scieee AI-readable full text Open interactive document viewer

Towards mitigating unwanted calls in voice over IP

Muhammad Ajmal Azad

Full text

FACULDADE DE ENGENHARIA DA UNIVERSIDADE DO PORTO Towards Mitigating Unwanted Calls in Voice Over IP Muhammad Ajmal Azad Programa Doutoral em Engenharia Electrotécnica e de Computadores Supervisor: Ricardo Santos Morla June 2016 c Muhammad Ajmal Azad, 2016 Towards Mitigating Unwanted Calls in Voice Over IP Muhammad Ajmal Azad Programa Doutoral em Engenharia Electrotécnica e de Computadores June 2016 I Dedicate This Thesis To My Parents and Wife For their endless love, support and encouragement. i Acknowledgments First and foremost, I would like to express my special gratitude and thanks to my advisor, Professor Dr. Ricardo Santos Morla for his continuous support, supervision and time. His suggestions, advice and criticism on my work have helped me a lot from finding a problem, design a solution and analyzing the solution. I am forever grateful to Dr. Morla for mentoring and helping me throughout the course of my doctoral research.. I would like to thanks my friends Dr. Arif Ur Rahman and Dr. Farhan Riaz for helping in understanding various aspects of research at the start of my Ph.D, Asif Mohammad for helping me in coding with Java, and Bilal Hussain for constructive debate other than academic research and continuous encouragements in the last three years. Of course acknowledgments are incomplete without thanking my parents, family members and loved ones. I am very thankful to my parents for spending on my education despite limited resources. They taught me about hard work, make me to study whenever I run away, encourage me to achieve the goals, self-respect and always encourage me for doing what i want. I am thankful to my sisters and brothers for continuous support, prayers and encouragements. I am proud of you all and love you all very much. Most importantly, my sincere thanks goes to my beloved wife who was always there whenever I need her. She single handedly cared our two daughters and allows me to concentrate on my research. I also thank little daughters Mehar Fatima and Haniya Hussain for coming into my life and thereby bringing a lot of happiness for me. I am also thankful to my sisters (Nayyab,Seemab and Eman) for their prayers and support, and my uncle Prof. Dr. Razzaque H. Bhatti and his family for invaluable support during my bachelor and master studies. Finally, i am very grateful to all my family members, friends, and brothers who ii iii supported me directly and indirectly during this PhD work. I am thankful to Renata Rodrigues at INESC TEC and the staff at Faculty of Engineering for making arrangement for my conferences. I am also thankful to FCT (Portuguese national funding agency for science, research and technology), FEUP (Faculty of Engineering University of Porto, Portugal) and NeTs project for providing me funding for my PhD. Muhammad Ajmal Azad Resumo A tecnologia VoIP (Voice over Internet Protocol) permite a realização de chamadas telefónicas baratas através da Internet. Uma vez que a tecnologia VoIP utiliza a mesma infraestrutura de Internet para o transporte da sinalização e da voz, està sujeita a todas as ameaças de segurança que afetam a Internet. Uma dessas ameaças é o spam de voz (em VoIP chamado SPIT), que é semelhante ao spam de e-mail mas que tem consequências mais severas do que o spam de e-mail porque uma chamada de voz requer uma resposta em tempo real do destinatàrio da chamada. De modo a aumentar a produtividade dos utilizadores desta tecnologia e prevenir perdas devido à fraude a ao spam, é extremamente importante identificar e bloquear o spam antes que afete e desagrade um número potencialmente elevado de utilizadores da tecnologia. O desafio no desenho de sistemas autónomos de deteção SPIT é a utilização em simultâneo de características da chamada e da rede social que sejam difíceis de contornar pelos spammers. Para endereçar este desafio, esta tese apresenta um sistema de deteção autónomo de SPIT chamado Caller-REP que consiste em dois módulos. 1) Um módulo de reputação – que calcula a reputação do utilizador através da utilização simultânea da duração das chamadas do utilizador, do débito de chamadas do utilizador, e do número de destinatàrios únicos que o utilizador chama. O càlculo da reputação desta forma poderà atribuir valores de reputação pequenos aos spammers devido às suas redes de chamadas desequilibradas e valores de reputação grandes para os utilizadores legmos. 2) Um módulo de deteção – que, utilizando os valores de reputação, calcula de forma automàtica um limiar abaixo do qual o utilizador é classificado como spammer. iv v Spammers e geradores de publicidade à distância têm como alvo um grande número de destinatàrios que estão geralmente distribuídos por vàrios fornecedores de serviço (SPs). Os sistemas de deteção autónomos consideram informação dos utilizadores registada localmente para distinguir spammers de utilizadores legítimos. Parece óbvio que a colaboração entre SPs poderà melhorar a exatidão e o tempo de deteção mas isto depende da quantidade de informação partilhada entre SPs. Os SPs partilham informação com outros SPs de forma relutante, tipicamente porque são concorrentes e porque estão preocupados com a privacidade dos seus clientes e da sua operação. Uma abordagem para convencer os SPs é a de partilha apenas de informação sumarizada e com um sistema central confiàvel para protejer a sua privacidade. Para atingir o objetivo de colaboração atenta à privacidade entre SPs, esta tese prope COSDS (Collaborative SPIT detection System, sistema de deteção de SPIT colaborativo) que requer a colaboração entre SPs e um repositório centralizado através da partilha de valores de reputação. O repositório centralizado (CR) calcula a reputação global (GR) dos utilizadores através da agregação dos valores de reputação local e responde aos SPs com a decisão e com os valores de GR. Um adversàrio no CR estaria numa posição mais difícil para obter informação privada sobre os utilizadores e os fornecedores de serviço. Spammers e geradores de publicidade à distância poderão ter identidades de chamada múltiplas para contornar o sistema de deteção de SPIT. Estabelecer uma ligação entre identidades que pertencem a uma mesma pessoa física é importante para a identificação mais atempada de spammers e para a caracterização completa do comportamento de utilizadores legítimos com mais de uma identidade de chamada. O desafio no que diz respeito a isto tem duas partes: a ligação de identidades e o càlculo de valores de reputação para cada indivíduo através da combinação de informação das suas vàrias identidades. Para endereçar este desafio, esta tese apresenta um sistema chamado EIS (Early Identification of Spammer, identificação atempada de spammer) que utiliza características da rede social e das chamadas para interligar identidades semelhantes que pertençam ao mesmo indivíduo. A reputação é então calculada para o indivíduo em vez vi da identidade de chamada e o indivíduo classificado como spammer se a sua reputação estiver abaixo do limiar calculado automaticamente. A ligação de identidades de chamada poderà não só ser útil na deteção de spammers que mudam frequentemente de identidades de chamada mas também poderà ajudar na deteção de redes criminais. As abordagens propostas nesta tese podem, juntas, ter um impacto significativo na identificação atempada de spammers numa rede VoIP sem serem intrusivas para o utilizador nem precisarem de mudanças na semântica e na arquitetura da rede VoIP. CONTENTS xiii 5.8 Conclusions.................................123 6 EIS: Early Identification of Spammers 125 6.1 Introduction.................................125 6.2 Motivation and Problem Definition . . . . . . . . . . . . . . . . . . . . . 128 6.2.1 SpammerNetwork .........................128 6.2.2 Why Users Have More Than One Identity . . . . . . . . . . . . . 129 6.2.3 Motivation .............................130 6.2.4 ProblemDefinition.........................131 6.2.5 Background Definitions . . . . . . . . . . . . . . . . . . . . . . 132 6.3 EIS: Early Identification of Spammers through Identity linking and ReputationAggregation.............................133 6.3.1 ID-CONNECT Module . . . . . . . . . . . . . . . . . . . . . . . 134 6.3.2 ReputationModule.........................139 6.3.3 Spam Detection Module . . . . . . . . . . . . . . . . . . . . . . 141 6.4 Experimental Data Set and Evaluation Parameters . . . . . . . . . . . . . 141 6.4.1 Analysis of ID-CONNECT . . . . . . . . . . . . . . . . . . . . . 142 6.4.2 Application to Spam Detection . . . . . . . . . . . . . . . . . . . 149 6.5 Discussion and Limitations of EIS . . . . . . . . . . . . . . . . . . . . . 153 6.6 Conclusions.................................156 7 Conclusions 157 7.1 Contributions ................................157 7.2 FutureWorks ................................160 List of Figures 1.1 Subscribers Forecast for the VoIP Technology 2013-2018 [INF15]. . . . . 2 1.2 Spammer’s Network Model. . . . . . . . . . . . . . . . . . . . . . . . . 5 2.1 A Taxonomy of SPIT Detection Systems. . . . . . . . . . . . . . . . . . 20 3.1 SIPBasedVoIPNetwork........................... 40 3.2 SIP Session Establishment and Termination. . . . . . . . . . . . . . . . . 42 3.3 Block Diagram of SPIT Detection System. . . . . . . . . . . . . . . . . . 44 3.4 Social Network of Subscribers Extracted from the CDRs. . . . . . . . . . 45 4.1 Building Blocks of Caller-REP. . . . . . . . . . . . . . . . . . . . . . . . 59 4.2 Interaction Between Caller-REP and Proxy-Server. . . . . . . . . . . . . 66 4.3 Caller Distribution: A) Caller Out-Degree to In-Degree; B) Caller OutDegree to Out-Duration; C) Caller Reputation to Out-Degree Using CallerREP...................................... 71 4.4 True Positive Rate Increases with Time: A) SPIT Rate of 10%; B) SPIT Rate of 20%; C) SPIT Rate of 30%. . . . . . . . . . . . . . . . . . . . . 74 4.5 False Positive Rate Decreases with Time: A)SPIT Rate of 10%; B) SPIT Rate of 20%; C) SPIT Rate of 30%. . . . . . . . . . . . . . . . . . . . . 75 4.6 Caller-REP Accuracy: A)SPIT Rate of 10%; B) SPIT Rate of 20%; C) SPITRateof30%. ............................. 77 4.7 Caller Reputation With The Time: A) Caller-REP; B) Call-Rank. . . . . 80 4.8 Caller-REP Performance Under Legitimate Network. . . . . . . . . . . . 81 4.9 True Positive Rate Under High SPIT Traffic and β=2............ 83 5.1 Collaboration Methods: A) Non-Collaboration; B) Distributed Collaboration; C) Centralized Collaboration. . . . . . . . . . . . . . . . . . . . . 91 5.2 Building Block of Collaborative SPIT Detection. . . . . . . . . . . . . . 96 5.3 SP’s Level Working of Collaborative SPIT Detection. . . . . . . . . . . . 97 5.4 Collaborative Simulation Model. . . . . . . . . . . . . . . . . . . . . . . 108 xiv LIST OF FIGURES xv 5.5 True Positive Rate of COSDS for SP trust=1 and βthreshold=1. . . . . . 111 5.6 False Positive Rate of COSDS for SP trust=1 and βthreshold=1. . . . . 113 5.7 Detection Accuracy for COSDS and non-collaborative system for SP trust=1 and βthreshold=1. .............................114 5.8 Information Summarization and True-Positive, False Positive and Accuracy trade-off for different Collaboration Methods. . . . . . . . . . . . . 116 5.9 The Effect of Threshold βfor TP and FP Rates for 5 Collaborators and fortheFirstDay. ..............................117 5.10 System Behavior Against Spammers Having High Out-Degree and High DurationCalls. ...............................118 5.11 System Behavior Against Spammers Having Small Out-Degree and Small DurationCalls. ...............................119 5.12 System Behavior against Spammers Having Small Out-Degree and Long DurationCalls. ...............................120 5.13 Privacy Breach Analysis for Different Scenarios: A) Probability of Breach for Some Auxiliary Information at SP; B) Percentage of Subscribers whose Relationship network identified to some percentage varying number of reputedsubscriber. ..............................121 6.1 Attack Network of Spammer. . . . . . . . . . . . . . . . . . . . . . . . . 129 6.2 The Calling network of physical individual for two different time periods with two different identities ID1and ID2. .................132 6.3 Building Block of EIS System Consisting of Three Major Modules. . . . 134 6.4 The work-flow of ID-CONNECT for identity linking. The approach outputs list of all identities from CDR1which are similar to a given identity from CDR2..................................135 6.5 An example Weighted Call Graph for a given identity ID2 from T2 and two identities (ID1 and ID3) from T1. Without link weights ID2 is similar to ID1 and ID3 but when link weights are considered then ID2 is more similar to ID1 than ID3 because of similar link weights. For ease of reading, rather than showing the WGSR weight directly on each edge, we show vector (CallRateSR,∑CDSR).........................138 6.6 Performance Results for Different Threshold and Barabási-Albert. . . . . 145 6.7 Performance Results for Erdös Réenyi. . . . . . . . . . . . . . . . . . . . 146 6.8 Performance Results for Small World Network. . . . . . . . . . . . . . . 147 6.9 Performance Results for 80% Mutual Friends. . . . . . . . . . . . . . . . 148 6.10 Performance Results for 50% Mutual Friends. . . . . . . . . . . . . . . . 148 xvi LIST OF FIGURES 6.11 Performance Results for 30% Mutual Friends. . . . . . . . . . . . . . . . 148 6.12 False Positive Rate for A) Barabási-Albert, B) Erdös Réenyi, and 3) Small WorldNetworks. ..............................150 6.13 True Positive Rate for Different Overlaps in Victim Network. . . . . . . . 152 6.14 False Positive Rate for Different Overlaps in Victim Network. . . . . . . 154 6.15 Accuracy for Different Overlaps in Victim Network. . . . . . . . . . . . 155 List of Tables 4.1 ConfusionMatrix............................... 72 5.1 Subscriber Level Privacy Breach for Different Collaboration Methods. . . 106 5.2 Service Provider’s Level Privacy Breach for Different Collaboration Methods. .....................................106 xvii Abbreviations and Symbols Abbreviations ACC Accuracy Aux Auxiliary Information BA Barabási-Albert C/R Challenge/Response CallerREP Caller Reputation CAPTCHACompletely Automated Public Turing test to tell Computers and Humans Apart CDR Call Detail Records CL Candidate List CON Out Mutual Friends Connections COSDS Collaborative SPIT Detection System CR Centralized Repository CSS Candidate Set Size DDoS Distributed Denial of Service Attack DoS Denial of Service Attack DTMF Dual Tone - Multi Frequency EC Eigen Centrality EIS Early Identification of Spammers ER Erdös Réenyi FN False Negative FP False Positive FTC Federal Trade Commission HTML HyperText Markup Language ID Identity IDC ID-CONNECT IETF Internet Engineering Task Force IL Identity Linking IM Instant Messaging xviii Abbreviations and Symbols xix IP Internet Protocol ITU International Telecommunication Union MCU Multipoint Control Units MF Mutual Friends MFS Mutual Friend Similarity MGCP Media Gateway Control Protocol NGN Next Generation Network OMF Out Mutual Friends OSR Out Sim-Rank PR Privacy PSTN Public Switched Telephone Network SAS Stand-Alone System SCCP Skinny Client Protocol SIP Session Initiation Protocol SMC Multi-party Computation SMS Short Message Service SP Service Provider SPIT Spam over Internet Telephony TN True Negative TP True Positive RTP Real-time Transport Protocol RTCP Real-time Transport Control Protocol UA User Agent USA United States of America VoIP Voice over IP WG Weighted Call Graph WS Weighted Similarity WS Watts-Strogatz Symbols A Total Number of Subscribers. S Caller who initiates the call request. R Callee who receive the call request. G Call Graph G between caller and the callee. DT Direct Trust LR Local Reputation GR Global Reputation xx Abbreviations and Symbols m 25th percentile of reputation scores. T Time period. βParameter defined by SP. CR Centralized Repository OD Out-Degree CD Call Duration PiIndividual who has multiple identities. Chapter 1 Introduction Voice over IP (VoIP) - an Internet Protocol (IP)-based voice communication system is increasingly used by a large number of people along with a traditional circuit switched network (mobile, landline) for business and personal communications. In recent years, VoIP has seen an enormous growth in the number of subscribers because it offers affordable calling rates for any destination across the world. Moreover, it provides affordable value services and flexibility of using IP networks for the voice communication. VoIP market is expected to reach more than 1200 million subscribers worldwide by 2018 [CIS18] with the expected revenue of more than $77 billion [INF15]. Figure 1.1 depicts the growth of residential VoIP subscribers from year 2013 to year 2018. The number of business subscribers is also increasing at the rate of 7.58% and would reach to 244 million business subscribers by 2018 [CIS18]. The affordable calling rates of VoIP, its easy integration with the IP networks, and value added services has also created a lucrative opportunity for spammers and telemarketers to make the unwanted, bulk un-solicited calls via VoIP. In VoIP these calls are referred as SPIT (SPam over Internet Telephony (SPIT) and are mainly used for advertising products, harassing subscribers, convincing subscribers to dial premium numbers, making Vishing(voice equivalent of web Phishing) attack to get private information of call recipients etc. Spammers can also make unwanted calls to steal user’s information [NNS+07], make calls to check unsecure gateways within the service provider for the termination of bulk un-billed calls [ZWY+07], and cause disruption in the network services through flooding and denial of service attacks [EGM10,KER11]. Unwanted phone calls and instant text messages can come at any hour of the day. These unwanted calls and instant messages require immediate response from the recipient, thus annoy call recipients while at work, disturb them in their family times, and can even interrupt sleep in late hours at night. Recent statistics on telephony spam have revealed that answering a spam call would result in an estimated loss of 20 million man 1 2Introduction Figure 1.1: Subscribers Forecast for the VoIP Technology 2013-2018 [INF15]. hours for a small business enterprise in the United States with the estimated loss of about $475 million annually [SPA2015]. Moreover, FTC (Federal Trade Communication) has estimated that every year scammers and spammers causes a loss of $8.6 billion annually to citizen of USA due to frauds and majority of them are initiated from the telephone. Every year service providers, regulators, and law enforcement agencies receive thousands of complaints from consumers for unsolicited, unauthorized, and fraudulent callers trying to abuse them. In 2012, FTC (Federal Trade Communication) in USA has received four times more complaints against unwanted calls than number of complaints they received in 2010 [JEN15]. The number of identified spam callers has also risen to 162% from January 2013 to January 2014 and call center fraud has risen to 45% since 2013 [PIN16]. 1.1 Spam Over Internet Telephony Voice spam or SPIT (Spam over Internet Telephony) are the unwanted, unsolicited, prerecorded advertisement phone calls made by the spam sender to a large number of recipients that has no prior social relationship with the recipients. VoIP spammers are similar 1.2 Behavior-based Collaborative SPIT Detection System 9 Privacy-Aware Collaboration: Existing standalone SPIT detection systems consider locally recorded call logs for modeling the behavior of the users within the service provider network. The standalone detection systems lack global view of user’s behavior in other service providers or home service provider. These systems can prolong the detection of spammers that make low rate spam calls to the recipients of particular service provider, but distribute calls to the recipients of many service providers. Collaboration among service providers would naturally improve the detection time and detection accuracy, but this depends on the amount of information exchanged during the collaboration process. Service providers are reluctant in talking part in collaborating with other service providers because they are business competitors and are concerned about privacy of their customers and their internal network configuration. The challenge in the design of an effective collaborative SPIT detection systems is three-fold: first, determine what filtered information should be exchanged among collaborators so that service provider remains confident and take parts in the collaboration, second, understand with whom this information should be exchanged such that privacy of collaborating service provider is not compromised, and third, determine what information should be return back to the collaborating service providers. 1.2 Behavior-based Collaborative SPIT Detection System There exist several reputation-based detection systems that use identity of a subscriber 1 for computing reputation of the subscriber within the service provider network. The core concept in the reputation-based systems is simple that is to use the behavioral communication patterns of the subscriber and classifies subscriber as a spammer if subscriber has abnormal communication patterns. These approaches are based on the fact that spammers and non-spammers exhibit different calling behavior towards their friends and nonfriends. The reputation-based approaches have shown some effectiveness in filtering spammers in an email and the social networks [KRS+06], [LY07]. These approaches mainly considered social network features such as total number of recipients, the clustering coefficient, reciprocity and bi-directional communication patterns of subscriber in a network. However, in a voice network, call duration and call-rate are additional features that can provide additional information about the relationship strength between subscribers. In a telephony, legitimate subscriber normally exhibit repetitive calling behavior with their family members and friends with a relative long duration calls [BSG+11]. The 1subscriber, individual, users terms are interchangeable in this thesis. A subscriber can be a caller who initiates a call, can be callee who receive a call or both. 10 Introduction legitimate subscribers also receive repetitive long duration calls from their family members and friends. However, on the other hand spammers normally try to have a larger footprint by targeting large number of users that result in a large number of small duration calls and non-repetitive calling behavior. This behavior is due to the fact that spammers crawls the web or a telephone directory for their victims or randomly generate large of identities of a specific series and large number of victims are not interested in talking for a long time. In a VoIP network, the performance of behavioral-based anti-SPIT systems depend on the type of social network features used for modeling the behavior and computing reputation of the subscribers. The challenge in reputation-based approaches is to ensure that they do not involve subscriber at any stage of call processing. In terms of selection of social network features these approaches require to use number of social network features collectively rather than using a single social network feature alone. Several reputationbased approaches have been proposed for filtering SPIT callers in a VoIP network [KD07], [DK05], [WBS+09], [BAP07], [RSM06], [RS05]. These approaches compute reputation of subscribers in two steps. First, a direct trust between subscriber and his called subscribers is computed from the subscriber’s past call transactions with others. Second, a global reputation of the subscriber is computed by aggregating the direct trust scores of a subscriber. The direct trust scores between subscribers represents a level of direct relationship between them and can be computed explicitly by getting feedback from the called subscriber after the end of call transaction [KD07], [DK05], [WBS+09], or implicitly use information from the call logs recorded in the call detail records [BAP07], [BSG+11]. The global reputation represents aggregate calling behavior of the subscriber by considering the behavior of subscriber towards all interacted subscribers. Presently, the existing reputation-based SPIT filters are intrusive to subscribers which not only annoy subscribers but also required changes in a VoIP handset and signaling messages. A non-intrusive reputation-based SPIT detection system computes reputation of subscriber by extracting information from the user’s call logs for his past transactions. Call-Rank [BAP07] is a reputation-based spit detection system that computes global reputation of the subscriber by leveraging average call duration feature between subscriber and his callees, and the Eigen trust algorithm. Additionally, Call-Rank asks callee for the final decision about whether to accept a call or reject a call by relaying caller’s reputation scores and caller’s social network credentials to the callees. This approach has few limitations. First, it only leverages average call duration feature for computing the direct trust that can be prone to be evaded by the spammers targeting large number of callees and managing good duration calls with only few of them. Secondly, Call-Rank is intrusive to the caller during the stage of CAPTCHA test and intrusive to the callee during the deci- 1.2 Behavior-based Collaborative SPIT Detection System 11 sion phase. Third, it discloses social network credentials of caller to the callee that can breach privacy of the caller. Fourth, it requires public and private key infrastructure for authentication which is difficult to be implemented in VoIP telephony. In [ZG09], authors used call duration with a threshold of 20 second as sign whether caller is spamming or not. The system considered caller call as reputed if call duration of the call is greater than 20 seconds and consider caller call as a non-reputed if call duration of the call is less than 20 seconds. However, we believe spammers would easily evade such system and would also have high false positive if legitimate callers also have calls less than 20 seconds. In terms of feature usage, the existing behavior-based approaches use only one feature for the computing reputation of the caller. However, we believe that collective use of features for computing reputation of the caller would significantly improve the effectiveness of a SPIT detection system without involving caller and the callee. Our objectives for the design of reputation-based SPIT filtering system for the VoIP and voice network is threefolds: 1) it must be non-intrusive (does not require any interaction with caller and callee at any stage of call processing); 2) it collectively uses call duration, call rate, and total number of recipients of the caller for computing direct trust and reputation of the caller, and 3) it automatically learns the classification threshold below which the caller is considered as a spammer. To achieve the objective of non-intrusive, feature rich collaborative behavioral-based SPIT filtering system we argue the following: 1. Direct trust and global reputation of caller: Subscribers usually develop two types of connections over the time: strong connections and weak connections. Strong connections are established with friends, family members and colleagues with whom subscriber interacts more frequently and for a long time duration. Weak connections are established with the people with whom subscriber interacts less frequently and with the smaller call durations. Call duration and call-rate between subscriber and his friends are important features that can provide information about the strength of the trust between subscriber and his called friends. However, we believe it should not be limited to call duration and call-rate in one direction (caller to callee) but should also incorporate call duration and interaction rate in both directions. A fundamental difference in call behavior of spammers and non-spammers is that spammers normally target an exceptionally large number of callees, whereas nonspammers have limited number of called callees. The use of total number of recipients would discriminate spammer from non-spammer but using it alone might be prone to be bypassed by the spammer and also have false positives. We believe that the collective use of out-degree, call rate, and call duration in both directions for computing direct trust and global reputation of a caller would probably result in a 12 Introduction small direct trust score and small global reputation score to spammers and a high reputation scores for the legitimate users. 2. Decision and Threshold Selection: The legitimate subscribers typically have high global reputation scores because of their strong connections with their callees. On the other hand, spammers have small reputation scores due to imbalanced in their communications i.e. large number of recipients, small incoming calls and small duration calls. Existing SPIT detection approaches rely on the callee for making a final decision about acceptance or rejection of the call, which is intrusive and require changes in a signaling messages. To reduce the interaction with the callee, the detection and reaction system within the service provider need to decide automatically whether to allow or block the caller using automated threshold. Furthermore, the threshold should be tunable and scalable so that it can be easily integrated with other social network features for the improved detection accuracy. 3. Service Provider Collaboration: Intelligent and smart spammers disperse their spam calls across many service providers without overwhelming a single service provider. These small rate spammers remain undetected by the standalone SPIT detection systems for a relative long time period. However, the behavior of spammers normally remains same across all attacked service providers, thus having collaboration among service providers would possibly improve the detection time and accuracy. However, convincing service providers to collaborate is a challenging task because service providers are reluctant in sharing information that may affect their network and customer privacy. There is a strong need for a resource intensive collaborative system that convinces service providers to be part of collaboration without worrying about the privacy of their customers. 4. Identity-Linking: A high number of spammers only make few spam calls to the recipients. This is because of two facts: first the spammer acquired a large number of identities and is targeting users from his different identities; and secondly, service providers block spammers for his spamming activity. Moreover, once service provider blocks certain spammer, the spammer either whitewashes his reputation scores or starts making spamming from a new identity. Though spammers change their identities but their target remains the same and there is a possibility that spammer has overlap in targets from their different identities. The linking of different identities of spammers would help in early detection of spammers that make small rate intelligent spamming to a large number of recipients from their different identities over time. Moreover, identity linking would also help in characterizing social 1.3 Thesis Contributions 13 behavior of people with more than one identity and possibly identifies criminal’s rings. 1.3 Thesis Contributions The thesis has three major contributions. First, we address the problem of spam from the perspective of standalone service provider, second, we involve service providers to take part in collaboration for early detection of spammer, and third we propose a method for identity linking in a voice networks. The major contributions of this thesis can be summarized as follows: Standalone SPIT Detection System: A non-intrusive reputation-based standalone SPIT detection system has been proposed that uses past calling behavior of subscriber modeled from the call details record of subscriber. To achieve objectives of an effective and non-intrusive standalone SPIT detection system, we contribute the following: •We present a method for computing direct trust between caller and the callee, and a method computing global reputation of the caller in a service provider. The proposed method explicitly uses information from the subscriber’s past call transactions and computes global reputation of the caller in two steps. In the first step, a direct trust between caller and the callee is computed by using three features collectively, namely: call-rate in both directions (caller to callee and callee to caller), call duration in the both directions and total number of callees of the caller. In a second step, a global reputation of the caller is computed by aggregating the normalized direct trust score of caller with his callee using modified power iteration algorithm. The computation of reputation in this way would assign a high global reputation scores to the legitimate callers and a small reputation scores to the spammers because of their non-connected social network and large number of target callees. •We present an automatic procedure for computing dynamic threshold below which callers are considered as spammers. For the automatic threshold, we adopted a dynamic 25th percentile based threshold that is being computed for each global aggregation cycle. The threshold is scalable and tuneable according to the requirement of the service provider detection policies and can be easily integrated with other call and social network features. 14 Introduction •A model for privacy protection of caller and the callee while computing reputation of the caller from the CDRs (Call Detail Records). CDR contains sensitive information about the social relationships network of subscriber with the other and the subscriber requires absolute protection of his data and relationship information. The privacy of the subscriber is protected by sending filtered information to the reputation engine. To achieve this objective, the proposed system adopts the following: first, the task of reputation computation and the detection is carried out on an independent system separated from the proxy server or main CDRs database, and second, a filtered and anonymized CDR is exchanged with the reputation and detection system. The detection and reputation engine responds back with the final results about subscriber without disclosing his friendship network. •Telecommunication data-sets are not available to analyze the performance of a detection system. In order to evaluate the performance of propose system, a detailed synthetic model is therefore required for the generation of synthetic data-set that can characterize the behavior of spammers and non-spammers in a real telecommunication network. To achieve this objective, we developed a comprehensive synthetic model for the generation of synthetic data-set that considers social behavior of spammers and non-spammers in terms of callrates, call durations, and out-degree distribution. The synthetic data-set is generated for a number of days and for different percentages of spammers and non-spammers. Finally, the standalone SPIT detection system is evaluated for the different performance metrics that are accuracy, true positive rate, false positive rate etc. Collaborative SPIT detection System: A collaborative SPIT detection system is presented that aggregates information from the collaborating service providers without compromising privacy of collaborators and their customers. To achieve objectives of a privacy-aware collaborative SPIT detection system we contribute with the following: •A privacy aware collaborative model is presented for the exchange of information among collaborating service providers. The proposed model protects privacy of the collaborators and their customers through the use of trusted centralized repository and through the exchange of non-sensitive information to the centralized repository. The centralized repository computes global reputation of the subscriber by applying a weighted average algorithm and updates 1.3 Thesis Contributions 15 collaborating service providers with the reputation scores and classification decisions. The intruder or an adversary at a centralized repository would not be able to infer social relationship network of subscribers and would also not be able to learn private information of collaborating service providers. •A procedure for aggregation of received reputation scores from the collaborating service providers and a detection decision. The proposed procedure uses a weighted averaging mechanism for the reputation aggregation. Moreover, a procedure for the computation of trust among service providers has also been proposed. We have also analyzed the privacy breach analysis for different adversarial information. •A procedure for the generation of extended synthetic data-set which considers users behavior within their home network and the visiting networks. The model is an extension of the model presented in contribution 1 and incorporates calls among different service providers. The collaborative SPIT detection system has also been analyzed for different numbers of collaborators and for different calling behavior of spammers. Identity Linking and Early Identification of Spammer: An Identity linking system that connects multiple identities of a single individual within the service provider. In developing this, we make the following contributions: •We introduce an ID-CONNECT system, a social network and behavior based model that links similar identities that probably belongs to a one physical individual. In ID-CONNECT, the weights on the links between identities are computed from the interaction rates and length of interactions. Individuals, especially spammers normally exhibit similar call behavior and have overlap in victims from their many identities. Two identities can only be considered as similar if they have common friends have similar calling behavior towards common friends. ID-Connect is a two-step approach: firstly, it estimates the weighted similarity measure between identities by considering the call behavior of identities towards their common friends. Secondly, it generates candidate set for the given identity using fixed thresholds. •A reputation engine that computes reputation of the individual by using callrate, call duration and out-degree of the individual after connecting his identities. The input to the reputation engine is the data of linked identities formulated from the ID-CONNECT module. We believe that reputation computed 16 Introduction after linking identities of an individual and analyzing his aggregate calling behavior would greatly separate spammers from the non-spammers. •A detection module for computing automated classification threshold below which individuals are flagged as spammers. A dynamic automated threshold is being computed for each reputation cycle using the percentile based approach. •We validate and evaluate EIS system through a comprehensive simulation study using a synthetic data set that we have generated using true behavior of spammers and non-spammers. The experimental results show that EIS system outperforms other identity linking systems and has shown effective resistance against spammers having many identities. The work presented in this thesis is intended to identify and block spammers in voice and VoIP service providers. The solution is non-intrusive and can be deployed within the service provider as a standalone system without making any substantial changes in the network. Additionally, the standalone system can also be integrated with other solutions, for example Turing or CAPTCHA test as a solution for the improved detection accuracy. 1.4 Publications The results of this thesis have been presented in the following publications: 1. Early Identification of Spammers Through Identity Linking, Social Network and Call Features [Muhammad Ajmal Azad, Ricardo Morla] Submitted to Elsevier Journal of Computational Sciences (Major Revision) 2. Blocking Spammers with Information Sharing across Multiple Service Providers [Muhammad Ajmal Azad, Ricardo Morla] Submitted to IEEE Transactions on Dependable and Secure Computing (Major Revision). 3. System and Methods for Detecting Spammers in a VoIP Network [Muhammad Ajmal Azad, Ricardo Morla] To be Submitted. 4. Caller-REP: Detecting unwanted Calls with Caller Social Strength Muhammad Ajmal Azad, Ricardo Morla] In Elsevier Computers & Security, Volume 39,Part B, pp-219-236. 5. ID-CONNECT: Combining Network and Call Features to Link Different Identities of a User [Muhammad Ajmal Azad, Ricardo Morla] In The 18th IEEE Conference on Computational Science and Engineering (18th IEEE CSE, Privacy, Trust and Security Track), October 2015. 1.5 Thesis Structure 17 6. COSDS: Privacy Aware Collaborative SPIT detection System [Muhammad Ajmal Azad, Ricardo Morla] in Ist Symposium on electrical and computer engineering June 2015. 7. Mitigating SPIT with Social Strength [Muhammad Ajmal Azad, Ricardo Morla] In The 11th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) 25-27 June 2012. 8. Multistage SPIT detection in Transit VoIP [Muhammad Ajmal Azad, Ricardo Morla] In The 19th International Conference on Software, Telecommunications and Computer Networks (SoftCOM) 14-17 September 2011. 1.5 Thesis Structure The remainder of this thesis is organized as follows: Chapter 2 describes the state-of-the-art research on the spam detection in a VoIP network. We provide state-of-the-art for the following: Standalone SPIT detection systems, collaborative SPIT detection systems, and identity linking systems. Moreover chapter 2 also discusses advantages and disadvantages of existing systems and motivates for the design of our behavioral-based collaborative SPIT detection system. Chapter 3 describes social behavior of the spammers and the non-spammers. This chapter also describes call detailed records used for the generation of call graph of the subscribers and examines the behavioral features that better characterize and differentiate spammers from the non-spammers. Chapter 4 motivates and describes our standalone SPIT detection system. A standalone method is proposed for computing reputation of the subscriber through his call and social network features, and classification threshold is computed below which a subscriber is classifies as a spammer. Chapter 5 motivates the objectives and needs for the collaborative SPIT detection system. A collaborative SPIT detection system is proposed that uses trusted centralized repository and filtered information for the collaboration process. Chapter 6 presents a mechanism for connecting identities that belong to one physical subscriber. A method is proposed that estimates similarity between two identities from CDRs at two different time periods. Furthermore, the chapter discusses the effect of identity linking on the SPIT detection. Chapter 7 discusses the impact of this thesis and highlights some future research issues related to security and privacy in a VoIP and voice network. Chapter 2 Systems for Detecting Unwanted Communications in a VoIP Network In the past few years, social networks and telephony (mobile, fixed and VoIP) have become the most important form of communication media for instant messaging and interactive communications. Spam over the Internet has long been the problem in the form of email spam that results in an overall loss of tens of billions of Dollars annually. However, recently email spamming has dropped drastically [REP15] as spammers are finding new ways to target users of other technologies such as telephony and social networks with the unsolicited communications. Spamming in an interactive media such as VoIP, instant messaging and traditional circuit switched network is more annoying than email spamming as recipients are required to respond the incoming call request immediately. These unwanted calls not only effect productivity of subscribers but also causes a financial loss to the target victim. Besides gaining financial benefits, spammers also try to distribute malware to infect recipient’s mobile and VoIP handsets or to find system vulnerabilities. In recent years, VoIP telephony has shown tremendous increase in the number of subscribers because of affordable telephony rates and flexible use of Internet technology for a voice communication. It is of utmost importance for the service providers to have an effective SPIT detection system that can significantly contribute telephony subscribers from abuses and frauds. The effective detection of spammers would not only increase productivity of telephony subscribers but also improve trust of subscribers on their service providers. Several approaches have been proposed for combating spammers in a VoIP network. These approaches can be grouped into two categories: content-based SPIT detection systems and the identity-based SPIT detection systems. The content-based detection systems process the speech streams that are being exchanged between sender and the recipient for 18 2.1 Stand-alone SPIT detection 25 add noticeable delay during call setup phase because of processing of policies of subscriber and his behavior towards these policies. In perspective of spammer’s attack, policy-based system can be circumvented by spammer through spoofing the policies of the legitimate callers. 2.1.6 Legislation-based Detection Systems The primary goal of the legislation is to create a legislative framework that would make spamming illegal and impose punishment on those involved in spamming activities. European Union, USA and Canada has already made some reasonable efforts in terms of legislation against initiators of spamming [ITU15], [CJE15], [LAW15]. These legislations prohibit unsolicited communication to reach the recipient unless prior consent of the recipient is obtained. The major limitation of legislation-based anti-SPIT system is the difficulty of tracing back the initiators of spam communication for the law enforcement agencies. Moreover, if the regulator or law enforcement agencies trace-back the initiator of unsolicited communication even then there is no such global law exists that will apply to spammers across the world. Moreover, spammers make spams from anywhere around the world thus make anti-spam law of one country inapplicable to the spammer spamming from places where no such law exists. 2.1.7 Multi-Stage Detection Systems The Multi-Stage anti-SPIT systems require internal collaboration among many independent standalone systems within the service provider in order to improve the detection accuracy and detection time. The multistage systems collectively utilize information from many standalone components or systems in order to make decisions about behavior of the subscriber. In [SNT+06], authors presented two stage system that processes speech streams and signaling messages of the subscriber for blocking the SPIT caller. Similarly, in [GM08], authors presented a two stage system that is based on the CAPTCHA test and a speech processing. In [DK05], authors presented content independent multistage system consisting of three stages: 1) a Rate limiting stage – that monitors call statistics such as call rate in a certain time period, 2) a blacklist module – for including spammers in a blacklist, and 3) a multivariable Bayesian network – for inferring reputation of a subscriber from the subscriber direct trust scores with other subscribers. In [QNT+08], authors use different thresholds for computing reputation at each stage of multistage detection system. In a first stage, the system computes reputation score of the subscriber and 26 Systems for Detecting Unwanted Communications in a VoIP Network compares this reputation score against two thresholds – low and high thresholds for forwarding call to the next stage. In a second stage, the system invoke Turing test for authorization and in a third stage the system asks call recipients for the feedback about the initiator of the call. In [AM11], authors presented a four stage system for blocking spammers in a transit VoIP network using internal collaboration between many stages. In [SAS06], authors use subscriber’s short and long time call patterns and blocks spammers using collaboration among various list databases – white, black and grey list. In [MNS08], authors proposed multistage system that incorporates feedback from multiple stages while making decision about subscribers as a spammer and a non-spammers. The multistage stage system requires collaboration among well-known detection systems such as blacklists, whitelists and call statistical analysis (call duration and call rate) into a multistage SPIT detection system. It is obvious that multistage systems would provide better detection accuracy and detection time but their performance depends on the types of standalone systems used together. The content-based multi-stage systems have same limitations as of approaches based on the speech content processing. Similarly, the CAPTCHA and reputation-based systems require interaction with the caller and the callee, thus are intrusive. Another major issue with multi-stage systems is that they would introduce considerable high delay during call setup phase. 2.1.8 Call Statistics-based Detection Systems A VoIP call consists of two parts: 1) a signaling phase – a series of call setup message exchanged between subscribers and the proxy server at the time of call request, and 2) a speech streaming phase – the exchange of actual speech content between caller and the callee after the call establishment phase. The statistics-based SPIT detection systems monitor different call statistics of the subscriber that are: the call-rate, the call duration, inter-arrival time between call requests made by a subscribers, number of speech packets exchanged between subscribers, which subscribers disconnected the call etc. Several machine learning approaches have also been applied to call statistics and calling behavior of subscribers for differentiating spammers from the non-spammers [TS13]. The information from call statistics (call rate, call duration etc.) and calling behavior (number of friends, number of incoming calls etc.) of subscribers can also be used for computing reputation of the subscribers which is then used to block subscriber if reputation of subscriber is less than certain threshold. The major limitation of statistics-based approaches is learning the behavior of legitimate and non-legitimate subscribers. It would be difficult in a statistical system to differ- 2.1 Stand-alone SPIT detection 27 entiate the spammer from the non-spammer with small false positives. In perspective of spammers, statistics-based systems could be easily circumvented by spammers by controlling the similar call statistics and also by spoofing identity of legitimate subscribers. In perspective of deployment, learning a dynamic threshold for each subscriber and for each aggregation cycle is also challenging and problematic. 2.1.9 Device Fingerprinting-based Detection Systems A device fingerprint is the information that has been recorded on a proxy server or a remote computing device for the purpose of identifying devices and software used by the subscriber. The fingerprinting-based anti-SPIT systems create fingerprints for a set of devices used for making calls in a VoIP network. The fingerprinting-based approaches assume that spammers and non-spammers uses different telephony devices and communication protocol stakes for making and receiving calls. These approaches are grouped in two types: active fingerprinting and the passive fingerprinting. In active fingerprinting remote device asks subscriber for transmitting packets to remote system for device analysis, whereas in the passive fingerprinting remote device actively monitor the fingerprints of device originating the calls. In [HSZ+06], authors analyze fingerprints of several commercial hard and soft phones for different call response messages using active and passive fingerprinting. The use of device fingerprinting in real deployment is not practical and scalable as it requires management of fingerprints large number of commercial and non-commercial VoIP devices. Additionally, spammer can bypass fingerprinting-based systems by adopting fingerprints and protocol stack similar to the devices used by the legitimate subscribers. 2.1.10 Honeypot-based Detection Systems Spammers normally crawls web or telephone directory for the collection of target identities without knowing whether target identities are real or virtual. Honey phones are virtual phones not assigned to human users but are used for analyzing the behavior of subscribers making calls to them. As honey-phone is not assigned to any physical person thus naturally would not make any call to users or receive any call from the legitimate subscriber. Subscribers calling honey-phones could be spammers but confirmation requires analysis of subscriber behavior towards honey-phones [NNS+07], [GSB+15], [LCW10] and other network users. In [GSB+15], authors deploy a large scale cloud based honeypot system for analyzing the social behavior of callers making calls to these honey-phones. In [BGG+16] authors deploy a MobiPot - a honeypot mobile system for collecting the 28 Systems for Detecting Unwanted Communications in a VoIP Network fraudulent calls and SMS. These calls and SMS are then analyzed for studying the mechanism used by spammers for collecting the identities of target victims and spamming attack patterns. Honeypot-based solution can identify spammers that are targeting to them but would not be able to identify those spammers spamming other users in the network. The spammers can also bypass honeypot systems by learning the numbering pattern of honey phones or by using phone numbers of confirmed human beings. 2.1.11 Reputation-based Detection Systems Collaboration among subscribers can assist subscribers who wish to make decision about whether to receive or reject the call from the subscribers not known to them. The reputationbased systems operate in two ways: distributed – where each subscriber directly collaborates with other subscribers and a centralized system – where subscriber directly collaborates with the centralized service provider or system. Several reputation-based anti-SPIT systems have been proposed for filtering spam in a VoIP network. These systems consist of two steps: computing direct trust between subscribers engaged in communications and then aggregation of direct trust scores of subscribers for their global behavior. The direct trust represents strength of direct relationship between subscriber and his interacted subscriber, whereas the global reputation represents aggregate behavior of subscriber towards all his interacted subscribers. If trust and reputation score of the subscriber is higher than some learned or fixed threshold then subscriber is considered reputed otherwise subscriber is considered non-reputed. The direct trust between subscriber and his interacted subscriber can be computed in two ways: 1) intrusive way – that implicitly requires interaction with the call recipient of the subscriber [KD07], [DK05], [WBS+09] for the feedback about subscriber, and 2) a non-intrusive way – that explicitly utilize information from call logs recorded for the billing purposes [BAP07], [RSM06], [RS05]. The global reputation score of the subscriber can be computed in two ways: by applying Eigen Trust [BAP07] to the direct trust scores and by applying machine learning approaches such as Bayesian networks and clustering to the direct trust scores of subscriber [KD07], [DK05], Spammers normally exhibit different calling behaviors from the legitimate subscriber with the following properties: they target large number of recipients, receive calls from only few callees and many of their received or made calls are of small duration. This calling behavior normally results in a spammer’s disconnected social network with the large number of their target victims. On the other hand legitimate subscribers normally have small number of recipients, have repetitive calling behavior with many of their called 2.1 Stand-alone SPIT detection 29 callees and also receive good number of calls from their called callees. This calling behavior of legitimate subscribers results in a subscriber’s strong relationship network with many of his callees. In [BAP07], authors proposed a Call-Rank system – a reputationbased system that uses average call duration for computing direct trust between subscriber and his called callees. The global reputation of subscriber is then computed by applying Eigen trust algorithm to the subscriber’s direct trust scores. Finally, Call-Rank asks callee for the final decision (accepting call or rejecting call) by sending reputation scores and social network credentials of caller to the callee. In [ZG09], authors considered subscriber interaction with his callee as reputed if call duration is greater than 20 seconds. In [COB+11] authors used call duration along with seven degree separation as a social network feature for the computing of reputation of the subscriber across the network. In [BSG+11], authors proposed three reputation-based solutions for filtering SPIT subscriber. In the first approach, they used concept of strong and weak social ties among subscribers, in the second approach, they enhanced Progressive Multi Grey-Leveling list to the Enhanced Progressive Multi Grey-Leveling by using call density and reciprocityindex features, and in the third approach, they adopted Page-Rank algorithm for computing global reputation of the subscriber. The direct trust between subscriber and his callees can also be computed by collecting feedback (positive or negative) from the callee for the subscriber’s call transaction which just ended. In [WBS+09], authors computed reputation of the subscriber aggregating callee’s feedback about the subscriber’s calls. The reputation scores and call statistics of subscriber are then used along with MPCK-Mean – a semi supervised clustering algorithm for clustering subscriber into SPIT and non-SPIT clusters. The proposed system performs well only when callee provides honest and accurate information about the caller. In [KD07] and [DK05] authors proposed a multistage system for the identification of spammers. The system consists of three stages that collaborates with each other: the direct trust stage computes direct trust between subscriber and his callees by aggregating feedback from the callee for the subscriber call, the global reputation stage that computes reputation by applying Bayesian network algorithm to the direct scores of the subscriber to all his callees, and the list database that maintains list of black and white listed subscribers. In [PD09], authors proposed an approach that aggregates callee feedback along with G-mail spam filtering method for blocking the spammers. In [PGK+08], authors proposed two approaches based on the content processing and feedback aggregation about behavior of the subscriber from his callees. In [SDN+09], authors computed reputation of the subscriber through a web of trust model between subscriber in a network. In [GYH08], authors proposed a multilayer system that incorporates behavioral characteristics of subscriber and his call signaling messages. One of the major limitations 30 Systems for Detecting Unwanted Communications in a VoIP Network of intrusive reputation approaches is their intrusiveness and also requires change in a VoIP handset and call signaling messages. Moreover, spammers can easily circumvent intrusive approaches by creating network among his identities and providing fake responses for their identities. Reputation based anti-SPIT systems have shown great effectiveness against spammers in email and VoIP network but their effectiveness depend on the set of features used for the computation of global reputation. In some cases, spammer could get high reputation scores by creating a Sybil network between his acquired identities and also spoofed identities of the legitimate subscriber for spamming and getting the high reputation scores. The CDR based-reputation systems minimize the effect of Sybil attack but its performance depends on features used for the computation of global reputation scores. The spammer normally targets large number of callees without repeating his callees thus normally results in a small duration calls to a large number of callees and good duration calls to only few callees. In non-repetitive calls, the average call duration of caller with the callee is same as of his aggregate call duration. This behavior might results in a high reputation scores for the subscribers having good duration calls to a large number of their called callees. Moreover, spammers can also collude among their several identities with good duration calls that would also increase spammer’s global reputation. In some CDR-based approaches, the global reputation score and social network credential of the caller are also sent to a callee for the final decision [BAP07] which is not only intrusive to the callee but also poses threat to the privacy of the caller. 2.2 Collaborative Detection Systems Spammers always try to find ways for evading the spam detection systems. They manipulate contents by adding noisy messages, acquire large number of identities for colluding and Sybil attack, and controlling number of spam calls to a single service provider but target many service providers in parallel. Spammer can make a large number of spam calls in aggregate from a given calling identity but distribute calls among many service providers. Existing anti-SPIT system decides about behavior of the subscriber based on his calling behavior observed at a single service provider. These approaches prolong detection time and block spammers only if spammers make significantly large number of spam calls to a single service provider. The non-availability of calling behavior of spammers across the service providers limits standalone system to react effectively against spammers. The calling behavior of subscriber becomes more meaningful when subscribers are observed across many service providers. Naturally, collaboration among service providers 2.2 Collaborative Detection Systems 31 would improve the detection time and detection accuracy because of collective use of information about behavior of subscriber from many autonomous collaborating service providers. Service provider or domain collaboration has been applied in various networking domains for identifying malicious intruders and spammers in a network. In this section, we provide detailed discussion on the collaborative systems in the perspective of SPIT and emailspam detection systems. 2.2.1 Collaborative SPIT Detection In order to evade the standalone systems, spammer targets large number of recipients that are dispersed across many service providers but his calling behavior remains same across all service providers. Collaboration among service provider is a natural way for early detection of spammer before they spam a large number of recipients. However, a very few works have been reported that incorporate collaboration among service providers for rating the subscribers. In [IMS2015] and [3GPP2015], 3GPP a standardization body on next generation network formalized best practice standards for fighting spammers in a VoIP and IMS networks. Particularly, they encouraged service providers to have collaboration among themselves for early and effective IM (Instant Messaging) and voice spam detection. However, this technical standard does not provide any information about how collaboration is to be carried out. In [SLS+10], authors exchange scorecards of subscriber among collaborating service providers and collaborating service providers react independently against the subscriber’s scorecard whether to allow or block the subscriber. This framework requires predefined trust relationship between collaborators which is practically not feasible in a telecommunication network. Additionally, no mechanism has been presented for the computation of subscriber score and trust assessment of collaborators. In [SS09], authors proposed a collaborative system where the home service provider collaborates with the visiting service provider with the exchange of information about their SPIT detection system in the form of call tags. The visiting service provider then access the performance of SPIT detection system deployed in a home service provider of the subscriber calling recipients of his network. This approach has some limitations: 1) it only evaluates performance of a SPIT detection system deployed in a service provider that provides the tag information, 2) it requires establishment of predefined trust between collaborating service providers, and 3) it requires change in the call signaling messages exchanged between collaborating service providers in order to incorporate tag information. In [WAB+09], authors proposed SPACEDIVE that detects intrusion in a VoIP network by correlating local and remote information from many collaborating service providers. In [WMH07], authors presented P2PAVS that computes reputation of subscribers through 32 Systems for Detecting Unwanted Communications in a VoIP Network collaborative response from the subscriber from many service providers. However, it does not provide any mechanism for the propagation of trust among subscribers. In VoIP normally collaboration is achieved in the form of multistage systems or collaboration among proxy servers within the service providers. In [SKE+14], authors proposed an approach that uses collaboration among several local VoIP servers within the service provider. However, mechanism for collection and aggregation of feedback among subscriber and proxy server is not provided. 2.2.2 Collaborative Spam Detection in Email Network A number of collaborative systems have been proposed for filtering spammers in an email network and detection of intruders in the IP-based networks. In perspective of email networks, the collaborative systems normally require collaboration in the form of exchanging spam message contents, spam HTML (Hyper Text Markup Language) tags and exchanging feedback about behavior of particular sender. Normally spammers send same spam message to a large number of recipients and collaboration with the message content would greatly improve the spam detection time but it poses threat to the privacy of email users. In [LZR09], authors presented a privacy-aware collaborative system called ALPACAS that invokes collaboration among service provider with the exchange of encrypted fingerprints of message contents. The similarity between fingerprints of user messages and messages stored in the database of ham and spam is estimated in order to classify the new message as a spam or a ham. HTML tags are available within the email headers and can be used to distinguish spam content from the non-spam. In [YPC+11], authors presented a COSDES system that collaborates with the exchange of HTML tags and computes distance between spam and ham tages using near duplicate approach. In [FZN06], authors presented a collaborative framework that requires distributed collaboration for making decisions about users. The collaborating email domain directly exchange information to each other and imposes some restrictions on domains not taking part in a collaboration process. The behavior of spammer remains same in all target service provider or domains and when analyzed collectively would decrease the detection time. In [RFV07], authors proposed a system called SpamTrackers that requires collaboration among domains with the communication behavioral patterns of email senders within collaborating domains. In a [DVP+04], authors presented a three layerd P2P architecture based on communication patterns of spammers and non-spammers. The architecture requires collaboration among end-users, mail service and the super peers. The super peer handles the exchange of message among themselves for tagging and classifying incoming mail digest as a spam or a 2.3 Identity Linking 33 non-spam. In [SBK07], authors presented RepuScore that require collaboration among email domains with the exchange of local reputation score of email sender within the domain. In RepuScore, a centralized system computes global reputation of user by aggregating local reputation scores. In [SKY11] and [CLO16] authors proposed social filter, a centralized system that aggregates feedback from individual spam detection systems for early detection of Phishers and spammers. Collaboration can also be carried out directly among end-users. In [KRS+06], authors presented a collaborative spam filter that uses collaboration and social network information of users for blocking spammers. In [CDN05], authors proposed two spam detection systems: a simple Mail-Rank and a personalized Mail-Rank that computes global reputation of email user by aggregating direct trust score through power iteration algorithm. Spammers are moving to different online social networks for increasing their footprint. The collaboration among different social network platforms would greatly improve the detection accuracy and detection time. In [WIP11], authors proposed a system that incorporates collaboration among different online social network platforms with the exchange of spam contents to be used for effective spam detection. All of the above proposed collaborative approaches classify incoming email into spam or non-spam by analyzing the contents of messages, contents of HTML tags and static rule for some features. These approaches cannot be applied directly for filtering spammers in a voice networks. In a voice network, contents are available in the form of speech signals and having collaboration with the exchange of speech signals is not feasible. Moreover, it requires sophisticated system and network resources for speech processing, storage and matching. In case of non-content-based collaborative approaches, the detection approaches utilize structure of the network while ignoring the weights on the links between users. In a voice network, few additional features such as call rate and call duration could provide information about relationship strength among users and should be used in a collaborative way. 2.3 Identity Linking There are many countries where number of subscribers exceeds the country population. For example Russia has 1.8 percent more mobile subscriber than its population, similarly Brazil has 1.2 percent more subscriber than its population. These numbers are not attributed to the fact that every citizen has one identity but attributed to the fact that many individuals have more than one calling identity. As VoIP offers cheap telephony rates 34 Systems for Detecting Unwanted Communications in a VoIP Network and acquiring new identity in a mobile and VoIP network is not costly that’s why spammers are exploiting VoIP network with the spamming activities from many identities. The spammer normally makes controlled attack from all his identity or rejoin network with new identity if blocked by the detection system. Moreover, spammer’s identities also collude with each in order to have high reputation score so as to remain undetected. The standalone and collaborative SPIT detection systems are able to identify such spammers that are making large number of calls from their each identity. The spammer can change his identity once its blocked by the service provider and targets user with new identity with same motive. However, connecting or linking multiple identities that belong to one physical person would greatly decrease the detection time and would improve the detection accuracy. Identity linking would also help in characterizing the complete behavior of physical user having multiple calling identities for other purposes such as recommendation and marketing of other value added service. To the best of our knowledge, we have not found any such study that has been carried out for linking multiple calling identities of the a physical individual in a voice network. For this reason, we are providing works that have been done for linking multiple identities of user across same or different online social networks. Normally, an active social network user or Internet user has multiple accounts across different social network or same social network with same or different identity. Current statistics show that 20% of facebook users also have twitter account and 91% of Twitter users also use Facebook to stay in touch with others [PER09]. In online social network like Facebook, twitter or Instagram etc. profiles are linked together by estimating similarity between identities in three dimensions. Firstly, profiles can be linked together by matching the profile information provided by the user at the time of creation of account across different social networks; secondly, profiles are matched by estimating the similarity in content posted by the user across different social networks; and thirdly, profiles are linked together by using information from friend’s network of users from different social networks. In [RCD10], authors considered three dimensions and presented an identity linking framework that links similar profiles together that belongs to one physical individual. In [VHS09], authors proposed a system that links profiles of users by estimating the similarity in profile information represented in a profile vector. Moreover, authors also identify number of significant features that better characterize the profiles of the same user. In [NCM12], authors represented user’s profile information as a feature vector and applied supervised machine learning (Support Vector Machines, Random Forests and Alternating Decision Trees) for making decisions about identities that belongs to one physical individual. 3.2 System Overview 41 speech signals between them. The SIP based VoIP network consists of two major components: the SIP User Agent (UA) and SIP Network Server. The SIP UA is the user soft or hard phone responsible for initiating and accepting calls. SIP Network Server manages signaling sessions among participating entities and consists of three main functional components: the SIP Registrar, the SIP proxy server and the SIP redirect server. SIP exhibits request and response model for the session management among communicating entities. Request messages are sent from the user to the Registrar server for the registration, call request messages are exchange between end users for the start of new session, updating the parameters of existing session, acknowledging session establishment between users and terminating the existing sessions [RFC3261]. Response messages are used for providing the appropriate reaction to the request messages, depending on the type of request message. Figure 3.2 represents the exchange of signaling messages used for call management between end-users and core VoIP network. The SIP based VoIP network also consists of other supporting servers such as: a CDR server for storing Call Detailed Record of users call transactions, billing system for billing and presence servers for storing the location and status of users. In addition SIP and H.323 protocols, VoIP networks may use other protocols establishing, terminating and managing the sessions. These protocols includes: SCCP (Skinny Client Protocol)– a CISCO proprietary protocol used by CISCO IP phones and CISCO call manager, a MGCP (Media Gateway Control Protocol)– for controlling media gateways on a VoIP network and an ITU MEGACO (Gateway Control Protocol) for providing interconnection between traditional public switched telephone network (PSTN) and modern packet networks. For the transport of speech streams or voice signals, The Real-time Transport Protocol (RTP) and Real-time Transport Control Protocol (RTCP) are widely used in a VoIP network. VoIP transports signaling and voice over an IP network thus vulnerable to the security threats already affecting IP network. These attack includes: Voice Phishing (Vishing), VoIP Spam (SPIT), scanning operator’s configurations for toll fraud, Dos and DDos attacks, billing attacks etc; and not only affect the performance of VoIP network but also causes serious discomfort to the end-users. 3.2 System Overview The architecture of our proposed collaborative, social reputation-based anti-SPIT system is shown in the Figure 3.3. The system consists of three parts: the standalone detection system, the collaborative system and the identity linking system. Of three parts, two 42 SPIT Detection System Based on Social Reputation Figure 3.2: SIP Session Establishment and Termination. parts operates independently, whereas the third part requires collaboration among independent standalone systems placed in different service providers. The intuition for this design choice is based on three observations. 1) Spammers and non-spammers normally exhibit different calling patterns towards their callees. We make use of this difference in the calling behavior of spammer and non-spammer and present an approach that uses call and social network features for making decision about behavior of the subscriber in a service provider network. 2) Spammers normally slowly make calls to recipients of many service providers; however, their behavior remains same across all service providers. For early identification of the spammer, we incorporate collaboration among service providers without having any threat to privacy of subscribers and service providers. 3) Spammers only make few spam calls from one identity and if blocked by the detection system rejoins the network with a new identity. However, spammers have some overlap in the 3.2 System Overview 43 target recipients of his different identities with more or less similar calling behavior. We incorporated identity linking procedure to the link the similar identities that belong to one physical individual and then computed reputation of an individual rather than calling identity. All systems process information from the CDR for the construction of call graph of subscribers and perform certain computations without having interaction with the subscriber. Each system of design approach is described as follows: Standalone SPIT Detection: The Standalone system can be placed in a service provider networks and uses a mechanism that uses subscribers social and call network features for identification of spammers in the network. The standalone system is based on the intuitions that legitimate subscribers normally have long duration calls with many of their called callees thus develop strong social connections with many subscribers and have weak social connections with only few subscribers. On the other hand spammers normally call large number of subscribers which more often results in a large number of small duration calls to many of his callees. This calling behavior thus develops a strong social connection with only few subscribers and has a weak social connection with the large number of subscribers. We incorporated behavioral patterns of subscriber for computing reputation of the subscriber with in the network. The system finally classifies subscriber as a spammer and non-spammer based on reputation scores and automated threshold below which subscriber are flagged as spammer. We called standalone system as Caller-REP (Caller-REPutation) and Chapter 4 provides further details on the approach used within Caller-REP system and its deployment in a real network. Collaborative SPIT Detection: The collaborative system in a proposed system is termed as COSDS (COllaborative Spit Detection System). COSDS perform its operation by have privacy-aware collaboration among independent standalone reputation systems deployed in the service provider network. The COSDS system is based on the following observations: 1) spammers distribute low rate spam calls to subscribers of many service providers without overwhelming any single service provider with a high rate spamming. 2) The behavior of spammers remains same across all service providers. Having collaboration among service providers would greatly improve the detection accuracy and decreases detection time, but it has challenge of convincing the service provider to be part of collaboration process. Service providers are not willing to take part in the collaboration because to them collaborating with peer service provider means exchange of information which might be threat to the privacy of their customers and its network configurations. However, use of trusted centralized repository and exchange of non-sensitive filtered information to the centralized repository would somehow convince service provider for taking part in the collaboration process. Chapter 5 provides further details on the design of a privacy-aware collaborative detection system that involve collaboration among service 44 SPIT Detection System Based on Social Reputation Figure 3.3: Block Diagram of SPIT Detection System. providers without making any threat to privacy of subscribers of collaborating service provider. Identity linking and Spam Detection: The third component of proposed system is termed as EIS (Early Identification of Spammer) – an identity linking and Spam detection system that uses call and social network features of identities to connect similar identities together and perform spam detection process. The intuition for the design of EIS system is based on the following observations: 1) spammers frequently change their identities in-order to remain undetected and 2) spammer has overlap in a call network among his several identities with more or less similar call patterns. The linking of identities that belong to one physical individual would identify the spammers having multiple identities in a timely way. Chapter 6 provides further details on the design of EIS system and its effect on the identification of the physical spammers having multiple identities. 3.3 Call Detail Records Telecommunication service providers (VoIP, Mobile, and Legacy Telephony) records call transactions of their subscribers in a Call Detail Record (CDR) that are basically used for 3.4 Social Call Graph 45 Figure 3.4: Social Network of Subscribers Extracted from the CDRs. billing purposes and network management. Service providers can utilize these call records for characterizing the behavioral patterns of their subscribers for other purposes such as marketing, personalized offering of new products and identification of malicious users targeting legitimate subscribers. CDR normally contains meta-data of call transactions without any recorded speech contents. A typical CDR widely consists of many fields but of them few are enough for characterizing the behavior of the user. These fields are: identities of a subscribers involved in a call (Caller and the Callee), time of call when subscriber initiates the call to the callee, time when call disconnected by caller or the callee, duration of a call, who disconnected the call, call type (voice, SMS,MMS) and status of the call (successful or failed) etc. In this thesis, we modeled behavior of the user using four fields and construct a weighted social graph of the subscriber. These fields are: calling identity of the caller and callee, time of the call and the call duration. 3.4 Social Call Graph Since CDRs stored detail information about call transactions (incoming and outgoing call) of the subscriber but are normally available in a raw form. The raw call records need to be 46 SPIT Detection System Based on Social Reputation processed in order to have meaningful information for business intelligence and identification of malicious subscribers abusing other subscriber or service provider for financial benefits. A complete weighted call graph Gof the subscriber is required for analyzing the behavior of the subscribers towards others. A weighted call graph Gis represented as G(N,E,W)which is generated for each identity or subscriber present in the raw call records. In G(N,E,W),Ndenotes the set of vertices representing the VoIP subscriber which can be either caller or the callee or both, Edenotes the a set of links between subscribers, and Wdenotes the weights on the links representing social strength between subscribers. The Ncan be either Caller Sor a Callee Rwhere (S,R)∈A. Specifically, if S is the caller and Ris the callee then an edge exists between Sand Rif Sand Rinteracted with each other at-least once. Social call graph can be directed or the undirected depending on the type of network. The direction of the link determines whether call is outgoing call from the subscriber or the incoming call to the subscriber. The weights on the links can be assigned from the callAn example call graph of subscribers from the CDRs is shown in a Figure 3.4 and is represented as a sparse adjacency matrix, where 1 represents that caller Shas interacted with callee Rand 0 represents that there happen no interaction between caller and the callee. A sparse adjacency matrix Aof subscriber is represented by an nxn adjacency matrix A with elements as: Ai j =   1 if i interacted with j 0 no interaction (3.1) In-case of weighted call graph, Ai j are replaced by the weights determined from the frequency of interaction and call duration of interactions. In this thesis, a weighted call graphs is constructed by extracting the following three parameters from the call records for the specific time period. Call Duration: Call Duration represent the time two subscribers spoke to each other. Specifically, out call duration of caller Sto a callee Ris the sum of duration of all calls made by caller Sto callee Rand incoming call duration of caller Sis the sum of duration of calls Sreceived from callee R. The aggregated call duration, therefore is the sum of call duration of all calls made and received by the subscriber A. Call-Rate: Call-Rate represents the frequency of interaction between caller and the callee. Specifically, out call rate between caller Sand callee Ris the sum of all calls made from caller Sto callee Rand in call rate of Sis the sum of calls made by Rto S. The aggregated call-rate, therefore is the sum of all calls made and received by the user A. Partners: Partner is the total number of unique subscriber a certain subscriber initiated calls to or received call from and can be grouped into incoming and outgoing partners. 3.5 Social Network Features 47 The incoming partners of caller Sis represented as PIS and out-going partners of caller S is represented as POS. The out-going Interactions represents that user is more important to the certain user than those he did not initiate any call. The goal in this thesis is to compute the direct trust and global reputation of the subscriber from the weighted call graphs Gand then classifies subscriber as a spammer and a non-spammer. 3.5 Social Network Features People use telephony for the interactive communication with each other and develop weak and strong social relationship with others over the time. Spammers also try to exploit the telephony network for financial intent (e.g. marketing of products, adverting, visihing, frauds etc.) and also develop strong and weak social network with many users. However, the social behavior of legitimate subscriber is different from the social behavior of spammers when analyzed in perspective of different social network and call features. This section presents social and call characteristics of subscriber that can help in differentiating spammers from the non-spammers. We outline calling behavior of spammers and nonspammers for the following features: number of callees the subscriber calls, number of callees calling the subscribers, call duration of subscriber’s incoming and out-going calls, incoming and out-going call rate of the subscriber, centrality measure and reciprocity measure of the subscriber. 3.5.1 Degree One of the most important structural measures of a subscriber in a social call graph is the degree of the subscriber. The degree of a subscriber in a social call graph is sum of subscribers he received and made calls. In a directed social call graph, the subscriber can have two degree measures: the out-degree and the in-degree. The out-degree of a subscriber iin an adjacency matrix Ais the sum of the row entries and the in-degree of subscriber iis the sum of the column entries associated with the subscriber iand can be represented as: Out −degreei = n ∑ i=1 Ai j (3.2) In −degreei= n ∑ j=1 Aji (3.3) 48 SPIT Detection System Based on Social Reputation Where Ai j =1 if there is an outgoing link from subscriber ito subscriber j, and zero otherwise. Similarly, Aji =1 if subscriber jhas out going link to subscriber iand zero otherwise. In case of a weighted network, the out-degree and in-degree is simply sum of weights of rows and columns of the subscriber i. The degree of the subscriber can also be represented as the degree distribution which is the probability distribution of the subscriber’s degree over the degree of a whole network. Many real networks such as World Wide Web [NEW05a], phone call graphs [NSC+08], [NGD+06], network of autonomous IP systems [FFF99] and online social network [MMG+07] exhibit a powerlaw degree distribution. It might be possible that inclusion of a large number of spammers in a network would divert the degree distribution from a power-law degree distribution [MOT12]. In a VoIP and voice networks, spammer normally calls large number of subscriber and hardly receives calls from a very few recipients thus has unbalanced out-degree and indegree structure. On the other hand, legitimate subscriber calls limited number of callees and normally receives calls from many of his callees thus results in a balanced out-degree and in-degree structure. The threshold on an out-degree and in-degree could be useful for blocking spammers [LY07], but using one feature (small in-degree or high-degree as sign of spamming) alone would result in a high false positive rate and small true positive rate. For example, using high in-degree as a sign that subscriber is legitimate would result in a blocking of some legitimate subscriber such as call centers and organizations having small in-degree but have high number of long duration out-going calls. Similarly, using small out-degree as a sign that subscriber is legitimate would block the legitimate subscriber having high out-degree with high duration calls as well has high in-degree with legitimate behavior. It is important that spam detection should not be limited to the degree distribution (in-degree and out-degree) but is also required to consider degree feature along with other call and social features such as call-rate, call duration and centrality. 3.5.2 Call-Rate Call-Rate is the sum of total number of calls made or received by the subscriber. CallRate can also be grouped into two types: in-coming call rate and out-going call rate. A high number of calls between two subscribers represent that they are strongly connected with each other. The in-coming and out-going call rate of a caller Swith a callee Rcan be computed as: Out −CallRate(S→R) = ∑Calls f rom S to R (3.4) In −CallRate(S←R) = ∑Calls f rom R to S (3.5) 3.5 Social Network Features 49 The aggregate out-going and in-coming call rate of the subscriber iis represented as: Out −CallRate(Ai) = n ∑ i=1 CallRatei j (3.6) In −CallRate(Ai) = n ∑ j=1 CallRateji (3.7) Where CallRatei j is adjacency matrix of call-rate of subscriber ito his called callees j. A legitimate subscriber normally has repetitive calling behavior with the large number of subscribers (family, friends) and has non-repetitive calling behavior with the few subscribers (strangers). On the other hand spammers or compromised calling identities would like to reach as many subscribers as possible without repeating a target thus develop a non-repetitive network with many subscriber. A large number of target victims and non-repetitive calling behavior with the large number of called victims can be a strong indication that subscriber is spamming. However, using a call rate feature alone would result in a high false positive and small true positive. For example non-legitimate debt collectors make calls to same recipients for payment of debt or a spammer making spam calls to same subscriber to convince on certain offer. Therefore, it is necessary to use the call rate feature along with other call and social network features. For example using ratio of out-degree and out-call rate. Spammers normally have this ratio near to one while legitimate subscribers would have this ratio near to 0.5 or less than 0.5. 3.5.3 Call Duration In telephony, the call duration is the length of duration subscribers talked to each other and can also be grouped into in-coming call duration and out-going call duration. The out-going call duration of subscriber represents how much subscriber trust and want to talk to other subscriber and in-coming call duration of a subscriber represent how much other subscriber trust and talked to the subscriber. The call duration and call-rate together characterize the strength of social ties between the subscribers. The higher the call-rate and call-duration between subscribers, the stronger the social tie exist between subscribers and smaller the call-rate and call duration between subscribers, the weaker the social tie exist between subscribers. The in and out-call duration between caller Sand the callee R can be represented as: Out −Call −Duration(S→R) = ∑Talk time f rom Sto R (3.8) 50 SPIT Detection System Based on Social Reputation In −Call −Duration(S←R) = ∑Talk time f rom Rto S (3.9) The aggregate out and in duration of a caller Sis represented as : Out −Call −Duration(Ai) = n ∑ i=1 TalkTimei j (3.10) In −Call −Duration(Ai) = n ∑ j=1 TalkTimeji (3.11) Where TalkTimei j is the adjacency matrix of call duration of subscribers. Similarly, the average in and going call duration of the caller is represented as: Avg.In −CallDuration(Ai) = ∑n i=1TalkTimei j ∑n i=1CallRatei j (3.12) Avg.In −CallDuration(Ai) = ∑n j=1TalkTimeji ∑n j=1CallRateji (3.13) Call duration or average call duration is an important feature for estimating the strength of social relationship between subscribers and is also useful for characterizing the behavior of the subscriber in a network. Legitimate subscribers normally have some good number of long duration calls with his friends, family members and colleagues, and have relatively small duration calls with only few callees for example strangers. On the other hand call recipients are not comfortable talking with unknown subscriber for the long time periods thus disconnect call as soon as they realized the true identity and motivation of the caller. Because of this behavior, spammers normally have large number of short duration calls with their recipients with only small number of long duration calls. However, small duration is not the only sign caller is spammer for example a school announces a short duration urgent announcement to a large number of student. The use of call duration along with call-rate and out-degree of subscriber would provide enough evidence to classify a subscriber as a spammer and a non-spammer. 3.5.4 Eigen Centrality Eigenvector centrality measures centrality of a subscriber in a call graph by computing eigenvector of the largest positive eigenvalue. Eigenvector provides information about 4.3 Caller-REP:Caller Classification-Based on Reputation 57 4.3 Caller-REP:Caller Classification-Based on Reputation This section describes requirements for the reputation-based SPIT detection system and data source used for non-intrusive SPIT detection system. Moreover, this section also describes components and algorithms of a Caller-REP system. Finally, we have also compared Caller-REP system with other reputation-based systems. 4.3.1 Requirements for Reputation Based SPIT Detection System Before describing our reputation-based SPIT detection system, it is important to point out few requirements for the design of an effective SPIT detection system based on the trust and reputation of subscribers. •The computation of direct trust between subscribers and the global reputation of the subscriber must not involve subscribers for the feedback at any stage of call processing thus must have ideally zero subscriber’s involvement. •The computation of the reputation and the direct trust of the subscriber needs to consider the subscriber’s past call transactions within the network along with the collective use of social and call features. •The proposed system must be robust against different malicious attacks such as Sybil attack and must not be easily circumvented by the spammers. •The system must carry out all computation in anonymized way in order to protect the privacy of network subscriber. •The overall system must not require any changes in the network or handset of the subscriber. •The system must be tune-able in terms of classification threshold according to requirement of service providers or carriers and can be easily integrated with other systems. 4.3.2 Data Source A VoIP service provider consist of a large number of networking devices that work together for providing telephony and messaging services to its subscribers. Each call transaction either received or made by the subscribers is recorded in the call logs at the proxy servers or call handling engine, that are later pushed to the CDR server for the billing and troubleshooting. The logs contain several fields providing information about the call 58 Caller-REP: Detecting Unwanted Calls Through Caller’s Social Strength transaction. The time-stamp provides information when call between subscribers established , call duration represent the how much time two subscribers talk to each other„ caller id reflects the calling identity of subscribers. Besides these fields, the CDR may also logs IP address of caller and the callee, type of call (SMS, voice or MMS), who disconnected call etc. In order to compute global reputation of the subscriber, we construct a directed call graph between subscribers by extracting the following information from the CDR logs. Call Duration: Talk time of the subscriber with his called callee. The subscriber can be either caller or the callee. We are mainly interested in characterizing behavior of subscriber as a caller. We represent call duration between the caller Sand the Callee Ras CDSR which is the sum of duration of all calls made from a caller Sto the callee R. Call Rate: Call-Rate is the number of calls made and received by the caller. We present call rate between caller and the callee as CallRateSR and is the sum of calls made from the caller Sto a callee R. Partners: Partner is the number of unique callees a caller has interacted or received calls from. We represent number of out partners as a POSwhich is the sum of unique callee a caller Sis calling. Our goal is to use information from directed call graph and develop a SPIT detection that classifies subscriber as a spammer and a non-spammer based on reputation of the subscriber. The block diagram of a Caller-REP is shown in a Figure 4.1. Specifically, after modeling the call graph from the CDRs, Caller-REP consists of three steps for classifying subscriber as a spammer and a non-spammer: 1) it computes direct trust of the subscriber with his called callee using social network and call features, 2) It computes global reputation of the subscriber using power iteration algorithm, and 3) It automatically computes the threshold below which subscriber is classified as spammer. 4.3.3 Subscriber Direct Trust The calling behavior of the subscriber can be estimated from the level of a trust a subscriber maintains with other subscribers. Trust represents the level of mutual relationship between subscribers which they have developed over the time and is computed from their direct call transactions. Direct Trust between subscribers represents the amount of duration and number of times the subscribers interacted to each other. Higher the call duration and call rate between subscribers, higher the trust exists between them. This trust information is then extended to estimate the network wide behavior of a subscriber termed as reputation of the subscriber. 4.3 Caller-REP:Caller Classification-Based on Reputation 59 Figure 4.1: Building Blocks of Caller-REP. The direct trust between subscribers characterizes the strength [GRA73] of social relationship between subscribers. In a voice network, subscribers can develop strong relationships if they have repetitive and reciprocated long duration calls to each other; and can develop weak relationship if subscribers have non-repetitive and non-reciprocated short duration calls to each other. In perspective of social behavior of legitimate and spam subscribers, we argue that legitimate subscribers usually have strong social ties with a large number of callees and weak social ties with a few callees , whereas a SPIT caller develops a weak relationship with a large number of their called callees. This trust information or relationship information can be used to classify subscriber as a spammer and a legitimate. In existing trust and reputation based SPIT detection systems, the direct trust between subscribers is computed in two ways: getting positive or negative feedback from the subscribers about their callers from their past call transactions and 2) implicitly using information from the call detail records. First approach is intrusive to subscribers and annoys subscribers for the feedback. Moreover, it also require changes in the handset and call setup messages which makes it infeasible to be deployed in a real VoIP network. Second approach normally uses single feature for computing direct trust between subscribers i.e. average call duration, but we argued that direct trust should not be limited to the single 60 Caller-REP: Detecting Unwanted Calls Through Caller’s Social Strength feature but should also consider number of features for computing direct trust between subscribers. As spammers normally target large number of callees and managed to have good duration calls with many of their callees. The use of average call duration feature for trust computation would result in a high trust score of the spammer with many of his callees. This in turn would have high reputation score despite having a large number of out-going calls and small number of incoming calls. For example, a subscriber with sum of call duration of 10 minutes in 10 calls has average call duration of 1 minute which is similar to the subscriber having sum duration of 1 minute in 1 call because average duration is 1 minute. Additionally, high number of long duration calls would also make spammer as a legitimate subscriber because a group of people may also be interested in spam call because of greed for financial benefits or the calls that terminated on the voice mail box. In a voice communication network, a subscriber can be either a caller or the callee. In the rest of this chapter we are interested in dealing subscriber as a caller. The subscriber’s transactions are represented as a sparse adjacency matrix in which rows represent callers and column represents the callees. We are interested in computing the direct trust between caller and the callee which is also represented as a sparse matrix. We incorporated the following features for computing the direct trust between caller and the callee: the frequency of interaction between caller and callee in in both directions (incoming and outgoing) , call duration between caller and the callee in both directions (incoming and outgoing) and the out-degree of the caller(number of unique callees of the caller). The call duration (CDSR;), call-rate (CallRateSR) and out-degree vector (POS) are collectively used to estimate the direct trust between subscriber Sand his callee Rusing equation 4.1. TrustSR =CDSR ×CallRateSR +CDRS ×CallRateRS POS (4.1) For all subscribers in the network, the direct trust matrix is defined as NXN sparse matrix. In equation 4.1 ,TrustSR represents the trust score of subscriber Swith his callee Rbased on their direct call transactions. In equation 4.1 CD is the call duration between subscriber Swith his callee R,CallRate is the interaction rate between subscriber Swith his callee R, and PO is the out-degree of the subscriber S. The TrustSR is represented as NXN adjacency matrix where row represent caller and column represent callee. The direct trust computed from equation 4.1 would result in a small direct trust scores for subscribers having large number of out-going partners with large number of small duration calls and have small number of incoming calls. On the basis of high call duration, repetitive calling behavior and small out-degree, equation 4.1 would assign a high trust 4.3 Caller-REP:Caller Classification-Based on Reputation 61 score to the legitimate subscriber and small trust score to spammers due to their high out-degree and non-repetitive short duration calls. The spammer would only be able to achieve high direct trust scores if he exhibits following behavior: 1) managed to have large duration repetitive incoming and outgoing calls, and 2) develop strong relationship with many callees. The reputation of the subscriber is computed from the normalized direct scores and present network wide view about behavior of the subscriber. The normalized direct trust matrix is computed by dividing each element of a row by summation of the respective row as shown in equation 4.2. This ensures that all trust scores will be between 0 and 1 and each row would sum to 1 as ∑RTSR =1 TSR =TrustSR ∑ R TrustSR (4.2) The direct trust scores provide information about direct relationship between subscribers and would characterize how strong or weak relationship exists between subscribers. Once the direct trust score of the subscriber has been computed the next step is to aggregate these normalized direct trust score to have network wide view about behavior of the subscriber. 4.3.4 Reputation of the Subscriber The global reputation represents the aggregate behavior of subscriber towards his entire interacted subscribers across the network. If a particular subscriber has no prior interaction with the other particular subscriber then the subscriber would ask other subscribers for the feedback about the subscriber. In this situation, the global reputation of the subscriber within the network would provide information about the aggregate behavior of the subscriber towards all his interacted subscribers. In this section, we outline procedure used for computing the global reputation of the subscriber. The global reputation of the subscriber is computed by aggregating the normalized direct trust scores. Eigen Trust algorithm [KSM03] has been widely applied in P2P network for computing reputation of the node from his direct trust scores. In Caller-REP, the reputation of the subscriber is computed using power iteration method with a slightly different initial reputation scores. The input to reputation computation method is the matrix of normalized direct trust TSR between each pair of subscribers (S,R). The output of this algorithm is a global reputation vector Gwith a global reputation score of a subscriber GSand is in between ∈[0,1]. The algorithm first initializes the initial global reputation values of each subscriber with the inverse of the out-degree POSof the subscriber S. The 62 Caller-REP: Detecting Unwanted Calls Through Caller’s Social Strength global reputation score of subscriber is then iteratively computed by multiplying the normalized direct trust matrix and initial reputation vector as represented in equation 4.3 and algorithm 1. The iteration process stops on the convergence of the norm of the global reputation vector kGRk=q∑SGR2 S. In each step of this iteration process, the global reputation vector is updated from the normalized direct trust and global reputation score as GR =T×GR.GR is normalized and its norm gr is used along with the previous norm grprevious for checking the convergence. GR(t+1) = TrustSR ∗GR(t)(4.3) The reputation computed in this way would result in a high reputation score for the subscribers having long duration repetitive calling behavior with the reputed subscribers. The spammers in this case would have a small reputation scores because of unbalanced calling behavior and large number of recipients. Algorithm 4.1 Reputation Computation 1: procedure GLOBAL REPUTATION OF ALL SUBSCRIBERS {S} 2: input ←Trust (normalized direct trust matrix, with elements TSR) 3: out put ←GR (Global reputation score vector, with elements GRS) 4: precision parameter ←ε 5: Initialize reputation vector GR 6: GRS= [1/POS] 7: % Iterate until convergence 8: while δ<εdo 9: GR ←Trust ×GR 10: GR ←GR/kGRk 11: gr ← kGRk 12: δ←gr−grprevious gr 13: grprevious ←gr 14: end while 15: end procedure 4.3.5 Detection of Spammers The reputation of a SPIT caller deviates from the reputation of legitimate subscribers and this deviation would help in distinguishing SPIT subscribers from the non-SPIT subscribers. In this section, we provide a method used for computing the automated threshold below which the subscribers is classified as a spammer. The global reputation score of the subscriber can be used in three ways to decide about the nature of the subscriber. 1) The global reputation scores can be sent to the callee as a 4.3 Caller-REP:Caller Classification-Based on Reputation 63 part of a SIP invite message and callee decides whether to accept or reject the call. 2) The global reputation scores can be compared with a fixed threshold. 3) The global reputation scores can be compared with a dynamic threshold learn from the set of reputation values. The first approach requires interaction with the callee thus is not only intrusive but also requires changes in the call setup messages. In the second approach, the threshold is decided based on a certain pre-defined true or false positive rate but this threshold is not flexible to accommodate a continuous changing behavior of the subscriber. In the third option, the threshold is computed automatically from the reputation score without subscriber’s intervention and can also account the changing behavior of the subscriber. We adopted third option for computing the automated threshold below which the subscriber is classified as a spammer. The dynamic threshold is advantageous as compared to the fixed threshold approach as it better minimizes false positive rate and maximizes true positive rate by considering the traffic patterns of subscribers within a specific time window. We set the dynamic threshold value based on a percentile method instead of a fixed value threshold. We sort the set of computed global reputation scores of all subscribers and set the threshold value to the 25th percentile of this set. The procedure for classifying subscriber as a SPIT or a non-SPIT is presented in algorithm 2. As in algorithm 2, GR is the global reputation vector of all subscriber and mis the 25th percentile value of the global reputation. First, the 25th percentile of global reputation is computed for each time window. Second, the mean of global reputation score of subscriber less than the 25th percentile value mis set as a dynamic threshold for a specific time window. Algorithm 4.2 Detection of Spammers 1: procedure SPIT DETECTION 2: input ←Global Reputation(GR), with elements GRS 3: out put ←SPIT (1) or non-SPIT(−1) detection vector, with elements SPITS 4: serviceprovider−de fined parameter ←β(β=1 if service provider has no preference) 5: m←1st-quartile(GR) 6: threshold ←mean(GR <m) 7: for All subscriber S do 8: if (GR[S]<β×threshold) then 9: Place Subscriber S in a SPIT List 10: else 11: Do Not Place Subscriber S in a SPIT List 12: end if 13: end for 14: end procedure 64 Caller-REP: Detecting Unwanted Calls Through Caller’s Social Strength Subscribers can be classified as legitimate 1 or non-legitimate -1 based on a following rule: SubscriberS=(GRS>β×threshold ; 1 GRS<β×threshold ; -1 Other approaches like Inter-quartile distance, mean absolute deviation and machine learning-based approaches can also be used for identifying the suspected SPIT subscribers. We believe that at any given time period, the VoIP network possibly has SPIT traffic less than 25% of the total incoming traffic and a dynamic threshold based on the 25th percentile would achieve better true positive rate. The service provider also wishes to block all the top spammers. Moreover, technologies normally witness a few malicious users until they become mature and attract large number of users. However, once it attracted large number of users then, it also starts attracting large number of malicious users and the percentage of spammers rises to as up as 40% of all identities joining the network on a particular day. For example, currently, it is estimated that 36% tweets on tweeter contains links [TWI16] and 25% of all personal computers may be infected by viruses. Over the time, we expect similar behavior in case when VoIP and telephony becomes affordable and a primary method for having personal and business communication. Furthermore, this threshold is tunable and can easily be integrated with service provider policies against spammer and non-spammer. However, the 25th percentile based approach would not provide good results if the percentage of SPIT traffic increases or if detection window size is decreased for the reputation computation. The 25th percentile performs better when large window size is used for the computation of reputation scores i.e. large number of call records and user interactions. The true positive and true negative rates in a network with high SPIT or legitimate traffic would be maximized by using Caller-REP with a β parameter set by the service provider according to his SPIT detection policies. 4.3.6 Caller-REP System Components Figure 4.2 shows the Caller-REP and its interactions with call processing system i.e. VoIP proxy server. The Caller-REP system can be implemented in two modes; as a standalone system having dedicated hardware resources or resides on the CDR or proxy server as a detection module. The later implementation would probably increase load on a proxy server and the former requires communication link between CDR server and Caller-REP server. However, in both implementations modes the system would not add any additional delay to the call setup message as the reputation is computed in the background and blacklist is consulted seamlessly during the process of getting billing and authorization 4.3 Caller-REP:Caller Classification-Based on Reputation 65 information. The Caller-REP system integrates with proxy server and operates in the following way. 1. On receiving a call request from the subscriber for the particular subscriber residing either in his network or other network, the proxy server first checks whether subscriber behavior is legitimate or not by checking subscriber status in black-list and white-list database. If the subscriber is found in the black-list, the proxy server immediately blocks the subscriber from calling and disconnects his call. If the subscriber is found in the white-list, the proxy server allows subscriber to reach the called subscriber and waits for the call termination. 2. Once a call between subscriber has been terminated, the proxy server records log of the call transaction in a CDR and periodically send anonymized CDR to the Caller-REP system for computing reputation of the subscriber. 3. Caller-REP system on receiving CDRs, extracts call and social network features of subscriber from the anonymized CDRs and computes direct trust and global reputation of the subscriber. The automated threshold is then computed from the global reputation scores that classifies the subscriber as spammer and non-spammer. Finally, Caller-REP engine responds to the proxy server with the results about the subscriber i.e status and global reputation score. 4.3.7 Caller-REP and Privacy Caller-REP system is based on the use of information from the call detail records to determine if a subscriber is a spammer or a non-spammer. The CDRs contain private information about when, where, and who the subscriber calls along with the length of phone calls and other personal information like billing addresses and IP addresses. The availability of this private information can raise serious privacy concerns and enable illicit activities that can put the subscriber at risk. The telecom service providers have to protect the privacy of their subscriber if they want to use this information for specific purposes - e.g. in our case for the spam detection. The following privacy protection requirements apply. 1) Subscribers have to be informed if their call detail records are being used for any specific purpose like intrusion detection or spam detection [OZ04] and be provided with an opt-out option. 2) The service provider has to keep the subscriber data secure and protected from un-authorized access [OZ04].3) The service provider has to make an effort to hide information that can directly identify the user [PEN04] (e.g. user name and phone number) even when providing authorized access to subscriber data to third parties and 66 Caller-REP: Detecting Unwanted Calls Through Caller’s Social Strength Figure 4.2: Interaction Between Caller-REP and Proxy-Server. to specific-purposed managed software like spam detection system. This could be done by removing user name and phone number from the data and tagging it with the random identifiers that are unique for each subscriber. This approach does not guarantee that the identity of the subscriber cannot be mapped to the data but makes it non-trivial. Caller-REP protects the privacy of the subscribers and manages privacy risks in a service provider network in the following way. 1) The service provider shall inform subscriber that their call records will be analyzed for the purpose of blocking spammers and allow subscribers to opt-out only if number of their unique callees are less than some fixed threshold (a small possible threshold, for example 5 unique callees). 2) The service provider should protect user data from unauthorized access using strong authentication process and policies on unauthorized disclosure of subscriber information by their staff. 3) In order to minimize the risk of misuse of data for other purposes, Caller-REP engine also assigns with a data after pseudonymizing [CKK05]. For that purpose, the service provider first selects few attributes from subscriber call transactions (i.e. caller and callee identity, call duration, and time of call transaction). It then replaces caller and callee identities with a key by which he can later re-identify a user account in case that have been positively identified as spammer. Additionally, in order to completely preserve the 4.5 Performance Evaluation 73 evaluate how fast the system is able to distinguish spammers and non-spammers. In Figures (5.5,5.6, and 4.6), label "YYY-ZZ%" represent the number of legitimate subscribers (YYY) and the percentage of SPIT subscribers (XX) in a simulated network. 4.5.1 True Positive Rate The first experiment examines the effects of percentage of spammers and non-spammer on the true positive rate of the Caller-REP system. The percentage of spammers is varied from 10% to 30% and the number of legitimate subscribers varied from 100 to 1500 subscribers. Particularly, the performances of Caller-REP has been evaluated for two aspects: 1) how true positive rate of system behaves when number of legitimate subscriber increases, and 2) how true positive rate is effected with the increase of percentage of SPIT callers. The results for true positive rate of both evaluation aspects are shown in Figure 5.5 which plots the fraction of spammers blocked with respect to time. In a first evaluation scenario that is varying the number of legitimate subscribers with a small percentage of spammers. In this scenario, Caller-REP allows few SPIT callers to pass through the system during first two days, but it starts blocking all SPIT callers with a maximum true positive rate after second day. This is because of the fact that some SPIT callers have small out-degree during first two days and managed to have good duration calls with good number of callees. But, as soon as the out-degree of spammers increases and other call features (duration and call-rate) decrease, Caller-REP start identifying spammers. Specifically, Caller-REP achieves true positive rate of less than 90% during first two days in a network with high number of legitimate subscribers. Over the time, Caller-REP achieves acceptable high true positive rate and eventually achieves almost 100% true positive rate after three days regardless of number of spammers and number of legitimate users. This is because during first two days the behavior of legitimate and non-legitimate subscriber might be same but over the time the legitimate caller develop many strong connections with their callees and spammer develops weak connections with the many callees which is enough to differentiate spammer from non-spammer. This start period or learning period is essential as it help legitimate callers in achieving high reputation scores with the time. For all scenarios the increase in number of legitimate callers, Caller-REP is not allowing any SPIT caller through the system after 3 days. In the second scenario, the behavior of the Caller-REP system is analyzed for different percentage of SPIT callers. The percentage of spammer varied from 10% to 30% while fixing the number of legitimate user between 100 and 1500. It is expected that system would have high true positive rate when percentage of spammer is small. The true positive rate of Caller-REP decreases with the increase in number of spammers from 10% to 30% 74 Caller-REP: Detecting Unwanted Calls Through Caller’s Social Strength Figure 4.4: True Positive Rate Increases with Time: A) SPIT Rate of 10%; B) SPIT Rate of 20%; C) SPIT Rate of 30%. as shown in Figure 5.5. Specifically, on a first day, the true positive rate of Caller-REP system decreases by 50% with the increase in number of spammers from 10% to 30%. This behavior is because on a first day, some spammers have small out-degree distribution similar to the legitimate subscriber and develop some relationship with many subscribers. However, over the time as out-degree increases, the true positive rate also increases. The results from Figure 5.5 reveals that Caller-REP is able to achieve true positive rate of more than 90% when the number of spammers is less than 20% and prolong detection to third day when percentage of spammer exceeds 20%. Specifically, Caller-REP is able to block all spammers in three days regardless of number of spammers in the network. We have also analyzed another critical performance aspect of Caller-REP system that is the time it takes to make the correct classification about the subscriber. The results from 4.5 Performance Evaluation 75 Figure 4.5: False Positive Rate Decreases with Time: A)SPIT Rate of 10%; B) SPIT Rate of 20%; C) SPIT Rate of 30%. Figure 5.5 show that Caller-REP allows a significant number of SPIT calls to pass through the system on first three days, but it blocks all SPIT caller after third day regardless of percentage of spammers and number of legitimate subscribers. Specifically, Caller REP has high true positive rate for small sized network during first few days rather than large scale network. However, Irrespective of network size and spamming rate, Caller-REP correctly classifies subscribers as a legitimate and a non-legitimate within three days of its initialization. 4.5.2 False Positive Rate Service provider does not want to block legitimate subscribers for various reasons: first it affects the revenue, secondly it annoys callee expecting calls from some legitimate 76 Caller-REP: Detecting Unwanted Calls Through Caller’s Social Strength subscriber, and thirdly it annoys legitimate subscribers if they bared from calling being honest. A well designed and effective system requires to have small false positive rate without effecting the true positive rate. The false positive rate of Caller-REP for all simulation scenario is shown in a Figure 5.6. The performance of Caller-REP for false positive rate is analyzed for the same performance aspects that we have used while evaluating the true positive rate. In the first simulation scenario where the number of legitimate subscriber increases, Caller REP able to manage a false positive rate of around 15% on first day, but it starts decreasing to less than 2% within three days. This is because some of the legitimate subscribers have short duration calls with many of their callees which results in a small reputation scores similar to that of SPIT callers. However, over the time, if the user behaves legitimately, the reputation scores increases due its strong social connections and if the user behaves non-legitimate, the reputation score decreases over the time due its weak social connection. Caller-REP correctly classifies non-spammer as non-spammer in three days with false positive rate less than 2%. The analysis for second scenario shows that Caller-REP achieves a better false positive rate in a network with a high number of SPIT callers, as shown in Figures 5.6.B and C as compared to false positive when number of spammer is small. Caller-REP achieves a false positive rate of less than 10% for a SPIT rate of 30% on the first day and eventually decreases to less than 1% on the third day. This means that under high SPIT rate, Caller-REP would not cause revenue loss to the service provider. Additionally, CallerREP achieves false positive rate of less than 1% within three days for any type of SPIT rate. The false positive rate can be further decreases with the use of CAPTCHA or Turing test to be generated for the subscriber classified as spammers. Additionally, Caller-REP can also be used in combination with social network features like out-degree to decrease false positive in non-intrusive way. The high false positive rate under small spamming rate and small false positive rate under high spamming rate on a first day is also attributed to the threshold computation. As discussed, Caller-REP is using 25th percentile based threshold for classification which results in a high false positive when spamming rate is small. The threshold can also be adjusted according to SPIT detection policies (require true positive and false positive rates) defined by service providers. In this scenario the 25th percentile threshold is multiplied with a some constant value between 0 and 1. A high threshold would block some legitimate subscribers whereas as small threshold would have small false positive rate. The threshold value need to be chosen in such a way it does not affects true positive rate by high margins. 4.5 Performance Evaluation 77 Figure 4.6: Caller-REP Accuracy: A)SPIT Rate of 10%; B) SPIT Rate of 20%; C) SPIT Rate of 30%. 4.5.3 Detection Accuracy The service provider wish to have such SPIT detection system that achieves high false negative (non-SPIT classified as non-SPIT (1-FP)) and high true positive rate. The accuracy metric best characterize the behavior of detection system as it incorporates all four terms of confusion matrix while computing performance of detection system. A small true positive rate results in allowing spammers to reach the subscriber and the high false mistakenly blocks many non-spammers from the subscriber. The True positive rate (TPR) and false positive rate (FPR) of Caller-REP is shown in Figures 5.5 and 5.6 that shows that Caller-REP stabilizes and achieves maximum TP and TN rate within three days. However, TPR and TNR needs to be analyzed together that is best characterize by computing accuracy of the system i.e. systems capability of correctly making decision about the 78 Caller-REP: Detecting Unwanted Calls Through Caller’s Social Strength subscriber behavior. In first two days, Caller-REP allows many SPIT callers to pass through undetected and blocks some of the legitimate subscribers which results in a accuracy less than 90% when spamming rate is less than 20% and accuracy less than 80% when spamming rate exceeds 20% as shown in Figure 4.6 . Specifically on a first day the accuracy for all spamming rate and number of legitimate user is less than 60% which further improves to almost 100% accuracy in 3 days. Results from Figure 5.5 and 5.6 reveal that the TP rate and TN rate increases over the time which is a positive sign of Caller-REP for not blocking any legitimate subscriber and not allowing any spam caller after 3 days. The small accuracy during first few days is mainly because of the high false positive rate or small true negative rate. In order to improve the accuracy we need to improve the false positives without affecting the true positive. In view of the above results, we believe that in addition to using a 25th percentile threshold, using some social network features or service provider defined threshold in decision process would be effective in improving the accuracy of the Caller-REP system. The Caller-REP can also relay the call to voice mail box and implicitly analyze the behavior of callee towards the message from voice mail box. It might be possible that subscriber develop only few relations during its introduction periods which results in a subscriber’s small reputation score and a sign to consider as spammer. Instead of directly blocking the subscriber having small reputation scores, Caller-REP can collectively use reputation score, threshold and out-degree of the subscriber. If out-degree is extremely small (less than 5) then it would not be sign that subscriber is spammer. 4.5.4 Sparse Subscriber’s Network In the context of social network, a sparse network is network where the nodes have edges with only fewer nodes from all nodes in a network. In telephone, user develops a scale free power law degree distribution which means that subscriber normally interacts with a small group of callees. This interaction behavior results in a sparse network matrix or sparse network for users. In this section, we analyze the performance of Caller-REP system in a sparse network. We expect, that sparseness would not result in a small reputation scores to subscribers having sparsity because of use of collective use of three call features: call duration, call rate and out-degree. In Caller-REP network sparseness is not the only factor that has an impact on a global reputation and direct trust. A sparse caller only gets bad reputation when along with sparseness it also has low call duration and low call rate. The evaluation of a sparse network requires a different simulation setup than the simulation setup that has been used for analyzing the TPR and FPR. For analyzing the effects 4.5 Performance Evaluation 79 of sparseness, we created a full network for 11000 users using the method from the section 5.5.1 and then added a percentage of users with a sparse network. We performed simulations for two scenarios. In a first scenario, 25% of callers has less than 10 friends. In this scenario, Caller-REP misclassifies only 11% of legitimate subscribers as spammers. In a second scenario, 45% of subscribers has less than 20 friends and Caller-REP misclassifies only 7% of legitimate subscribers. The results also show that decreasing the degree of sparseness would decrease the FPR. Additionally, the sparseness has no effect on the TPR. On further investigation, the sparse legitimate subscribers that were misclassified as spammer were found to have small average call duration and calling rates. 4.5.5 Subscriber Reputation The reputation of a legitimate subscriber increases and reputation of non-legitimate subscriber decreases over the time. This is because of the fact that the legitimate subscriber has repetitive long duration calls to a large number of their called callees and has short duration calls with only few callees. On the other hand non-legitimate subscribers target large number of callees and managed strong connection with only few callees. This behavior would result in a high reputation score to legitimate subscriber which further increases over the time and small reputation score to the spammers which further decreases over the time. The global reputation scores of spammer fluctuate around his initial reputation score whereas non-spammer show increase in reputation scores from their initial reputation scores. The small reputation score to spammers and high reputation score to non-spammer is because of the collective use call-features (duration and call rate) and the out-degree distribution. The high out-degree with small duration call will largely effect the reputation of the subscriber. In Caller-REP, it is difficult for spammer to obtain and maintain high reputation scores. This is because the reputation is based on the call interaction, call duration, and the outdegree of the subscriber. The spammer needs not to have good duration bi-directional repetitive calls but also need to control his out-degree in order to have high reputation score but this is not practical in real scenario and spammer would not have benefit from it. A legitimate subscriber, on the other hand, will have a high reputation value due to high number of repetitive long duration calls in both direction and relative small out-degree. Figure 4.7.A shows the reputation score distribution of spammers and non-spammer over the period of 10 days. From Figure 4.7.A, it is clear that reputation of suspect spammer is not increasing much and does not vary over the time, whereas the legitimate subscribers show continuous increase in their reputation scores. The reputation scores for Call-Rank 80 Caller-REP: Detecting Unwanted Calls Through Caller’s Social Strength Figure 4.7: Caller Reputation With The Time: A) Caller-REP; B) Call-Rank. system for ten days is shown in Figure 4.7.B which shows that global reputation of spammers is also increasing if subscriber has high out-degree and some moderate duration calls. From a Figure 4.7.A, we also conclude that 25th percentile could provide better detection accuracy for the Caller-REP than the Call-Rank system. 4.5.6 Caller-REP Vs. Call-Rank In section 5.4.1 we have presented how Caller-REP is different from other SPIT detection systems. In this section we compare the performance of Caller-REP with its closely related counterpart approach the Call-Rank. The social network of legitimate subscriber becomes strengthen with the passage of time as compared to non-legitimate subscriber having weak social network over the passage of time. The reputations of legitimate and non-legitimate subscribers using Caller-REP and Call-Rank approach is presented in Figure 4.7. The reputation of legitimate and non-legitimate subscribers in Call-Rank increases with the time as shown in Figure 4.7.B. This means that if Call-Rank misses a certain non-legitimate subscriber on the first day, it would not be able to detect this suspected subscriber on next days because of his improved global reputation value. On the other hand Caller-REP would not increase the reputation of suspected non-legitimate subscribers over the period of time instead it decreases over the time. This means that if Caller-REP misses a certain non-legitimate subscribers on the first day then it would eventually detect it on the next days because of its slight change in a reputation values. In terms of detection performance, the Call-Rank achieves a maximum true positive much later then that of Caller-REP system. However, Caller-REP achieves a true positive rate of 4.5 Performance Evaluation 81 Figure 4.8: Caller-REP Performance Under Legitimate Network. almost 100% on the third day under any type of spamming network. In terms of false positive rate, caller-REP blocks 10% of the legitimate subscribers, which is much higher than the false positive rate of Call-Rank. However, with time this false positive rate decreases to less than 1% and behaves similarly to a the Call-Rank. 4.5.7 Caller-REP under Legitimate Network The deployment of Caller-REP in a real VoIP network may face another major challenge when all subscribers in a network are legitimate. There are no SPIT subscribers in this condition. In its original form, Caller-REP may wrongly classify weakly connected legitimate subscribers as SPITter. In order to minimize this misclassification, Caller-REP can be improved using additional social network features and improved automatic threshold detection. The following social network features could be used along with Caller-REP: clustering coefficient, ratio of incoming to total calls, path distance measure and outdegree distribution. The computation of few these features becomes difficult when the subscribers are on different networks and service providers are not willing to share callee internal network structure. However, out-degree and in-degree distribution of subscriber can be easily computed without extra effort and provide information along with reputation score. Usually the SPIT caller tries to reach a large number of callees and consequently has a more unbalanced out-degree distribution than the legitimate subscribers. In a legitimate network, Caller-REP misclassifies callers with short duration calls and small number of unique callees. The small number of unique callees in a day cannot be taken by itself 82 Caller-REP: Detecting Unwanted Calls Through Caller’s Social Strength as the sign of SPIT callers [SWN12]. Figure 4.8 presents the performance of CallerREP and Extended-Caller-REP under a legitimate network. In extended Caller-REP we consider callers as legitimate if their number of out-partners is less than 5 even if the subscriber is classified as non-legitimate by Caller-REP. Caller-REP achieves 90% true negative rate (non-SPIT detected as non-SPIT) in a legitimate network. The extended Caller-REP behaves well at start, but its true negative rate decreases to 96% with the time. The decrease in true negative in extended Caller-REP is due to the fact that some legitimate subscribers have low duration calls with few callees and also do not receives calls from called callees. 4.5.8 Caller-REP under High SPIT Rate Currently the email spam traffic dominates the total legitimate email traffic. However, in Telephony not many SPIT events have been reported. In future, advertisers will likely starts using VoIP as a mechanism for advertising their products. In a high SPIT attack, where the network comprises more SPIT traffic than non-SPIT traffic, the Caller-REP only blocks a limited number of SPIT callers having extremely low reputation values. The positive aspect of Caller-REP under a high SPIT rate scenario and βvalue of 2 is that it would not block any legitimate subscribers. However, in order to block all SPIT callers, the Caller-REP can be improved by carefully setting the βparameter. We performed experiments for 2000 users, for a varying number of spammers from 45% to 80%, and a fixed βvalue of 2. Figure 4.9 presents the true positive rate of Caller-REP under high number of SPIT callers and βvalue of 2. The true positive rate decreases with the increase in a percentage of SPIT callers; however, Caller-REP only allows less than 8% of SPIT callers to make calls under high number of SPIT callers. The CallerREP allows all legitimate subscribers with a zero false positives. The true positive rate of Caller-REP under heavy SPIT attack also stabilizes with the time and achieves the true positive rate of 96% within 3 days and around 98% in 8 days. 4.6 Discussion on Caller-REP In this section, we discuss various aspects of Caller-REP system. We first discuss some important characteristics of Caller-REP system and discuss how it can be bypassed by the spammers. We then discuss deployment issues of Caller-REP in a real VoIP network. 4.7 Conclusions 89 service provider. We believe that this collaboration would further minimize the detection time and achieves high accuracy. Chapter 5 COSDS: Blocking Spammers with Information Sharing across Multiple Service Providers 5.1 Introduction Telecommunications service providers (SPs) can deploy standalone spam detection systems [DK05], [KD07], [WBS+09], [BAP07], [AM12], [AM13] within their network for protecting their subscribers from unsolicited calls and SMS. The standalone detection systems 5.1(a) consider data from one source for analyzing the calling behavior of subscribers within service provider. Spammers can evade these standalone systems by making a large number of spam calls in aggregate to recipients of many service providers without overwhelming any single service provider with the spam calls. By doing so, spammers remain undetected for a longer time period within the service provider, since service provider is not receiving large number of calls from the spammers that flagged them as spammers. An effective solution to detect low rate spammers requires monitoring of behavioral patterns of subscribers across multiple SPs. Obviously, collaboration and information sharing can be an effective way to block such spammers making low rate spam calls to recipients of many service providers. However, there are two key challenges in collaborative spam detection: firstly, what information should be exchanged during the collaboration process; and secondly, to whom this information should be made available. Collaboration will probably achieve better detection accuracy and time than the standalone detection systems but its performance depends on the amount of information exchanged among collaborators. The collaborative solution can be either the distributed 5.1(b) or the centralized 5.1(c): distributed - where 90 5.1 Introduction 91 (a) Non-Collaborative (b) Distributed Collaboration (c) Centralized Collaboration Figure 5.1: Collaboration Methods: A) Non-Collaboration; B) Distributed Collaboration; C) Centralized Collaboration. 92 COSDS: Blocking Spammers with Information Sharing across Multiple Service Providers the information from each SP is shared and processed in a completely distributed fashion without a central coordinator; centralized - where all information from SP is reported to the single centralized location for analysis. The distributed data aggregation and analysis lack privacy protections. The service providers are not willing to share operational data of their customers with each other, because they are business competitors and are concerned about compromising the privacy of their customers. Generally, better detection accuracy is expected when collaboration is achieved through the exchange of complete call records but at the cost of system and network resources. Moreover, SPs are likely to be reluctant in a direct exchange of CDRs to peer SPs or the trusted Centralized Respository (CR) because CDRs contain subscriber’s private information as well as operational details of their network. SPs may be more comfortable in exchanging summarized information to the trusted CR rather than exchanging information directly with other SPs. The exchange of summarized information could deteriorate the system performance in terms of detection accuracy and time but it does not require extensive network resources and exchange of call records. A key challenge in the design of a collaborative SPAM detection system is to achieve high detection accuracy and minmizes the detection time without compromising computation resources and without the exchange of CDRs. To address the above challenges, we propose a Collaborative Spit Detection System (COSDS) for an accurate and early detection of SPIT subscriber, which is based on collaboration among many autonomous SPs. The major feature of COSDS is that it does not require direct collaboration among SPs. Instead the collaboration is carried out with the exchange of summarized information with the trusted CR thus reducing the network load. In particular, each SP submits the Local Reputation (LR) scores (summarized information) of their subscribers to the trusted CR. These reputation scores represent the behavior of subscribers within the SP network and have been computed from subscribers past call transactions within the SP. The CR is responsible for the computation of global reputation of subscribers by aggregating the received LR scores and deciding about spamming behavior of subscribers. The CR responds collaborating SPs with the GR scores and decisions about subscribers, which also allows each SP to act independently against spammers. In COSDS, only a summarized information i.e. LR scores are sent to the trusted CR which are not resource demanding. Each collaborating SP interacts directly with the CR and requires only two transmission cycles for getting GR of their subscribers i.e. one cycle for sending LR to the CR and one cycle for receiving GR from the CR. Additionally, the use of trusted CR and exchange of summarized information further likely to convince SP to take part in a collaboration. We evaluate our system using synthetic data that we have generated through models of spammers and non-spammers social behavior. The evaluation has been performed for dif- 5.1 Introduction 93 ferent performance metrics and for different percentages of spammers and collaborators. We demonstrate that collaboration among SP outperforms standalone detection systems in terms of detection accuracy and detection time. Specifically, for a network having a large number of spammers, COSDS managed to achieve zero FP rate and blocked all spammers within 3 days. The results also reveal that COSDS achieves detection accuracy that is comparable to that of a system where collaboration is carried out through the exchange of call detail records. COSDS approach is fast, requires small communication overhead and only requires a few iterations for the reputation convergence within the SP. The proposed approach is an extension of the SP level SPIT detection system presented in Chapter 4. In this chapter, we establish cooperation among SPs and focus on defining the components and mechanism for collaborative SPIT detection. This enables early and accurate detection of the spammer while considering the LR scores of the subscribers across many collaborating SPs. In a summary, the contributions of this chapter are: •The design of a collaborative SPIT detection system that incorporates collaboration from multiple autonomous SPs for an early identification of spammers distributing low rate spam calls to recipients of many SPs. Each autonomous SP is capable of processing locally recorded call transactions of their subscribers for computing LR scores of subscribers, which are then sent to the trusted CR. The trusted CR computes GR of subscribers by aggregating the reputation scores and makes meaningful decisions about behavior of a subscriber as a spammer or a non-spammer. The exchange of summarized local reputation scores not only convince SP to be a part of collaboration process but is also not resource demanding regarding network and system resources. The proposed centralized design and exchange of summarized information further ensures the privacy protection of subscribers within SP as well as at the CR. •A detailed evaluation has been performed on the synthetic CDRs. Particularly, we evaluated the system for different number of collaborators, different percentage of spammers and for the following metrics: true positive rate (TPR), false positive rate (FPR) and accuracy. We also compare the performance of COSDS to a system where collaboration is carried out through the exchange of CDRs or direct trust scores with the CR. In addition, we also evaluate subscriber’s privacy aspects within the collaborating SP and at the centralized repository for different auxiliary information known to adversary. The chapter is structured as follows. In Section 5.4, we describe architecture of collaborative SPIT detection system and design options for the collaboration. Additionally, 94 COSDS: Blocking Spammers with Information Sharing across Multiple Service Providers Section 5.4 also provides discussion on deployment challenges of COSDS in the SP network. The experimental setup is presented in Section 6.4 and detail evaluation for different performance metrics is presented in Section 5.6. In section 5.7 we discuss features of collaborative system and then conclude the chapter in Section 5.8. 5.2 Limitations of Stand-alone Detection Systems Stand-alone SPIT detection systems are currently major systems for thwarting SPIT subscribers. These systems are typical placed within one SP and consider only locally recorded data within the SP for deciding about behavior of the subscriber as a spammer and a non-spammer. Since there is no cooperation among SPs, no data from SP is passed to other SPs except call handling messages. Standalone anti-SPIT systems may have high false negative rate and prolonged detection when spammers are making low rate spam calls to recipients of several SPs without making large number of spam calls to any single SP. In particular, stand-alone systems could manage to detect low rate spammer over time (after receiving enough number of calls) and when the number of spam calls from the same subscriber spikes. However, this detection is too late as spammer has already reached to a large number of subscribers in a particular SP and across several SPs. The prolonged detection is because of unavailability of information for making reasonable decision about the sender. The stand-alone systems can improve their detection capability by combining several stand-alone detection approaches into a single multistage system or asking subscriber for solving the CAPTCHA test. However, these implementations have following limitations. First, CAPTCHA involves subscriber for solving the challenge that is not only resource intensive but is also intrusive to the subscribers. Second, multistage systems require call request to pass through many detection components thus would increase the call setup delays. Third, multistage systems still require a relatively large number of calls from the same subscriber for making the final decision about the subscriber and still still allows spammers to reach several subscribers. 5.3 Motivation Existing SPIT detection systems classify subscriber as spammer and non-spammers based on the call patterns of subscriber observed at a single service provider. A low rate spam subscriber that distributes spam calls across many SPs may evade the stand-alone detection systems. However, for financial benefits, a low rate spammer makes a low rate unsolicited calls to recipients of many SPs and his calling behavior remain same across 5.4 Collaborative SPIT detection System 95 all target SPs. Thus, observing calling behavior of user across multiple SPs could help in early identification of spammers that are responsible for making large number of spam calls. The existing collaborative anti-SPIT systems [SS09] though involve collaboration among SPs but it only rates detection capability of spam detection system placed in home network of the subscriber. The COSDS approach is different from [SS09] in a sense that it computes reputation of end users instead of computing reputation of detection system placed in a home service provider of the end user. Moreover [SS09] requires changes in the call setup messages to incorporate tags that are exchanged between collaborators, whereas COSDS does not require any change in the network architecture and call setup messages. To increase the detection accuracy and reduce detection time, it is utmost important to establish a collaboration among SPs for computing aggregate reputation of end-users. The effectiveness of collaborative anti-SPIT system mainly depends on the amount of information being exchanged in a collaboration process and has challenges of privacy protection, communication overheads and system resources. There is a strong need to have a collaborative system that fulfills following conditions. 1) Collaboration among SPs needs to be carried out without establishing a direct trust relationship between collaborators. 2) The information used for the collaboration should not be resource intensive regarding network and system resources. 3) The information exchanged should not contain any sensitive information that could be used by the adversary to infer the relationship network of users. 4) The design system should have high true positive rate and small false positive rate. 5.4 Collaborative SPIT detection System We consider four assumptions: 1) people calling behavior can change over time (they add or remove links, have different call behavior with family and friends etc.) [SMS+08]; 2) the calling behavior of legitimate subscriber is different from that of spammer [BSG+11], [CMP+13], [DTN11]; 3) The calling behavior of a spammer remains the same across many SPs; and 4) the detection approaches based on collaboration are more likely to have better detection accuracy and detection time than that of stand-alone detection approaches. Based on these assumptions, the rest of the chapter discusses a system called COSDS, which blocks spam subscriber based on the collaboration from the autonomous SPs. The basic components of our collaborative spam detection system are shown in a Figure 5.2. In the following sections, we describe the method used for computing GR of the subscriber (Section 5.4.2), the method used for classifying subscriber as spammer and non-spammer 96 COSDS: Blocking Spammers with Information Sharing across Multiple Service Providers Figure 5.2: Building Block of Collaborative SPIT Detection. (Section 5.4.3), and design options for collaboration and their effects on the detection accuracy (Section 5.4.4). 5.4.1 System Design Overview Figure 5.2 presents the system architecture of the COSDS system. COSDS consist of three layers. At the lowest layers, subscribers (end-users or subscribers) make and receive calls among each other. There is a local reputation engine placed in each SPs network that computes local reputation of a subscriber using his local call patterns extracted from the recorded CDRs at the SP. The SP reports LR scores to the trusted centralized repository in a following format: [CallerID, LR, Trust for SP]. CallerID is the unique identity of a subscriber (can be a telephone number, an IP address or both). We are using telephone number as the identity of the subscriber. The LR is the local reputation score of the subscriber and takes value in between 0 and 1. The third argument is optional and represents SP trusts score on other SPs from where it receives traffic or sends traffic to. The CR is a trusted third party or regulator entity responsible for reputation aggregation and ensures that SP’s provided information would not be disclosed to any other entity. The CR computes global reputation of subscriber by aggregating received LR, makes decisions about subscriber (spammer and non-spammer) and report back results to collaborating SPs in a following format [Caller ID, GR, Decision]. The GR score is the aggregated reputation of the subscriber and the decision is the status of a subscriber as a spammer and a non-spammer. 5.4 Collaborative SPIT detection System 97 Figure 5.3: SP’s Level Working of Collaborative SPIT Detection. Figure 5.3 presents SP’s reaction towards a call request from the subscriber. Upon reception of a call request, SP first checks caller-id against its local database. If a callerid is present in a spam list then the SP immediately blocks the subscriber and if the subscriber is legitimate then SP allows subscriber to have communication with the callee. At the end of conversation, the SP updates direct trust between subscriber and callee, computes subscriber’s LR and periodically sends LR to the CR. The CR computes GR of the subscriber considering new reputation score reported from the collaborators. At the end of a collaboration process, the SP receives aggregate GR and classification result of a subscriber from the CR. The SP can either rely on CR decision to update his spammerlegitimate database or uses GR scores along with social behavior of subscriber within the SP. 5.4.2 Global Reputation of a Subscriber The GR of a subscriber is computed in two steps. First, a SP computes LR of the subscriber and sends it to the CR, and secondly, a CR computes GR of the subscriber by aggregating received reputation scores from the collaborating SPs. The computation of LR of the subscriber in a SP is a two steps approach. First, a direct trust between a subscriber and his called callees is computed from the subscriber’s past call transactions with his callees. Second, a LR of the subscriber is computed using the Eigen Trust algorithm. Existing methods used for computing direct trust of subscriber uses two main approaches: getting positive and negative feedback from the callee about the subscriber and using call features from the CDR e.g. average call duration. Relying on 98 COSDS: Blocking Spammers with Information Sharing across Multiple Service Providers a subscriber’s feedback is intrusive and relying on a average call duration will lead to allowing spammers having few good duration out-going calls from a large number of called recipients. A combined use of several features would be more effective in characterizing the real behavior of the subscriber within the service provider. In a combined approach, a direct trust between subscriber and his called callee is computed by collectively considering the in-coming and out-going call rate of the subscriber to the callee, the call duration of calls made and received between subscriber and the callee and the number of unique callees a subscriber has for a particular time window. These features have been adopted because of the fact that legitimate and spam subscribers exhibit different calling behavior. The legitimate subscribers usually have long duration, bi-directional repetitive calling behavior with their friends and family members, and also have small duration bidirectional calls to very few called callees. On the other hand, the spammer or the advertiser usually targets large number of callees, which normally results in a short duration calls to a large number of callees. Spammer also manages a moderate duration calls with a few target callees as well as receives calls from the few targeted callees. This unbalanced calling behavior of spammer i.e. high number of out-going calls and few in-coming calls would result in a small direct trust score for a spammer with the large number of called callees. Within a service provider SP, the direct trust TrustSP SR between subscriber Sand his callee Ris computed by using equation 5.1. TrustSP SR =CDSP SR ×CallRateSP SR +CDSP RS ×CallRateSP RS POSP S (5.1) In equation 5.1,CD is the in and out call duration between a subscriber and the callee in a specific time interval, Call −Rate is a frequency of in and out calls made between subscriber and his callee in a specific time interval, and PO is the out-degree of the subscriber. The SP defines a sparse trust matrix of dimensions N×N, where Nis the total number of subscribers within the SP. If there is no interaction between subscribers then TrustSP SR from subscriber Sto subscriber Ris set to be zero. The direct trust between subscribers is asymmetric as the subscriber and his callee might have different number of out-going callees. For the spammers, equation 5.1 would result in a weak trust relationship with a large number of callees and moderate trust with only few callees. For the legitimate subscribers this would result in a strong trust relationship with many of his callees and moderate trust relationship with a large number of called callees. 5.4 Collaborative SPIT detection System 105 of the target subscriber. The Probability that an adversary can breach the privacy and get true records given AUX information is presented as: Pr(PrivacyBreach|AUX) = (1/X;i f X >0 0 ;i f X =0(5.5) Where X is number of subscribers returned for the AUX information. 5.4.6.2 Privacy Protection at SP The SP processes CDRs for the computation of LR score of the subscriber. The adversary learns following information for breaching the privacy of subscriber during computation of LR: AUX1: An adversary knows call related information of the target user and wants to find anonymized identity of the target user. For example, an adversary knows target user called someone known person at 11:20 am. AUX2: An adversary knows out-degree of target user along with AUX1. For example, an adversary knows call times of calls made by the target user and number of callees target user called. AUX3: An adversary knows the calling behavior of target user along with AUX1 and AUX2. For example, an adversary knows call rate and call duration of target user’s few calls and wants to learn complete relationship network of the target user. COSDS protects privacy of the subscriber within the SP by setting the following best practices. 1) The SP shall protect records of the subscribers from unauthorized access using strong authentication processes, 2) The SP shall provide opt-op option to the subscriber if his out-degree is small, and 3) The SP shall pseudonymized identity of subscriber for further reducing the risk of misuse of the data. Pseudonymized identities can provide one level of protection but adversary can still find pseudonymized identity of target by using single AUX or correlating multiple AUX. In Section 5.6.7, we will show that Pseudonymized identity is not providing absolute privacy protection for AUX1, AUX2 and AUX3. We use following mechanism for the CDR anonymization: P1: The local reputation engine computes reputation for the specific time period, we strip the minutes and seconds information from the time and date of the CDR. By doing this the probability of inferring the pseudonymized identity is small for the AUX1. 106 COSDS: Blocking Spammers with Information Sharing across Multiple Service Providers Social Network Calling Behavior Trust Network Complete CDR YES YES YES IDs with Rate and Duration YES YES YES IDs with Trust Matrix YES NO YES IDs with Reputation Scores NO NO NO Table 5.1: Subscriber Level Privacy Breach for Different Collaboration Methods. P2: The out-degree of the subscribers in the CDR can be k-anonymized. For subscribers having unique out-degree, random noisy subscriber can be generated which is exactly similar to the subscriber but with different pseudo identity. This k-anonymization would affect the detection accuracy but provides privacy protection for AUX2. The adversary knows AUX1 of his target subscriber; for example, adversary learns from media that presidents of two countries talk to each other for some duration on some specific time and wants to learn pseudo identities associated with both presidents. The adversary can find possibly a small candidate-set if time in CDR is not properly anonymized and by correlating more information adversary can find correct identities of both presidents. However, in our scheme, striping minutes and second further minimizes the risk of de-identification. In some scenario, the adversary can make some calls to the target subscriber and intends to find whether the target has interactions with his friends or not. In a first case, adversary knows call duration and call time of all his calls to the target subscriber. Again, the adversary can learn his target’s pseudonymized identities and so the presence of link between target and his other friends if time of call is not stripped. The adversary can also correlate multiple AUX to reduce the size of candidate set. However, our proposed anonymization approach significantly reduces the risk but adversary can breach privacy by making some large number of bi-directional links which are normally not under his control. Subscriber Home SP Calling Behavior SP Network Complete CDR YES YES YES IDs with Rate and Duration YES YES YES IDs with Trust Matrix YES YES YES IDs with Reputation Scores YES NO NO Table 5.2: Service Provider’s Level Privacy Breach for Different Collaboration Methods. 5.5 Experimental Methodology 107 5.4.6.3 Privacy Protection at CR In a centralized collaboration, the CR computes GR of subscribers by aggregating information received from the collaborating SP. The use of trusted CR ensures that provided information would not be misused but still has possibility of privacy breach attack by the adversary. The exchange of reputation scores to the trusted CR is not disclosing any information about underlying relationship network of subscribers but adversary or other SP can try to infer some information about target given local and GR scores. The goal of adversary at a CR is to utilize the reputation of the target subscriber and learn his possible relationship network. In some scenarios, the SP itself become adversary and wants to learn relationship network of target belonging to other SP from the received GR and locally recorded CDR of the target. The adversary has the following AUX information at CR: AUX4: The adversary knows LR of target user and other subscribers in a target SP. The adversary also learns that target user only interacts with highly reputed subscribers or subscribers having similar reputation scores. The goal of adversary is to predict possible relationship network of the target user in a target SP. We assume that the communication between CR and collaborating SPs is secure. The exchange of single reputation score ensures privacy protection against AUX 1, 2 and 3 as shown in Tables 5.1 and 5.2 for subscriber level and SP level privacy breach. However, the adversary SP can make a guess about relationship network of target subscriber given AUX 4 but the probability of breach is extremely small and further computationally impossible when the number of reputed subscribers are high. 5.5 Experimental Methodology In this section, we provide an overview of method used for generating the synthetic dataset and the evaluation criteria used for evaluating the performance of proposed detection system. 5.5.1 Synthetic Data-Set We generated a synthetic call detail records using same approach as discussed in chapter 4. Our objective is to generate synthetic CDRs that exhibit similar characteristics to that of the real world CDRs. The communication behavior of the subscriber within the service provider is modeled through three fundamental features such as call-rate, call 108 COSDS: Blocking Spammers with Information Sharing across Multiple Service Providers Figure 5.4: Collaborative Simulation Model. duration and number of unique callees of the subscriber. The communication behavior of legitimate subscriber is different from the spammer in perspective of following three features. Firstly, the legitimate subscriber normally has long duration calls with many of his recipients, whereas SPIT subscriber has large number of short duration calls with his called recipients because recipient disconnects call immediately as soon as he realized that subscriber is a telemarketer or an advertiser [CMP+13], [DTN11]. Secondly, the SPIT subscriber does not exhibit repetitive calling behavior, but legitimate subscribers have repetitive calling behavior with many of his callees [DTN11]. Thirdly, the SPIT subscriber targets large number of recipients thus has high out-degree, whereas the legitimate subscriber has some controlled out-degree. The basis of our synthetic CDRs is a graph representing the social network of the subscribers in a service provider. Vertices represent the calling identity of the subscriber and edges between vertices represent the phone call between two vertices (caller and the callee). In a simulation setup, legitimate subscribers has following distributions for the out-degree, call duration and call rate [AM13]. 1) The degree of legitimate subscriber fits into the power-law distribution [NGD+06]. In order to have a power-law distribution, we modeled the social network of subscriber as a Barabasi-Albert graph model with the average out-degree of 10 [NGD+06]. 2) The call duration of the legitimate subscriber is modeled using exponential distribution with the average call duration of 360 seconds. 3) The call rate of the legitimate subscriber is modeled using Poisson distribution with mean value of 5 calls. The simulation model in Figure 5.4 consists of five VoIP service providers and each service provider has 50000 legitimate callers with different percent- 5.6 Performance Evaluation 109 ages of spammers. The callees of legitimate caller are distributed across all the service providers with 60% of the callees belong to callers registered network and remaining 40% are equally distributed in across other service providers. The spammer usually tries large number of callee. In simulation, spammer calls 10%- to 30% of unique calls per day and each callee is randomly selected from the legitimate caller. The call duration of the SPIT subscriber is modeled through exponential distribution with different average duration i.e. average duration of 180 with few callees and average duration of 60 seconds with majority of callees [CMP+13], [DTN11]. The degree of the SPIT subscriber is randomly chosen between 500 and 4000 [CMP+13] and has non-repetitive calling behavior. The spammer equally distributes callee across all the service providers. We provided results for 2, 3, 4, and 5 collaborators. Each SP consists of 50 thousands legitimate and different percentage of spammers. The collaborating SP computes LR of their subscribers and periodically updates CR with subscriber’s reputation. In a simulation, the SP updates CR after one day and all SPs update CR at the same time. We assume secure communication channel between SP and the CR for the exchange of information. For each scenario, we performed simulations for 10 times and show the average results with standard deviation. 5.5.2 Evaluation Metrics We use the standard information retrieval metrics of True Positive (TP) rate, False Positive (FP) rate and Accuracy (ACC) to measure the spam detection capability of COSDS. The true positive rate is defined as the ratio of the number of subscriber identifies as spammer to the total number of spammers. A legitimate subscriber that is classified as a spam subscriber by the detection system is termed as a false positive. The false positive rate is defined as the ratio of the number of false positive subscriber to the total number of legitimate subscriber in the call record. The evaluation metrics can be explained through the confusion matrix illustrated in a Table 4.1. The TPR, FPR and accuracy is computed as TPR= TP/(TP+FN), FPR = (FP)/(TN+FP) and ACC=(TP+TN)/(TP+TN+FN+FP). 5.6 Performance Evaluation In this section, we present the performance results of COSDS and compare its performance to the performance of Caller-REP and Call-Rank. Additionally, we also provide privacy breach analysis for the different auxiliary information. 110 COSDS: Blocking Spammers with Information Sharing across Multiple Service Providers 5.6.1 True Positive Rate We evaluated detection rate of COSDS and other system for three parameters: TP rate over the time, TP rate against different percentages of spammers, and TP rate against varying number of collaborators. It can be seen from a Figure 5.5 that COSDS approach out-performs other approaches and is able to block almost all spammers within 3 days in any percentage of spammers. Specifically, COSDS manages to achieve a TP rate greater than 80% on a first day which increases further to a 100% TP rate over the time regardless of number of spammers in the network. On the other hand, the non-collaborative CallerREP achieves TP rate of up to 97% in 5 days when the number of spammers are small and prolongs detection time when the number of spammers in the network are high. This behavior is due to the fact that stand-alone detection systems only consider the local view of subscriber while computing direct trust and reputation of the subscriber within the SP. Nonetheless, non-collaborative systems are still capable of identifying local spammers and spammers from the other service providers spamming at a high rate. The improved performance of COSDS is attributed to the followings: firstly, it collectively uses different features while computing local reputation of the subscriber within the service provider; and secondly, SP collaborates for the computation of global reputation. The TP rate of COSDS increases as the number of collaborators increases since more collaborators are providing information about subscriber’s reputation in their network as shown in Figure 5.5. Figure 5.5 also reveals that TP rate increases over the time regardless of number of spammers and it it can also be seen that COSDS achieves almost similar detection rate to that of CDR based collaborative system. From a Figure 5.5, we also observe that the TP rate of COSDS decreases slightly with the increase in the number of spammers and decreases considerably more for the non-collaborative system. Specifically, the TP rate of COSDS decreases to 60% when percentage of spammers varies from 40% to 70% as shown in a Figure 5.9.A. This can be further improved by using SP’s-defined βparameter greater than 1. Figure 5.5 also presents the detection rate of Caller-REP and Call-Rank under varying number of spammers. The detection rate of COSDS is much better than that of Caller-REP and Call-Rank. We observe that Call-Rank has degraded detection rate when compared to the Caller-REP. We can attribute TP rate of Caller-REP and Call-Rank to the following. Call-Rank considers average call duration while computing global reputation of the subscriber which allows spammer having some good duration calls to achieve high reputation scores within the network despite having high out-degree. On the other hand Caller-REP collectively uses call-rate of the caller in both directions, call duration of caller in both directions, and out-degree of the caller which results in a small reputation score to those 5.6 Performance Evaluation 111 (a) 5% Spammer (b) 10% Spammer (c) 20% Spammer (d) 30% Spammer Figure 5.5: True Positive Rate of COSDS for SP trust=1 and βthreshold=1. subscribers having high out-degree and manage some long duration calls. The scalability of the collaborative system is dependent on the number of collaborator participating in collaboration. The results from figure 5.5 show that 4 SP are enough for blocking above 98% of SPIT subscriber regardless of spamming rate. In a scenario where collaboration scores are received from the 50% of the total SPs, COSDS manages to block all spammers in 4 days for a spamming rate of less than 20% and achieves detection rate of more than 90% in 10 days when the number of spammers exceeds 20%. It can also be observed that the detection rate increases and the detection time decreases with the 112 COSDS: Blocking Spammers with Information Sharing across Multiple Service Providers number of collaborators. We also observed that in all simulation scenarios COSDS approach provides almost - but not exactly - similar detection rate as the Direct-CDR approach. This happens despite COSDS preserving privacy and being less computationally and network demanding. 5.6.2 False Positive Rate Although TP rate is the key performance measure for evaluating the performance of SPIT detection system but it should have ideally zero FP rate. The FP rate not only annoys legitimate subscribers and callees but also results in a revenue loss for the SP because of blocking a legitimate subscribers. COSDS outperforms non-collaborative system in terms of FP rate and achieves FP rate of 0% in 3 days when percentage of spammer is high. The non-collaborative Caller-REP suffers from a high FP rate even after 5 days as shown in a Figure 5.6. The FP rate decreases further with the number of collaborators. It can be seen from a Figure 5.6 that with the 5 collaborators COSDS achieves FP rate less than 5% in three days for any percentage of spammers. Specifically, under a small percentage of spammers such as 5% and 10%, COSDS misclassifies large number of legitimate subscribers as spammers on a first few days and further improves it to FP rate of less than 5% within 3 days as shown in Figures 5.6.A and 5.6.B. In a condition of high spamming rate COSDS manges to achieve almost zero FP rate in 2 days with five collaborators as shown in Figures 5.6.C and 5.6.D. The FP rate of non-collaborative Caller-REP and Call-Rank is not acceptable as both have FP rate more than 5% even after 5 days. Specifically, the non-collaborative Caller-REP system has FP rate of more than 15% on first few days and achieves almost zero FP rate in 10 days which is too late. COSDS uses local reputation scores for the computation of global reputation and decision about the subscriber. Some social behavioral features may provide some additional information about subscriber, for example a subscriber cannot be categorized as a spammer if his out-degree is extremely small. The FP rate can be further minimize by allowing SP to utilize other behavioral features along with the received global reputation scores and decision from the CR. Few such features are number of unique callees of the subscriber or ratio between total calls and number of friends. The FP rate can also be minimized by using a fixed threshold βdefined by the SPs according to their requirements. The FP rate of COSDS and collaboration with Direct-CDR is almost similar to each other. 5.6 Performance Evaluation 113 (a) 5% Spammer (b) 10% Spammer (c) 20% Spammer (d) 30% Spammer Figure 5.6: False Positive Rate of COSDS for SP trust=1 and βthreshold=1. 5.6.3 Detection Accuracy The detection accuracy is the proportion of true identification (both true positives and true negatives) to the total number of subscribers (either spammer or legitimate). It characterizes system’s capability of making correct decision about all subscribers (classifying spammer as a spammer and non-spammer as a non-spammer). Under small spamming rate, the COSDS approach achieves high true positive rate with considerably high FP rate. However, under high spamming rate, COSDS manages to achieve better detection rate with a small FP rate. Figure 5.7 shows the detection accuracy of COSDS and other 114 COSDS: Blocking Spammers with Information Sharing across Multiple Service Providers (a) 5% Spammer (b) 10% Spammer (c) 20% Spammer (d) 30% Spammer Figure 5.7: Detection Accuracy for COSDS and non-collaborative system for SP trust=1 and βthreshold=1. approaches when the number of spammers varied from 5% to 30%. COSDS achieves high detection accuracy than non-collaborative system because of collaboration which increases TP rate and decreases FP rate. Our experimental results show that, on an average, the accuracy of COSDS with five collaborator reaches to almost 100% in 4 days for any spamming rate which is much better than non-collaborative system as shown in a Figure 5.7. Specifically, we observe that COSDS reaches an overall accuracy of 99% in 5 days when the number of spammers are small (<10%) and reaches to overall accuracy of 99% in three days when number of spammers are high (>10%). This is due to the fact that 5.6 Performance Evaluation 121 (a) SP Anonymization (b) Percentage of Subscriber Identified Network Figure 5.13: Privacy Breach Analysis for Different Scenarios: A) Probability of Breach for Some Auxiliary Information at SP; B) Percentage of Subscribers whose Relationship network identified to some percentage varying number of reputed subscriber. trolling their number of callees or have to control out-degree. In order to remain undetected by COSDS, spammers need to control their number of callees with repetitive calling behavior. 5.6.7 Privacy Breach Analysis One design consideration of COSDS approach is privacy preservation of relationship links of the subscribers. To estimate the possibility of privacy breach, we simulated the system for two privacy breach models: first, a privacy breach model where an adversary gets access to the local reputation engine and secondly, a privacy breach model where an adversary gets access to the global reputation scores of the subscribers at the CR. In a first privacy breach model, the adversary learns some auxiliary information (callrate, call-time, call duration, out-degree etc.) from the external source and intends to find the anonymized identity of the target subscriber so as to breach the relationship network of the target subscriber. Figure 5.13.A shows the CDF of privacy breach for the different auxiliary information that clearly shows that call time feature is more vulnerable to relationship privacy breach followed by the out-degree feature. We believe that collectively using the out-degree and call-time feature together would further increase the risk of a privacy breach. However, COSDS incorporates identity anonymization along with stripping of the call-time (stripping of seconds and minutes information from the call transactions) 122 COSDS: Blocking Spammers with Information Sharing across Multiple Service Providers thus reduces the risk of relationship privacy breach to almost zero using call-time as an auxiliary feature as shown in a Figure 5.13.A. However, it still vulnerable to the privacy breach using out-degree feature. The risk of privacy breach through use of out-degree auxiliary information can be minimized by using k-anonymized out-degree distribution but it will affect the detection accuracy. In a second privacy breach model, an adversary obtains a part of highly reputed subscribers in a SP from the global reputation scores at CR and intends to make a guess for the relationship network of the target subscriber. The adversary creates predicted obituary relationship network of target subscriber by computing similarity between reputation score of target subscriber and other subscribers in a SP. If the predicted subscriber from obituary reputed list is also part of original relationship network of the target subscriber then we conclude that privacy breach has occurred to some extent. Figure 5.13.B shows the relationship level privacy breach percentages of COSDS approach as the number of subscriber in the adversary generated reputed list varies from 100 to 5000. The results from 5.13.B show the adversary would not be able to get at-least one friend of the target subscriber in his reputed list for more than 60% of the time. Normally, the percentage of relationship privacy breach increases with the increase in the number of subscribers in the obituary reputed list but it would not provide 100 % privacy breach even for high number of subscribers unless the adversary use all subscriber of particular SP in his reputed list. The number of friends in a reputed list can be too spare to form a detectable friendship network for the target. The adversary can guess with high probability that a part of relationship network of the target subscriber is a subset of his generated reputed list (say 10% has high probability shown in Figure 5.13.B), but he still does not have any clue which subscribers are common in adversary generated list and original target’s friends list. Another way to ensure the privacy of collaborators and their customers is to compute global reputation score through Secure Multi-party Computation (SMC) protocols. SMC enables collaborators to carry out computation task without revealing their reputation scores or private data. One such approach to perform encrypted computation is a homomorphic encryption scheme that performs computation on the encrypted data. There are a number of homomorphic schemes for example secure sum [CKV+02] and Paillier encryption [PAI99], which are homomorphic in summation and multiplication. However, the use of homomorphic approach would introduce overhead in computation process and further require evaluation for other performance metrics such as how privacy is protected in presence of malicious and honest but curious collaborators. Moreover, we believe that use of homomorphic encryption or secure sum would not affect the spam detection results of COSDS but would incorporate some additional overhead. 5.7 Discussion on COSDS System 123 5.7 Discussion on COSDS System The spammer may be able to bypass COSDS when it spams to only a few subscribers of the SP and then targets the SP again with a new identity. In this case the CR responds to SP with the same reputation score that the subscriber has within the SP. This can be overcome by binding the number of identities to the IP-address within the SP, linking many identities to same physical person or through imposing cost for a new identity. Linking identity to same physical person is a part of our future work. The spammer can also bypass COSDS by creating calling links between identities from multiple SPs. This allows spammers to call a reasonable large number of recipients but COSDS is able to block these spammers over the time. A new subscriber does not have social links and must be introduced within the SP in order to develop social relationships with their callees. If the SPs do not have any information about subscriber’s local or global reputation then the SPs allow such subscriber to pass through network for few calls. Although the percentile based detection shows resistance against top spammers, there is still much room for improvement with respect to collaboration with more features and classification approach for lowto mid-rank spammers. The detection approach can be improved by incorporating local social network features of the subscriber and a SPsdefined threshold along with the global reputation for final classification. This would minimize the FP rate caused by the low spamming rate and improve TP under high spamming percentage. COSDS can also implemented in a distributed way where the SP collaborate with their directly connected SPs in a privacy protection way. The COSDS approach can also be implemented with other reputation based approaches with slight changes and also involve callee for the final decision. 5.8 Conclusions In this chapter, we have presented a collaborative SPIT detection system called COSDS, which employs collaboration among autonomous SPs for an accurate and early detection of spammers making low rate spam calls to recipients across many SP. The designed system requires collaboration with the exchange of non-sensitive summarized information to the trusted CR, which is not resource demanding regarding system and network resource, and is non-sensitive regarding subscriber’s private information and operational aspects of SP. COSDS computes local reputation of the subscriber from subscriber’s past call transactions within the SP and exchanges it to the CR for reputation aggregation and decisions about behavior subscriber. Our evaluation on synthetic data show that the COSDS 124 COSDS: Blocking Spammers with Information Sharing across Multiple Service Providers approach is very effective in detecting spammers, has reduced the detection time and provides privacy protection to the collaborating SPs. Specifically, it out-performs SAS in terms of detection time and accuracy, and achieves considerable same detection accuracy when collaboration is carried out through the exchange of CDRs and direct trust scores. Chapter 6 EIS: Early Identification of Spammers 6.1 Introduction In recent years, telecommunication networks have seen a dramatic increase in the number of subscribers around the world. According to GSMA statistics, there are more than 7 billion mobile users in total and more than 4 billion unique mobile users across the world. Malicious users can also acquire large number of identities to gain financial benefits because of spamming, advertisements and phishing attacks. Users having multiple identities are able to evade the defense against spamming by pretending to be multiple, distinct individual in the network. Multiple identities can be misused to spread malicious information and spams. A spamming individual with multiple identities can use some of its identities to provide high recommendation to its other identities so to increase their reputation and evade detection system. Recent statistics revealed that Facebook has 1.23 billion active users and of which more than 90 million accounts are duplicate [FAC14]. This means that multiple accounts are owned by one individual and are mainly used for the malicious activities. A Phoneypot [GSB+15] study over seven weeks reveals that 36,912 unique phonetokens have received 1.3 million calls from the total of 252,621 unique sources. This can be attributed to the fact that telephony users receive large number of spam calls when scaled over a large number of users. Spammers in the telephony are more intrusive, require immediate response from call recipients and undermine the use of telephony for legitimate users. Traditional reputation-based spam detection systems utilize user’s identity for combating spamming activities [KER11], [AM13], [TDZ+16]. If spammers make spam directly from one known identity to victims, they would be easily blocked by the spam detection system. However, spammers are adopting new ways to evade the spam detection systems 125 126 EIS: Early Identification of Spammers and stay undetected for unsolicited calls by acquiring large number of identities. Spammers can have a large set of calling identities for small cost and effectively obfuscates these calling identities to evade the spam detection systems. Although the spammer can have many identities but their victim network largely remains the same. Furthermore, spammer is not able to develop a strong social network with legitimate users from his different calling identities. The service provider requires an effective spam detection system against spammers having multiple identities in order to improve the experience of users, to ensure the trustworthiness of services provided and positively gain trust of customers. Recently, several approaches have been proposed to link profiles of an individual across different and same social networks. These approaches estimate similarity between two profiles that belongs to one physical individual by using several features in three dimensions: 1) attempt to connect similar profiles owned by an individual by using social network structure of an individual across different social network platforms [ACF13], 2) attempt to estimate the similarity in profiles (age, sex, religion, location, name) of an individual on a two different social network platforms [VHS09,LWZ+14], and 3) attempt to measure the similarity in content posted by an individual on both platforms. In telephony, applying these features for connecting similar identities is not straight forward. Content-based similarity measure cannot be applied in telephony because content in telephony is speech which is resource intensive in terms of storing, retrieving and processing. As there is no profile information available in telephony, the feasible option left is social network connections of identities for estimating the similarity between identities. The information from user’s social network connections have also been used for linking profiles of an individual from different social networks [ACF13], [JKJ13], but these approaches have only considered network connections and did not consider connectivity strength of an individual with others. This chapter presents EIS (Early Identification of Spammers), a novel system that limits and blocks set of identities that are owned by a same spamming individual in a VoIP and voice networks. We exploit the notion that spammers can have multiple identities but they cannot establish strong connection with honest users and also have similar set of victims with similar calling behavior. The basic idea is that if the spammer has many identities, his social call graph become same in the sense that it has many common users between his identities. Our design is based on a use of call patterns and social network graph of identities. EIS system consists of three modules. 1) An ID-CONNECT module that connects similar identities that belongs to one physical person or individual by utilizing social network structure and calling behavior of identities. 2) A reputation computation module that computes reputation of an individual by using call-duration, call-rate and out-degree of the individual. 3) A spam detection module that flagged individual as 6.1 Introduction 127 a spammer if reputation of the individual is less than automated dynamic threshold. To the best of our knowledge, our work is the first that utilizes weighted call graph for linking similar identities together in a voice network and uses identity linking for a spammer identification. We evaluate our proposed approach through experimental study using a synthetic graph dataset for the number of graph models and different spamming behaviors. We find that the proposed approach achieves high linking rate with a small candidate set size and is effective for the early identification of spammers frequently changing their identities. We believe that EIS system can be easily applied for connecting similar profiles in social networks by analyzing the social structure of profiles. In summary, this chapter makes the following contributions: •We introduce an ID-CONNECT system, a social network and behavior based model that links similar identities that probably belongs to a one physical individual. In ID-CONNECT, the weights on the links between identities are computed from the interaction rates and length of interactions. Individuals, especially spammers normally exhibit similar call behavior and have overlap in victims from their many identities. Two identities can only be considered as similar if they have common friends and have similar calling behavior towards common friends. ID-Connect is a two-step approach: firstly, it estimates the weighted similarity measure between identities by considering the call behavior of identities towards their common friends. Secondly, it generates candidate set for the given identity using fixed thresholds. •A reputation engine that computes reputation of the individual by using call-rate, call duration and out-degree of the individual after connecting his identities. The input to the reputation engine is the data of linked identities formulated from the IDCONNECT module. We believe that reputation computed after linking identities of an individual and analyzing his aggregate calling behavior would greatly separate spammers from the non-spammers. •A detection module for computing automated classification threshold below which individuals are flagged as spammers. A dynamic automated threshold is being computed for each reputation cycle using the percentile based approach. •We validate and evaluate EIS system through a comprehensive simulation study using a synthetic data set that we have generated using true behavior of spammers and non-spammers. The experimental results show that EIS system outperforms other identity linking systems and has shown effective resistance against spammers having many identities. 128 EIS: Early Identification of Spammers The rest of the chapter is structured as follows. Section 6.2 presents scenarios where users can have more than one calling identity and will provide definition of the identity linking and spam detection problem in a voice network. Section 6.3.1 overviews the procedure by which the proposed approach link identities together to be used for computing aggregate reputation of an individual and detection of the spammer. Section 6.4 explains our data generation process and presents some performance evaluation metric. Section 6.4 presents experimental results for different network models and different percentages of spammers. Section 6.5 provides discussion on an EIS system and finally, conclusions and future works are presented in Section 6.6. 6.2 Motivation and Problem Definition In this section, we discuss the problem of spamming in a voice network, why legitimate users own more than one calling identity and define identity linking problem in a voice network. Furthermore, in section 6.2.5 we provide some necessary background definitions about social call graphs used towards design of identity linking system. 6.2.1 Spammer Network In VoIP and other communication network (email, social network etc.), a legitimate user can receive spam calls and messages from several spam identities. It might be possible that several spamming identities are owned by one physical person or controlled by a one botnet. In email network, it is estimated that there exist more than 20% overlap in the distribution lists of the typical spammers [GCA+04] [JMG+09]. This large overlap is because of the fact that spammers normally use automatic ways to create the target identities, harvests identities or acquires identities of targets from some sources and launched spam attack from their different identities. The larger overlap in victim is also due to a fixed number of users in the network. In VoIP and mobile network acquiring a new identity is virtually not very costly, support plug and play, and can be easily integrated with the spamming systems over the Internet. A Phoneypot [GSB+15] study over two months reveals that 36,912 unique phonetokens have received 1.3 million calls from the total of 252,621 unique sources. This can be attributed to the fact that few unique sources share similar victims as many unique sources called phonetokens only once. The spamming model of the spammer is presented in a Figure 6.1. 6.2 Motivation and Problem Definition 129 Figure 6.1: Attack Network of Spammer. 6.2.2 Why Users Have More Than One Identity The number of active mobile connections around the world stands at more than 7 billion1 and there are many countries where number of active cellular users are more than country’s population. For example, Russia has 1.8 times more active cellular users than its population. This does not mean that every person in the country has exactly one mobile phone but can be attributed to a large number of people owning multiple calling identities. Legitimate users can have multiple calling identities for various reasons such as business and personal communications or to take advantage of cheap calling plans for the local and long distance calls. In addition to legitimate users, there are also non-legitimate users: users that are involved in illegally obtaining financial benefits by tricking people with scams. Spammers can purchase a large number of calling identities for free2or with minimal cost 3and can use them from anywhere across the world with a simple Internet connection. Multiple calling identities can be misused to spread the malicious information and spams. The reputation of an individual is associated with the calling identity. A spamming individual can have many identities to defeat the reputation system by pre1GSMAIntelligence https://gsmaintelligence.com/ 2google voice, inum 3http://www.voipfone.co.uk/ 130 EIS: Early Identification of Spammers tending that identities belong to multiple individuals. A spamming individual with many identities can also use some of its identities to provide high recommendation to its other identities so to increase their reputation and evade detection system. Furthermore the use of Do not call lists in many countries also induce system abusers to frequently change their identities so to reach their targets without being blocked. 6.2.3 Motivation A spammer can have more than one calling identity either by buying identities or faking identities of legitimate users. The spammer then uses these identities to target the legitimate users of the service provider. Connecting identities that belong to the same individual would provide detailed view about the behavior of the individual. In the spam detection domain, the linking of multiple identities of spammers would help in early identification of spammers and minimize the chances of Phishing and identity theft attack in a telecommunication network. One way to limit the number of identities to one individual is to cap the number of identities any single person can buy or impose some extra cost for buying identities. However, this still does not ensure that acquired identities would not be used for non-legitimate activities and it would also require a mechanism for linking similar identities if not properly linked at the time of identity purchase. However, in telephony identities can be acquired with minimal cost and plug and play is straightforward as users can buy SIM card or VoIP identity and start using. Another possible way to link identities is to link IP address in-case of VoIP and IMEI number (International mobile Equipment Identity) in-case of Mobile to link the identity and logs records of which identity belongs to which IP-address and IMEI. However acquiring new IP-address is not costly and the IMEI number can be manipulated. There is a strong need to have a system that automatically links similar identities together using calling behavior of identities and further use this to identify spammers and criminal rings. The Spam detection systems presented in Chapters 4and 5decide about status of subscriber as a spammer or a non-spammer on the basis of observed call patterns for a specific subscriber identity. Since there is no identity linking, the spammer can easily bypass such system by simple changing their identity or whitewashing their global reputation system and rejoining the network. An important feature which can be used to distinguish spammers from non-spammers is the overlap in victims from spammer different identities and similar call behavior towards the overlapped victims. Beside spam detection, identity linking would also be effective for characterizing behavior of legitimate user for their different identities and identification of criminal groups.