In this report, we explore methods to facilitate the traceback of telecommunications and approaches to mitigate against spoofing attacks.
Prepared by external expert Eric Priezkalns for ENACT, the report provides,
- An introduction to traceback, spoofing, their relationship and links to network fraud
- The innovative methods criminals are using to go beyond traditional telephony
- The different approaches to traceback systems across the world and the organisations pursuing international traceback
- A review and analysis of current traceback mechanisms
- Recommendations on how to address the challenge
This report was prepared by the External Expert Erik Priezkalns, while the topic of the report was requested by Europol’s European Cybercrime Centre (EC3) to analyse existing and operational technical solutions to mitigate Caller-ID and Sender-ID spoofing.
Read the report: Methods to Facilitate the Traceback and Mitigate the Spoofing of Telecommunications
We’re collecting feedback on this report through the EU Survey Platform, if you’d like to share your thoughts please click on the link below.
https://ec.europa.eu/eusurvey/runner/enact-report-feedback
Executive Smmary
The tracing of communications is used to fight many kinds of crime, but its effectiveness depends on the resources that law enforcement agencies (LEAs) can dedicate to acting upon intelligence supplied by communication providers (CPs). China has extradited many thousands of scammers from overseas call centres despite not asking foreign countries to build new systems to facilitate traceback. The USA’s strategy concentrates on technology, including heavy expenditure on systems that facilitate traceback. However, the resulting number of prosecutions has been modest despite large volumes of scam calls originating on major US networks and a continued rise in the amounts lost by American consumers to scams instigated by a phone call. Europe can draw lessons from the different approaches adopted by China and the USA, including their respective strengths and limitations. In turn, Europe has much to teach the rest of the world about its own successes in tackling scams.
There is some ambiguity in what different parties mean when they discuss traceback. This leads to confusion about what is required of a traceback system. Solutions are designed incorrectly if there is no clear statement of requirements. Several respondents to our survey noted that traceback essentially involves asking CPs where a communication came from, per the records they retained. Countries have been tracing communications for many years. So, when considering how to implement a new system, we should ask what we are trying to trace, where we expect to trace it to, and what is deficient with the systems to be replaced.
The notion that a global traceback system stems from work on an allied problem: the authentication of communications.‘Authentication’ is a way of saying work has been done to prevent impersonation. Much of this work is imperfect. This report links the questions of how to tackle spoofing with how to trace communications. Tracing is more general in application. And if we know the origin of a communication with certainty, because it has been authenticated and the sender was subject to rigorous know-your-customer (KYC) checks, then ‘tracing’ that communication is just a peculiar way of saying we look at the sender’s address per the communication. Chapter 5 of this report evaluates 15 methods for authentication or tracing (or both). Considering all the options helps to clarify the strengths and weaknesses of each one.
The effectiveness of traceback methods based on hop-by-hop tracing may be limited by criminal adaptation and cross-border implementation challenges. Hop-by-hop tracing is easy to defeat on a technical level because criminals will find alternate routes for their traffic to prevent it being traced. They have decades of experience of routing international communications traffic to evade detection. Hop-by-hop tracing can also be obstructed by laws that prevent the international exchange of relevant data.
Even if all countries could be persuaded to support a global hop-by-hop method of tracing dialled voice calls, it would still be rendered redundant before it entered service because criminals would stop using dialled voice calls and start using other ways to transmit their voice.Phone users are switching to over the top services that allow them to speak and send messages to friends, family and businesses without dialling telephone numbers. So are scammers.
We should be clear about whether we want to speed up the way tracing has been done in the past – by making enquiries of each CP in turn – or if LEAs want to identify the sources of crime as directly as possible. Transmitting tracing and authentication data in-band within telecoms networks means it follows the same route as the communication, and hence incurs the risk of being interrupted at any hop. Transmitting data out of band avoids those risks because it only requires cooperation between the authorities and CPs at the origin and destination of the communication. Out of band methods are less mature at present but have a more realistic prospect of eventual success. Some individual nations are setting up out of band data exchanges between their telcos without trying to standardise for international cooperation. Meanwhile, the limitations identified in current STIR/SHAKEN implementations have prompted renewed interest in alternative approaches, including out of band SHAKEN and Open Verified Communication. The EU has an opportunity to become a technological leader in this domain by connecting the threads of this work to its eIDAS roadmap for digital ID.
European LEAs could look to the future by seeking general-purpose authentication and tracing systems that can also be applied to the newer generations of services that deliver voice and messaging communications through over-the-top and hybrid routes. This would involve out of band transfers of authentication and traceback data so the flow of data is independent of the specifics of the communication protocols implemented by the private sector. The benefit would be that a future-proofed tracing and authentication framework would ignore the increasingly artificial distinction between a voice call instigated using a dialled number or an app, or between text messages sent via SMS, RCS, WhatsApp and iMessage.
For all the focus on novel network technologies, it is easy to overlook the fact that Europe is already a world leader in tackling spoofing. The widespread adoption of ECC Recommendation (23)03 has greatly reduced the number of inbound international calls that spoof the domestic phone numbers of Europeans.Where figures are available, it is not unusual to see this control being credited for reductions in scam calls of around 70 or 80 percent. Its effectiveness greatly alters the cost-benefit argument for other controls that require different countries to cooperate. Sender ID registries are similarly effective at reducing the most common text message scams.
Some of the most effective anti-scam methods covered by this report have been put into effect in countries that have advanced anti-scam policies, such as Singapore and Australia. But Europe does not need to look to other continents for leadership. Ireland provides an example of a national strategy that has combined relatively simple measures with reported reductions in telecom-related scams.
The EU is well-placed to coordinate efforts to tackle networked crime, just as it led the telecoms and tech industries through the adoption of the GSM standards for mobile telephony, the introduction of mobile roaming, and the data privacy rules enshrined in GDPR. ECC Recommendation (23)03 is an example of recent European leadership in consumer protection; eIDAS establishes a positive future for digital ID that serves the needs of EU citizens. By first concentrating on methods that obstruct the flow of scam communications, and then implementing bilateral exchanges of data with countries that want to aid the prosecution of criminals they harbour, Europe can make the most tangible gains in reducing scams. Europe can do this by favouring the authentication and tracing technologies that already prioritise the goal of consumer protection while respecting European standards for security and privacy.