Spoofing Against Spoofing: Towards Caller ID Verification In Heterogeneous Telecommunication Systems
Shen Wang, Mahshid Delavar, Muhammad Ajmal Azad, Farshad Nabizadeh,, Steve Smith, Feng Hao

TL;DR
This paper introduces CIV, a PKI-free caller ID verification method that uses challenge-response and leverages spoofing to combat caller ID spoofing across heterogeneous telecommunication systems, including IP and non-IP networks.
Contribution
It presents the first working prototype of a caller ID verification system applicable to VoIP, cellular, and landline phones, supporting heterogeneous networks without relying on PKI.
Findings
CIV effectively authenticates caller IDs across different telecom systems.
Spoofing is used innovatively to implement challenge-response verification.
The system can be integrated into telecom clouds for scalable deployment.
Abstract
Caller ID spoofing is a global industry problem and often acts as a critical enabler for telephone fraud. To address this problem, the Federal Communications Commission (FCC) has mandated telecom providers in the US to implement STIR/SHAKEN, an industry-driven solution based on digital signatures. STIR/SHAKEN relies on a public key infrastructure (PKI) to manage digital certificates, but scaling up this PKI for the global telecom industry is extremely difficult, if not impossible. Furthermore, it only works with IP-based systems (e.g., SIP), leaving the traditional non-IP systems (e.g., SS7) unprotected. So far the alternatives to the STIR/SHAKEN have not been sufficiently studied. In this paper, we propose a PKI-free solution, called Caller ID Verification (CIV). CIV authenticates the caller ID based on a challenge-response process instead of digital signatures, hence requiring no PKI.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsIPv6, Mobility, Handover, Networks, Security · Internet Traffic Analysis and Secure E-voting · Advanced Authentication Protocols Security
