Data-driven approach for automatic telephony threat analysis and campaign detection

被引:3
|
作者
Bordjiba, Houssem Eddine [1 ]
Karbab, ElMouatez Billah [1 ]
Debbabi, Mourad [1 ]
机构
[1] Concordia Univ, Montreal, PQ, Canada
关键词
Telephony abuse; Telephony complaints; Vishing; Spoofing; Telephony abuse campaigns;
D O I
10.1016/j.diin.2018.01.016
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The growth of the telephone network and the availability of Voice over Internet Protocol (VoIP) have both contributed to the availability of a flexible and easy to use artifact for users, but also to a significant increase in cyberecriminal activity. These criminals use emergent technologies to conduct illegal and suspicious activities. For instance, they use VoIP's flexibility to abuse and scam victims. According to (F. I. F.. N. D. N. C. R. D. Book, Available at: https://www. ftc. gov/news-events/press-releases/2016/12/ftc-issues- fy-2016-national-do-not-call-registry-data-book, accessed on: 27 August 2017), US government revealed receiving more than 5.3 million telephony abuse complaints in 2016. Based on this report, more than 226 million phone numbers were registered on the Do Not Call Registry list as not to receive tele-marketing calls. For instance, they use VoIP's flexibility to abuse and scam victims. A lot of interest has been expressed into the analysis and assessment of telephony cyber-threats. A better understanding of these types of abuse is required in order to detect, mitigate, and attribute these attacks. The purpose of this research work is to generate relevant and timely telephony abuse intelligence that can support the mitigation and/or the investigation of such activities. To achieve this objective, we present, in this paper, the design and implementation of a Telephony Abuse Intelligence Framework (TAINT) that automatically aggregates, analyzes and reports on telephony abuse activities. We deploy our framework on a large dataset of telephony complaints, spanning over seven years, to provide in-depth insights and intelligence about emerging telephony threats. The framework presented in this paper is of a paramount importance when it comes to the mitigation, the prevention and the attribution of telephony abuse incidents. We analyze the data and report on the complaint distribution, the used numbers and the spoofed callers' identifiers. In addition, we identify and geo-locate the sources of the phone calls, and further investigate the underlying telephony threats. Moreover, we quantify the similarity between reported phone numbers to unveil potential groups that are behind specific telephony abuse activities that are actually launched as telephony abuse campaigns. (C) 2018 The Author(s). Published by Elsevier Ltd on behalf of DFRWS.
引用
收藏
页码:S131 / S141
页数:11
相关论文
共 50 条
  • [31] Sparse Actuator Attack Detection and Identification: A Data-Driven Approach
    Zhao, Zhengen
    Xu, Yunsong
    Li, Yuzhe
    Zhao, Yu
    Wang, Bohui
    Wen, Guanghui
    [J]. IEEE TRANSACTIONS ON CYBERNETICS, 2023, 53 (06) : 4054 - 4064
  • [32] An approach for robust data-driven fault detection with industrial application
    Yin, Shen
    Wang, Guang
    [J]. 39TH ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY (IECON 2013), 2013, : 3317 - 3322
  • [33] Learning to Detect: A Data-driven Approach for Network Intrusion Detection
    Tauscher, Zachary
    Jiang, Yushan
    Zhang, Kai
    Wang, Jian
    Song, Houbing
    [J]. 2021 IEEE INTERNATIONAL PERFORMANCE, COMPUTING, AND COMMUNICATIONS CONFERENCE (IPCCC), 2021,
  • [34] Data-Driven Approach for Fault Detection and Diagnostic in Semiconductor Manufacturing
    Fan, Shu-Kai S.
    Hsu, Chia-Yu
    Tsai, Du-Ming
    He, Fei
    Cheng, Chun-Chung
    [J]. IEEE TRANSACTIONS ON AUTOMATION SCIENCE AND ENGINEERING, 2020, 17 (04) : 1925 - 1936
  • [35] An H∞ approach to data-driven simultaneous fault detection and control
    Salim, M.
    Khosrowjerdi, M. J.
    [J]. IMA JOURNAL OF MATHEMATICAL CONTROL AND INFORMATION, 2017, 34 (04) : 1195 - 1213
  • [36] Data-driven approach for fault detection and isolation in nonlinear system
    Kallas, Maya
    Mourot, Gilles
    Maquin, Didier
    Ragot, Jose
    [J]. INTERNATIONAL JOURNAL OF ADAPTIVE CONTROL AND SIGNAL PROCESSING, 2018, 32 (11) : 1569 - 1590
  • [37] A Data-Driven Approach for Detection and Estimation of Residential PV Installations
    Zhang, Xiaochen
    Grijalva, Santiago
    [J]. IEEE TRANSACTIONS ON SMART GRID, 2016, 7 (05) : 2477 - 2485
  • [38] Poster Abstract: Themis: A Data-Driven Approach to Bot Detection
    Kalmbach, Patrick
    Blenk, Andreas
    Kellerer, Wolfgang
    Schmid, Stefan
    [J]. IEEE INFOCOM 2018 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2018,
  • [39] A Probabilistic Projection Approach to Data-Driven Dynamic Fault Detection
    Xue, Ting
    Ding, Steven X.
    Zhong, Maiying
    Zhou, Donghua
    [J]. IFAC PAPERSONLINE, 2022, 55 (06): : 43 - 48
  • [40] A Novel Combined Data-Driven Approach for Electricity Theft Detection
    Zheng, Kedi
    Chen, Qixin
    Wang, Yi
    Kang, Chongqing
    Xia, Qing
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2019, 15 (03) : 1809 - 1819