+ All Categories
Home > Documents > 001-MAVIS - Criminal acts in the telecom field

001-MAVIS - Criminal acts in the telecom field

Date post: 23-Jan-2017
Category:
Upload: michalis-mavis-msc-msc
View: 262 times
Download: 2 times
Share this document with a friend
23
1 Criminal acts in the Telecom Field, detection methods and countermeasures Mr. Michalis Mavis, MSc, MSc f. Chairman Hellenic Fraud Forum TELECOM FORUM SULTANATE OF OMAN 13-15 April 2015
Transcript
Page 1: 001-MAVIS - Criminal acts in the telecom field

1

Criminal acts in the Telecom Field, detection methods and countermeasures

Mr. Michalis Mavis, MSc, MSc

f. Chairman Hellenic Fraud Forum

TELECOM FORUMSULTANATE OF OMAN

13-15 April 2015

Page 2: 001-MAVIS - Criminal acts in the telecom field

2

White Collar Crime increase

• WCC=> White Collar

Crime.

• Normally no

weapons, bombs or

guns are used…

Massive surge in criminal incidents during the past 10 years.

Page 3: 001-MAVIS - Criminal acts in the telecom field

3

Many faces of fraud and E-crimes

• Telecom Fraud.

• Banking fraud & money

laundering.

• Mortage fraud.

• Insurance fraud.

• Other types of fraud and

electronic crimes.

Page 4: 001-MAVIS - Criminal acts in the telecom field

4

Target of Fraud and E-crimes

Telecom fraud may be committed by :

• C2B fraud: Isolated persons or organized

criminal rings against Telecom Operators

and/or Service Providers.

• B2B fraud: But it may take place when

fraud is committed by one Telecom

Operator against other Telecom Operator

and/or Service Provider (competitor fraud)...

• G2B & G2G attacks !!!

Page 5: 001-MAVIS - Criminal acts in the telecom field

5

TrendsPresent & Future

Page 6: 001-MAVIS - Criminal acts in the telecom field

6

Current & future trends

• Convergence of IT, Telecom, Banking and

Entertainment.

• Mobility everywhere (business and private

environment).

• New services (e.g. mobile banking) and new

terminal equipment (e.g. smart watch).

• Next Generation Networks (based on IP

technology).

• Crime and fraud move now … against content.

Page 7: 001-MAVIS - Criminal acts in the telecom field

7

Some interesting business cases …

TELECOM

FRAUD

Page 8: 001-MAVIS - Criminal acts in the telecom field

8

Identity theft (a fast growing problem)

• Social Media (e.g. Facebook) information about

the victim.

• Stealing an original bill (e.g. power line bill) from

victim’s house post-box, or building entrance.

This is now a good proof of address.

• Producing faked docs (e.g. tax

certificate and/or id-card).

• Hacking his mobile or pc for

additional information.

Page 9: 001-MAVIS - Criminal acts in the telecom field

9

Skimming attack on the RFID passports

• Cheap hardware used for illegal copying

information (on the air) from the victim’s

passport (in airports, cafeterias etc.).

Page 10: 001-MAVIS - Criminal acts in the telecom field

10

• ID-theft then used to get illegally SIM cards and

other goods (subscription fraud).

• Mobile phones with SIM cards got with other

persons private data are then used for financial

fraud (high value money fraud).

• Calls are made to Premium Rate Services

numbers (high cost phone services). In the

country or abroad

(roaming fraud). The fraudster

gets “bonus” for those calls

from the PRS provider.

Subscription fraud calls to PRS

Page 11: 001-MAVIS - Criminal acts in the telecom field

11

INTENTITY THEFT AND SUBSCRIPTION FRAUD IN MOBILE PHONES…

Page 12: 001-MAVIS - Criminal acts in the telecom field

12

Gabling and casinosmobile phones subscription fraud

• SIM cards illegally obtained (subscription fraud) are then

used, in different applications, e.g. to play in online casino.

• The fraudster using the illegal SIM cards makes calls to

Casino PRS numbers to get marks for playing in the online

Casino (e.g. 100 $/per call).

• Instead of playing to the Casino with the credit he got,

transfers the money to a bank account obtained under faked

identity.

• He gets the money and disappears.

Page 13: 001-MAVIS - Criminal acts in the telecom field

13

P.R.S. calls for illegal money

• Fraudulent calls by mobile

subscription fraud.

TELEPHONE PIZZA

• Telephone cards that

never expire …

Page 14: 001-MAVIS - Criminal acts in the telecom field

14

M-commerce & m-banking fraud

• Cloned SIM cards used in m-commerce or

m-banking. The bill goes to the owner of the card.

• IP spoofing: IP packets from an illegal device

seem to originate from a legal one.

• Hackers using sniffer types of programs are

stealing from the traffic credit card numbers and

other sensitive

information.

Page 15: 001-MAVIS - Criminal acts in the telecom field

15

Recent multinational banking fraud

The CarBanak attack

Page 16: 001-MAVIS - Criminal acts in the telecom field

16

ILLEGAL MONITORING

of communications(industrial or government

espionage)

C2C, G2B & G2G attacks…

Page 17: 001-MAVIS - Criminal acts in the telecom field

17

PABX fraud

• Attacking the DISA service for making free calls.

• Call Selling operations.

• Activating illegal monitoring of communications

without traces… (automatic attendant).

Page 18: 001-MAVIS - Criminal acts in the telecom field

18

Spying programs:

Monitoring performed

for your own benefit…

Page 19: 001-MAVIS - Criminal acts in the telecom field

19

Page 20: 001-MAVIS - Criminal acts in the telecom field

20

Espionage malware :

(the Equation Group attack) (known in Feb-2015)

Page 21: 001-MAVIS - Criminal acts in the telecom field

21

Victims infected since 2001

• Government and diplomatic institutions.

• Telecoms.

• Aerospace.

• Energy.

• Nuclear research.

• Oil and gas.

• Military.

• Nanotechnology.

• Mass media.

• Transportation.

• Financial institutions.

• Companies developing encryption technologies.

Page 22: 001-MAVIS - Criminal acts in the telecom field

22

Detection & Countermeasures

• Training (know the enemy).

• Use of tools (FMS, A2)

• Build a well trained Anti-fraud Unit

in your company – organization.

• Establish a Security Policy and

enforce its use.

• Participate to international

organizations dealing with fraud

and security (GSM Fraud Forum, FIINA, etc.)

• Built a National Fraud Forum to exchange information inside your

country. Examples in Europe include UKFF, DFF, HFF etc.

• Be proactive and search continually for new threats.

• Perform security audits in regular intervals.

Page 23: 001-MAVIS - Criminal acts in the telecom field

23

Thank you !

Mr. Michalis Mavis, MSc, MSc

//gr.linkedin.com/in/mmavis

Email: [email protected]


Recommended