e.156

📋 Audit Checklist: Telecommunication Fraud Prevention

Field Security Audit // Node_Operational
Completion_Index0%

Numbering Resource Integrity (E.156 / E.164)

item_em-0

E.164 Source Validation: Confirm that all B-numbers in CDRs map to valid allocations in the itu-t E.164 Operational Bulletin. Audit the "High-Risk Destinations" list. Is it updated weekly against GSMA fraud database?

item_em-1

International Revenue Share Fraud (IRSF) Detection: Traffic Inflation Monitoring: Is there a 15-minute rollup for spikes in international call volume to high-cost destinations (e.g., Diego Garcia, Ascension Island)? Pre-Call Verification: Does the SBC perform RBT (Real-time Blacklist) checks for premium numbers?

item_em-2

CLI Spoofing & Origin-Based Authentication (OBA): E.157 Verification: Verify that the network strips invalid or non-E.164 CLI formats at the border. STIR/SHAKEN Alignment: If applicable, are incoming SIP INVITEs checked for valid identity headers (Identity/PASSporT)? Origin-Based Authentication (OBA): Audit the Charging Data Records (CDRs) for discrepant A-party labels.

Wangiri & Call-back Fraud (TR.MMWF)

item_em-3

Wangiri Pattern Recognition: CDR Analysis (Real-time): Do monitoring tools flag high-volume, short-duration (single ring, <2s) calls from unknown foreign prefixes? Callback Rate Monitoring: Is there an automated alert for subscribers calling back suspicious international missed calls?

item_em-4

Automated Mitigation: Prefix Rate-Limiting: Are high-risk prefixes automatically rate-limited at the I-GMSC when TR.MMWF patterns are detected? Voice Prompt Intervention: For callbacks to high-risk destinations, is a warning prompt (e.g., "You are calling a premium international number") active?

item_em-5

Fraudulent International Call Forwarding: Audit the HLR/HSS for unauthorized CFW (Call Forwarding) to international numbers, specifically for subscriber accounts with high credit limits.

Technical Network Hardening (E.408)

item_em-6

PBX Hacking Prevention: Confirm that all customer PBX trunking interfaces have "Anti-Fraud Triggers" (e.g., maximum concurrent calls per trunk).

item_em-7

Signaling Guarding: Are signaling protocols (SS7/Diameter) filtered to prevent "False Billing" or "Subscriber Location Tracking"? (Cross-ref Series-Q).

Restricted Mission
You are in Read-Only mode. Sign in to save progress and synchronize audit results across your devices.
TELCOSEC INITIATIVEEST. 2026 // GLOBAL STANDARDS RESEARCH

Independent, non-affiliated security research project dedicated to hardening global telecommunications infrastructure through data-driven auditing.