Understanding and Detecting International Revenue Share Fraud
Merve Sahin, Aurélien Francillon
Abstract
—Premium rate phone numbers are often abused by malicious parties (e.g., via various phone scams, mobile malware) as a way to obtain monetary benefit. This benefit comes from the ‘revenue share’ mechanism that enables the owner of the premium rate number to receive some part of the call revenue for each minute of the call traffic generated towards this number. This work focuses on International Revenue Share Fraud (IRSF), which abuses regular international phone numbers as the so-called International Premium Rate Numbers (IPRN) . IRSF often involves multiple parties (e.g., a fraudulent telecom operator in collaboration with a premium rate service provider) who collect and share the call revenue, and is usually combined with other fraud schemes to generate call traffic without payment. Although this fraud scheme has been around for several years, it remains to be one of the most common phone fraud schemes, reportedly leading to billions of dollars of losses every year. In this paper we explore the IRSF ecosystem from multiple angles, via: (i) A telephony honeypot that observes IRSF attempts towards an unused phone number range (i.e., a phone number gray space ), (ii) A dataset of more than 3 Million test IPRNs and more than 206K test call logs we collected from several online IPRN service providers during 4 years, and finally, (iii) A real-world call data set from a small European operator, involving 689K call records, that we analyze to find IRSF cases. By leveraging our observations from (ii), we propose several machine learning features that can be used in IRSF detection. We validate our approach on the dataset in (iii), achieving 98% accuracy with a 0.28% false positive rate in detecting the fraudulent calls.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e85f8d41-93e5-44c8-84df-2c77727e221aCited by top-tier papers4
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Jäger: Automated Telephone Call TracebackDavid Adei, Varun Madathil, Sathvik Prasad, Bradley Reaves et al.CCS 2024 · 2 citations
- Preventing SIM Box Fraud Using Device Model FingerprintingBeomseok Oh, Junho Ahn, Sangwook Bae, Mincheol Son et al.NDSS 2023
- MobileAtlas: Geographically Decoupled Measurements in Cellular Networks for Security and Privacy ResearchGabriel K. Gegenhuber, Wilfried Mayer, Edgar R. Weippl, Adrian DabrowskiUSENIX Security 2023
Builds on4
- SoK: Everyone Hates Robocalls: A Survey of Techniques Against Telephone SpamHuahong Tu, Adam Doupé, Ziming Zhao, Gail-Joon AhnS&P 2016 · 90 citations
- High Precision Detection of Business Email CompromiseAsaf Cidon, Lior Gavish, Itay Bleier, Nadia Korshun et al.USENIX Security 2019 · 68 citations
- A Machine Learning Approach to Prevent Malicious Calls over Telephony NetworksHuichen Li, Xiaojun Xu, Chang Liu, Teng Ren et al.S&P 2018 · 48 citations
- Over-The-Top Bypass: Study of a Recent Telephony FraudMerve Sahin, Aurélien FrancillonCCS 2016 · 21 citations
Related papers
- Preventing Artificially Inflated SMS Attacks through Large-Scale Traffic InspectionJun Ho Huh, Hyejin Shin, Sunwoo Ahn, Hayoon Yi et al.USENIX Security 2025
- Who's Calling? Characterizing Robocalls through Audio and Metadata AnalysisSathvik Prasad, Elijah Robert Bouma-Sims, Athishay Kiran Mylappan, Bradley ReavesUSENIX Security 2020
- Towards Measuring the Effectiveness of Telephony BlacklistsSharbani Pandit, Roberto Perdisci, Mustaque Ahamad, Payas GuptaNDSS 2018 · 36 citations
- Dark Hazard: Learning-based, Large-Scale Discovery of Hidden Sensitive Operations in Android AppsXiaorui Pan, Xueqiang Wang, Yue Duan, XiaoFeng Wang et al.NDSS 2017 · 69 citations
- Domains Do Change Their Spots: Quantifying Potential Abuse of Residual TrustJohnny So, Najmeh Miramirkhani, Michael Ferdman, Nick NikiforakisS&P 2022 · 15 citations
