The Berkman Center Defines Bypass Fraud
“If you use a discount calling card from the US or Europe to phone Ecuador, Nigeria or any one of dozens of developing countries, your voice is now more likely streaming over the Internet and terminating via an illegal operator rather than travelling over conventional channels,” The Berkman Center, Harvard Law School.
What is the problem?
Legitimate operators negotiate interconnection agreements with other legitimate operators that define the routes and cost of termination calls (often international) on their network. An international call may route through the interconnection points of several operators: at each point a termination fee is charged by the operator through which the call is routed. Routing calls in a manner that avoids these agreed interconnection points is bypass fraud.
How big is the problem?
Bypass fraud has existed for years. Many early bypass operators used satellite communication to avoid operator international termination charges. The sophisticated equipment, considerable investment, and specialized skills needed to set-up satellite bypass contributed to keeping this fraud contained.
The advent of Voice over IP (VoIP) has made bypass easier and more common. VoIP equipment is readily available, low-cost, and easy to set-up. Individuals and groups have sprung up that use VoIP as a method to route calls onto or away from an operator’s network avoiding the interconnection points.
The value of bypass is difficult to quantify, but it is acknowledged that large telcos are losing significant revenue to VoIP routing. For example, the Wall Street Journal reported that a Mexican carrier had lodged a complaint to the WTO stating that illegal bypass by VoIP provider cost it $200 million in 2003 alone. More recently, it was estimated that Europeans spent $31 billion on VoIP bypass in 2006.
How it occurs
There are many variants of bypass fraud: international, national, mobile to mobile, mobile to fixed, and re-file. All variants and methods exploit the difference between regulated termination fees and cheaper, unofficial call routes.
Commonly, SIM boxes are used to perpetrate bypass fraud, so we shall use this technique for illustration. Other variants work in similar ways, but use different technologies, such as PBX.
The figure below shows two different routes of an international call to a mobile phone: the official route and bypass route. In the official route, the call charge may be made up of the originating section (up to the international switch), the international transit (between international switches), and the local termination.
The bypass route avoids the local termination by using VoIP to carry the call to a SIM Box in the destination country.
The SIM box maps the call from VoIP to a SIM card (in the SIM box) of the same mobile operator of the destination mobile. Calls between mobile phones (or SIMs) on the same network are usually cheap compared to the cost of terminating the international call.
How it can be tackled
Several techniques exist for detecting bypass fraud (specifically SIM boxing), for example:
B-number diversity: a series of calls placed through a bypass route are rarely to the same number as the calls are placed by large numbers of unrelated individuals. B-number/destination diversity is a reliable, low cost indicator of bypass fraud.
Roaming record matching: if an operator’s roaming subscriber’s call is routed through a bypass operator, the B-number and timestamp in the TAP record will match those of an on-network Mobile Originated Call, but the originating numbers will differ. This method is low-cost and reliable, but only identifies a narrow set of bypass situations.
International calling to SIM-card where CLIR has been removed: this method relies on initiating calls from international destinations and collecting routing information. It is highly reliable, but costly and requires operator co-operation.
Bypass routes have several other characteristics that can help reduce false positives:
*** High call volume;
*** Only voice service (i.e. no voicemail, SMS, etc);
*** Only on-network calls (originator and destination service provider is the same);
*** Mostly outgoing calls (or incoming calls, depending on the direction of bypass);
*** No movement of the SIM (for mobile);
*** Possible cell site flooding; and
*** Known SIM Box IMEIs.
How Minotaur™ can tackle it specifically
As stated, there are many characteristics that can identify a number used for call bypass. However, expecting all these characteristics to be present is unreliable as fraudsters will employ techniques to avoid detection, e.g. virtual SIMs can be used to simulate movement, small numbers of non-voice service can be used, etc.
The items below illustrates this point, where each bypass scenario, of which there are four, includes some, but not all typical characteristics:
On-net Call Volume - (Scenarios 2 and 4);
Hot IMEI - (Scenario 3);
Call Direction Ratio - (Scenario 1);
Static Cell Site - (Scenarios 1 and 2);
On-net Call Ratio - (Scenario 4);
Destination Diversity - (Scenario 4); and
Hot Cell Site - (Scenario 2).
Minotaur’s™ multi-stage analysis is ideally suited to detecting the variant nature of bypass fraud. A series of rules are defined in the first stage analysis process: one rule for each characteristic (e.g. high on-network call volume, unusual service usage ratio, static cell site, etc). The second stage analysis looks for different combinations of these alarms before deciding to raise a ticket. This approach results in high detection rate with low false positives.
Mobile call terminating using official route
A typical operator will carry 15,000 minutes per month per circuit. Assuming the cost to terminate a mobile call is $0.125 per minute (not untypical), the revenue per circuit is 15000 x $0.125 = $1,875. per month.
Int (raised to the Nth power) Switch = $0.125/min
Mobile call appearing as on-net (local) due to bypass
The cost of an on-network mobile to mobile call for the same operator is $0.04732 per minute. Therefore, the same circuit with 15,000 minutes per month results in 15,000 x $0.04732 = $710 per month when the call is routed through a bypass operator.
VoIP Gateway > VoIP Internet = $0.04732/min
A typical bypass operator will have 60 circuits, resulting in $69,912 per month of lost revenue! This lost revenue is revenue potential for the bypass operator.
This post was provided through the courtesy of Neural Technologies Ltd.
Related Articles:
- BTC Mobile Takes a Firm Stand Against Bypass Fraud with Neural Technologies’ Deal BTC Mobile implemented Neural Technologies’ (NT) Minotaur™ solution to enable it to tackle fraud on its network. BTC Mobile has over a million mobile subscribers. A fraud review carried out by the operator in 2006 highlighted several areas of concern, the most pressing of which was Bypass Fraud. Bypass Fraud is the illegal routing of calls in order to avoid paying interconnection fees. Legitimate operators negotiate interconnection agreements between each other that define the routes and the cost to terminate calls on their network; routing calls in a manner that avoids these agreed interconnection points is Bypass Fraud. The advent...
- Subex Azure Defines Revenue Operations Center at Risk Management and Internal Audit in Telecoms 2006 Subex Azure, the world's largest vendor of revenue maximization solutions for telecom operators, will be exhibiting and speaking at the 9th Annual Risk Management and Internal Audit in Telecoms 2006 conference, which takes place at the Cafe Royal, London, UK between 18 and 19 September 2006. Karthikeyan Ramnath, Product Manager, Subex Azure, will be presenting a session entitled "Reducing the Day Sales Outstanding (DSO) using the Revenue Operations Center (ROC)" on Tuesday 19 September 2006. Karthikeyan will be looking at the benefits of collaboration between fraud and risk management; how the ROC is defined; aligning departmental strategies with corporate strategy,...
- Are you attending APAC’s only Billing RA Fraud Event? The 7th Annual Asia Pacific Billing & Revenue Assurance 2007 co-located with the Telecom Fraud Summit 2007 is now less than 4 weeks away. Wondering how valuable it is for you to attend? Here are 25 reasons why you must not miss this rare opportunity to adapt new ideas for your key revenue protection functions - billing, revenue assurance and fraud management: 25 Operator Case Studies from Leading Operators like: PLUS! The agenda is packed with some real-world issues suggested by your peers. Some highlights include: Track A - Billing >> Should you upgrade or replace when re-designing your next...
- Mtel Hosted Contact Center Selected Covergence to Manage and Control SIP Trunking Session Manager provides cost savings and increased call control though deployment of a SIP trunking solution Covergence(r) announced that Mtel selected the Covergence Session Manager (CSM) to deliver a single point of policy enforcement for real-time applications used within its Whizper online contact center services. The Covergence Session Manager will enable Mtel to increase the scalability and flexibility of its on-demand hosted contact center services through utilizing the advantages of the SIP protocol between customers' contact center and their remote agents. This provides significant cost savings and eliminates the need to route calls over legacy infrastructure and the public telephone...
- WeDo technologies Debuts Fraud:RAID, a New Fraud Management System Global Business Assurance solution provider announced the latest expansion of its product portfolio WeDo Technologies announced the launch of Fraud:RAID, its new Fraud Management System (FMS). This system is the first to be designed with full client configurability, which enables users to dynamically configure their systems to target new fraud threats. This solution represents the latest addition to WeDo Technologies’ expanding business assurance product portfolio and has been designed to comply with the requirements of the telecom industry’s next generation IP fraud risk environment. Fraud:RAID has been developed on the acclaimed RAID platform, which has been successfully deployed in more...
- Vodafone Selected XINTEC FMSlite Solution for Fraud Management FMSlite, the world’s first lightweight Fraud Management System (FMS) for near-real-time roaming fraud detection, has been selected by Vodafone Malta for immediate implementation. Designed to overcome the challenges of roaming-related fraud, a phenomenon which continues to erode mobile operator revenues worldwide, the FMSlite platform is a lightweight, cost-effective and powerful fraud management system providing a complete set of collection, detection, reporting and dashboard features to ensure fraud detection and the near-real-time monitoring of mobile calls. Vodafone’s choice accompanies the mandatory introduction of near-real-time roaming data exchange (NRTRDE) on 1st October 2008 by the GSM Association, which is the industry’s global...
- Study Reveals Fraud Contributes Greatest Revenue Loss Among North American Operators Fraud and new service rollouts continue to pose challenges to operator profitability LONDON and WESTMINSTER, CO., Azure Solutions, the global revenue-assurance company, today revealed that global telecoms operators are losing an estimated 11.6 percent of revenue (over $170 billion) through fraud and other types of revenue leakage in 2005, compared to 10.7 percent in 2004. The study also shows that North American operators experience more loss than the global average, with an estimated 15.5 percent of total revenue leakage ($70 billion), compared to 14.3 percent in 2004. These are key findings from the annual research Azure conducted in conjunction with...
- Subex Azure Signs Fraud Management Contract with Safaricom Subex Azure Ltd, the world's largest vendor of revenue maximization solutions for telecom operators, has announced that it has won a contract to provide its fraud management system to Safaricom Ltd, the Kenyan mobile services provider. Safaricom is the largest mobile operator in Kenya with a customer base of 4.4 million subscribers. The number of mobile phone subscribers in Kenya has risen by 41 per cent over the last year according to the Communiciations Commission of Kenya. Safaricom wanted a scalable fraud management solution to help it reduce and identify subscriber fraud on its pre-and post-paid services. After a nine-month...
- Azure Solutions’ Fraud Control System Version 3.5 Launched Azure Solutions, the revenue-assurance company, today announced the launch of the Azure Fraud Control System (AFCS) version 3.5, which is aimed at helping combat the annual $37.9 billion problem of telecoms fraud worldwide. AFCS version 3.5 is the latest version of Azure's fraud-detection system and bureau service, which enables telecoms operators to detect fraud across their network effectively and efficiently. AFCS uses intelligent and unique detection technology, and accepts multiple data feeds to allow all types of product or service to be monitored (fixed, mobile, interconnect, IP etc). A new core addition to AFCS version 3.5 is the Exceptions Handler...
- Subex Azure Wins Telecom Fraud Management Deal with Operator in Southeast Asia Subex Azure Ltd, the world's largest vendor of revenue maximization solutions for telecom operators, has recently won a contract to provide its fraud management system to a leading telecom operator in Southeast Asia. The operator currently provides fixed-line, mobile, internet and dataservices to over 20 million residential and business customers. The operator wanted to implement a fraud management system that would enable it address new types of fraud such as interconnect fraud - fraud and malpractice between communication service providers. The Subex Azure Fraud Management Solution (SAFMS) is an advanced fraud management system, which enables telecoms operators to detect both...



