with advanced call routing features Solutions for Carriers & Service Providers Parlay i60 ISDN Access Multiplexer a miracle in terms of possible applications Cost efficient
When you are prompted to enroll, you will be asked to enter a Security Phrase and select/answer three different Challenge Questions.
IMPORTANT SECURITY INFORMATION We take your online security seriously. Your online banking site contains a security feature called Enhanced Authentication. Everyone will be required to enroll in Enhanced
White Paper A SECURITY GUIDE TO PROTECTING IP PHONE SYSTEMS AGAINST ATTACK. A balancing act
A SECURITY GUIDE TO PROTECTING IP PHONE SYSTEMS AGAINST ATTACK With organizations rushing to adopt Voice over IP (VoIP) technology to cut costs and integrate applications designed to serve customers better,
Farmers Mutual Telephone Company (FMTC) Network Management Practices Policy
Farmers Mutual Telephone Company (FMTC) Network Management Practices Policy Pursuant to the Federal Communications Commission s newly enacted Open Internet Rules found in Part 8 of Title 47 of the Code
When you listen to the news, you hear about many different forms of computer infection(s). The most common are:
Access to information and entertainment, credit and financial services, products from every corner of the world even to your work is greater than ever. Thanks to the Internet, you can conduct your banking,
Consensus Policy Resource Community. Lab Security Policy
Lab Security Policy Free Use Disclaimer: This policy was created by or for the SANS Institute for the Internet community. All or parts of this policy can be freely used for your organization. There is
Recognizing Spam. IT Computer Technical Support Newsletter
IT Computer Technical Support Newsletter March 23, 2015 Vol.1, No.22 Recognizing Spam Spam messages are messages that are unwanted. If you have received an e-mail from the Internal Revenue Service or the
Reduce Mobile Phone Expense with Avaya Unified Communications
Reduce Mobile Phone Expense with Avaya Unified Communications Table of Contents Section 1: Reduce Inbound Minutes... 2 Section 2: Reduce Outbound Minutes... 3 Section 3: Take Greater Advantage of Free
Defending Against Data Beaches: Internal Controls for Cybersecurity
Defending Against Data Beaches: Internal Controls for Cybersecurity Presented by: Michael Walter, Managing Director and Chris Manning, Associate Director Protiviti Atlanta Office Agenda Defining Cybersecurity
CCT Telecomm offers the following tips to ensure your protection from phone fraud at your home or business:
Fraud FAQs Telephone and Internet fraud happens every day. It rings up billions in fraudulent phone charges and victimizes millions of people a year. It can happen in public, in your home, at your business
ICT SECURITY POLICY. Strategic Aim To continue to develop and ensure effective leadership, governance and management throughout the organisation
ICT SECURITY POLICY Strategic Aim To continue to develop and ensure effective leadership, governance and management throughout the organisation Responsibility Assistant Principal, Learner Services Jannette
