Approaches to Contact Center Fraud Mitigation
Originally published at tobyallens.blogspot.com
Originally published on my personal Blogger site tobyallens.blogspot.com on 8 March 2017, during my time at Acme Packet. Reposted here verbatim from the original.
There are many approaches to mitigating contact center fraud. Each approach has its pros and cons. Some are easy to implement but also relatively easy to bypass. Some are more effective but create a poor user experience for both agents and customers. Others offer excellent customer experience and effectively but are expensive to implement. Thus a careful balancing act needs to be played between effectiveness, cost and user experience.
Some example approaches are:
-
Automatic Number Identification (ANI) – ANI leverages known lists of bad actors which may be updated by analysis systems which look at call volumes etc. This technology is often deployed in consumer robo-call blocking solutions. Unfortunately its effectiveness is limited as it is relatively simple for sophisticated fraudsters to spoof calling party numbers. This is especially true as SIP gains popularity allowing bot-nets to be leveraged.
-
Knowledge Based Authentication (KBA) – Asks the customer something that they know, such as names of childhood pets or credit information. KBA comes in two flavors, static and dynamic.
-
Static KBA leverages a series of pre-collected information, is simple to implement and offers a relatively good user experience. Unfortunately, it is often relatively easy for attackers to learn this information either via social media or access to database breaches of other online services.
-
Dynamic KBA on the other hand seeks to leverage information generated on demand. Two Factor authentication (2FA) in which a customer is sent a code via an alternative channel such as text message (SMS) or an application notification, represents the simplest form of Dynamic KBA More sophisticated forms leverage information such as balance queries and recent transaction dates. Dynamic KBA is much more effective than static KBA. Unfortunately, as the questions become more dynamic and thus effective at preventing fraud they tend to become more difficult for genuine customers to answer. This drives customer dissatisfaction. Additionally, dynamic KBA is relatively expensive to deploy which means its utilization is typically limited in scope.
-
Behavioral Analysis (BA) – Leverages rules and interaction analysis to detect suspect usage patterns, such as those generated by automatic scripts attempting to find valid account numbers. Feedback from BA tools can be used to try and thwart attackers by dynamically changing IVR prompts thus breaking robocalling scripts. BA provides a good user experience because it is transparent to the end user. The downside is that providers of BA tools understand the effectiveness and enhanced user experience provided so they can leverage this to charge a premium for BA tools increasing costs in the contact center. Additionally, it can be challenging to implement BA systems in a comprehensive manner while maintaining compliance.
-
Audio Analysis (AA) – Comes in two broad flavors phone printing and voice printing.
-
Voice Printing (VP) – Is the most commonly deployed form of AA. It leverages historical analysis of calls with a customer, typically repeating a pre-recorded phrase, to authenticate the user. VP is seen as so effective that many organizations, including the Australian Tax Office, leverage it to by-pass all other authentication mechanisms. VP is relatively expensive to deploy. Further it is subject to exploitation through pre-recording of user responses.
-
Phone Printing (PP) – PP differs from voice printing in that instead of focusing on the caller’s voice it leverages analysis of the underlying audio stream to provide a risk assessment. PP can be used determine the type of telephony networks traversed, source geography and calling device. The effectiveness of PP is relatively high however it may be bypassed by sophisticated fraudsters. For example, rather than originating calls from overseas fraudsters may instead opt to exploit flaws in homebased devices to generate calls effectively emulating a customer.
-
Secure Telephony Identity (STI) ¬ Is a recent focus of standards bodies such as the IETF and the Alliance for Telecommunications Industry Solutions (ATIS) to create a new method for authenticating the identity of originating telephony service providers and individuals. STI is intended to be deployed by service providers and does appear to be a strong long term solution to reducing fraudulent calling attacks. Unfortunately the standards are probably several years away from ratification. Let alone deployment at a scale to be effective. Finally, it is not clear if enterprises will gain access to these tools.
This is just a quick summary of some of the approaches to CC fraud mitigation. Please let me know in the comments if you think I’ve missed any others.
