InGuard (Toll Fraud Guard)
Description
Toll Fraud
Toll Fraud is a term used to describe the occurrence of unauthorized calls on a PBX.
• The rise in Dial through Fraud (DTF) and VoIP security threats reported recently indicates that the
worst misuse is likely to be generated remotely by hackers who exploit any available remote access
to the customers PBX to generate expensive unauthorized calls.
• It is important to note that any customer who is affected is still liable for all such call charges and
these can be extremely expensive.
• DTF can be perpetrated via a number of access methods. Examples include: IP-PBX systems
reprogrammed remotely, SIP Trunks, SIP Extensions, DISA (Direct Inward Service Access) or
Voicemail.
• The hacker's objective is to obtain access codes and passwords/PINs that enables unauthorized
calls to be made via a customer's switch. Often, the hackers sell these details to an organized
fraudster for profit.
Toll Fraud Guard
The Toll Fraud Guard is an active call monitoring application. It works by monitoring SMDR output
provided by the PBX and applies user configured rules to look for call trends that could be deemed
fraudulent.
• When the guard detects any fraudulent activity it will send email notifications to users informing
them of the suspicion.
• The application has the ability to modify PBX configuration so that further fraudulent activity does
not takes place, it takes the following actions for the same:
- If the same extension is making a high number of calls, it can be moved to a restricted toll
restriction class to prevent it from making further calls.
- Likewise, if the Guard sees many outbound calls to the same number, it can block this number
from being dialed.
Action Mechanism
There are two stages to the blocking actions for outbound calls:
• Email alerts are first sent to warn the user about possible fraudulent activity.
• Secondly, an automatic blocking action can be carried out. This blocking action could place the
extension in a restrictive toll restriction class or block the number from being dialed.
• The Guard requires access to an email server that is enabled for SMTP and POP3; these are used
for email integration to the application. The application is accessed using a Web Browser.
Conditions
• The following Web Browsers are supported for the Guard Application; Internet Explorer 11,
Chrome™ 43.0 and Firefox 42.
Default Settings
By default, the SL2100 does not have the Toll Guard application installed.
ISSUE 1.0
SL2100
Features and Specifications Manual
1-399
I
Summary of Contents for UNIVERGE SL2100
Page 1: ...Features and Specifications Manual GVT 010794 401 00 AU ISSUE 1 0 May 2017 ...
Page 14: ...MEMO SL2100 ISSUE 1 0 R 4 Regulatory ...
Page 313: ...Operation None ISSUE 1 0 SL2100 Features and Specifications Manual 1 299 D ...
Page 412: ...Operation None SL2100 ISSUE 1 0 1 398 Howler Tone Service H ...
Page 572: ...LCR Dial LCR Dial Editing SL2100 ISSUE 1 0 1 558 LCR Least Cost Routing L ...
Page 573: ...LCR Cost Center Code ISSUE 1 0 SL2100 Features and Specifications Manual 1 559 L ...
Page 846: ...2 Press Hold key and talk with the party SL2100 ISSUE 1 0 1 832 Tone Override T ...
Page 878: ...Operation None SL2100 ISSUE 1 0 1 864 Universal Slots U ...
Page 946: ...MEMO SL2100 ISSUE 1 0 1 932 Warning Tone for Long Conversation W ...
Page 976: ...MEMO SL2100 ISSUE 1 0 3 6 Features Availability by Software Revision ...
Page 977: ...MEMO ISSUE 1 0 SL2100 Features and Specifications Manual 3 7 ...
Page 978: ...Features and Specifications Manual NEC Corporation ISSUE 1 0 ...