Towards Measuring the Effectiveness of Telephony Blacklists
Sharbani Pandit, Roberto Perdisci, Mustaque Ahamad, Payas Gupta
Abstract
The convergence of telephony with the Internet has led to numerous new attacks that make use of phone calls to defraud victims. In response to the increasing number of unwanted or fraudulent phone calls, a number of call blocking applications have appeared on smartphone app stores, including a recent update to the default Android phone app that alerts users of suspected spam calls. However, little is known about the methods used by these apps to identify malicious numbers, and how effective these methods are in practice. In this paper, we are the first to systematically investigate multiple data sources that may be leveraged to automatically learn phone blacklists, and to explore the potential effectiveness of such blacklists by measuring their ability to block future unwanted phone calls. Specifically, we consider four different data sources: user-reported call complaints submitted to the Federal Trade Commission (FTC), complaints collected via crowd-sourced efforts (e.g., 800notes.com), call detail records (CDR) from a large telephony honeypot [1], and honeypot-based phone call audio recordings. Overall, our results show that phone blacklists are capable of blocking a significant fraction of future unwanted calls (e.g., more than 55%). Also, they have a very low false positive rate of only 0.01% for phone numbers of legitimate businesses. We also propose an unsupervised learning method to identify prevalent spam campaigns from different data sources, and show how effective blacklists may be as a defense against such campaigns.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dcc0ee1f-14dd-4726-895f-92f9230ec9aaCited by top-tier papers6
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- UCBlocker: Unwanted Call Blocking Using Anonymous AuthenticationChanglai Du, Hexuan Yu, Yang Xiao, Y. Thomas Hou et al.USENIX Security 2023
- Are You Going to Answer That? Measuring User Responses to Anti-Robocall Application IndicatorsImani N. Sherman, Jasmine D. Bowers, Keith McNamara Jr., Juan E. Gilbert et al.NDSS 2020
- Who's Calling? Characterizing Robocalls through Audio and Metadata AnalysisSathvik Prasad, Elijah Robert Bouma-Sims, Athishay Kiran Mylappan, Bradley ReavesUSENIX Security 2020
- Characterizing Robocalls with Multiple Vantage PointsSathvik Prasad, Aleksandr Nahapetyan, Bradley ReavesS&P 2025
Builds on4
- Dial One for Scam: A Large-Scale Analysis of Technical Support ScamsNajmeh Miramirkhani, Oleksii Starov, Nick NikiforakisNDSS 2017 · 116 citations
- SoK: Everyone Hates Robocalls: A Survey of Techniques Against Telephone SpamHuahong Tu, Adam Doupé, Ziming Zhao, Gail-Joon AhnS&P 2016 · 90 citations
- AuthLoop: End-to-End Cryptographic Authentication for Telephony over Voice ChannelsBradley Reaves, Logan Blue, Patrick TraynorUSENIX Security 2016 · 40 citations
- AuthentiCall: Efficient Identity and Content Authentication for Phone CallsBradley Reaves, Logan Blue, Hadi Abdullah, Luis Vargas et al.USENIX Security 2017 · 39 citations
Related papers
- A Machine Learning Approach to Prevent Malicious Calls over Telephony NetworksHuichen Li, Xiaojun Xu, Chang Liu, Teng Ren et al.S&P 2018 · 48 citations
- Combating Robocalls with Phone Virtual Assistant Mediated InteractionSharbani Pandit, Krishanu Sarker, Roberto Perdisci, Mustaque Ahamad et al.USENIX Security 2023
- Understanding and Detecting International Revenue Share FraudMerve Sahin, Aurélien FrancillonNDSS 2021
- When Scammers Talk Back: Understanding Potentially Unwanted Calls via LLM-Based InteractionZhuoer Lyu, Marzieh Bitaab, Shuyi Huang, Alireza Karimi et al.CCS 2026
- Diving into Robocall Content with SnorCallSathvik Prasad, Trevor Dunlap, Alexander J. Ross, Bradley ReavesUSENIX Security 2023
