How Does STIR/SHAKEN Authenticate Caller ID?

805 views
•
February 6, 2019
by
RSAC Cybersecurity
YouTube video player
How Does STIR/SHAKEN Authenticate Caller ID?

TL;DR

STIR/SHAKEN helps combat illegal caller ID spoofing by digitally signing and verifying the telephone number associated with a SIP call. STIR defines the signing protocols, while SHAKEN supplies interoperable implementation guidelines. Successful verification can support call delivery, while failed verification can trigger a warning or call rejection according to the receiving provider's policy.

Transcript

Hi, I'm Daksha Bhaskar, and I would like to welcome you to my session, STIR/SHAKEN SIP to Stop Robocalling. As tax season is upon us, we can expect to see a surge in robocalls on this topic. This call officially a final notice from IRS, Internal Revenue Service. The reason of this call is to inform you that IRS is filling a lawsuit on your name bec... Read More

Key Insights

  • Illegal robocalling is the number one consumer complaint in the United States, United Kingdom, and Canada according to the presentation. Its continued growth is linked to sharply reduced calling costs and software that allows a single internet-connected computer to place thousands of calls in an hour.
  • Phone-based tax scams caused more than 12,000 victims to pay over $63 million collectively from October 2013 through the period discussed. Criminals use robocalls and spoofed caller IDs to impersonate IRS officials and pressure victims into paying bogus tax bills.
  • Caller ID spoofing is the practice of displaying a telephone number different from the number actually originating the call. It makes validating a call's origin difficult and allows criminals to appear to be calling from a trusted person, organization, or government agency.
  • Robocalling is not inherently malicious because automated calls can have legitimate uses. Caller ID spoofing can also be legitimate, and the two techniques do not always occur together, which makes accurately detecting and flagging only illegal calls technically challenging.
  • STIR is a standard called Secure Telephone Identity Revisited that defines protocols used with SIP to apply digital signatures to calling-party telephone numbers. Its purpose is to support authentication of the telephone number presented during call setup.
  • SHAKEN is an implementation framework for STIR that helps network equipment vendors and service providers deploy the protocols consistently. Its guidelines reduce the risk that differing provider implementations will create interoperability problems across interconnected voice networks.
  • The originating authentication server is responsible for authenticating the caller and confirming that the caller is authorized to use the telephone number placed in the SIP invite. It then constructs and signs an identity token that travels with the call request.
  • The receiving verification service is responsible for checking the identity token's signature using public keys available through a certificate repository. A successful result permits normal delivery, while an unsuccessful result can cause the call to be flagged, delivered, or dropped according to policy.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What problem does STIR/SHAKEN address?

STIR/SHAKEN addresses the difficulty of validating a telephone call's origin when callers can spoof the number shown on caller ID. It creates a foundation for real-time authentication of telephone numbers used in SIP calls. This authentication can help service providers identify illegal spoofing associated with robocalling while recognizing that automated calls and altered caller IDs may also have legitimate uses.

Q: How does STIR/SHAKEN authenticate a SIP call?

The originating user agent sends a SIP invite containing a telephone number to its domain's authentication server. That server authenticates the caller, verifies authorization to use the stated number, creates a digitally signed identity token, and adds it to the invite. The receiving domain's verification service then checks the signature using public keys obtained from a certificate repository.

Q: What is the difference between STIR and SHAKEN?

STIR, or Secure Telephone Identity Revisited, defines protocols for applying digital signatures to the telephone numbers of calling parties within SIP. SHAKEN provides the framework and implementation guidelines for deploying STIR. Those guidelines help network equipment vendors and service providers build compatible implementations, reducing interoperability problems that could result from different deployment choices across networks.

Q: Why is caller ID spoofing difficult to stop?

Caller ID spoofing lets a caller display a telephone number different from the number actually placing the call, making the call's origin difficult to validate. Detection is further complicated because spoofing is not always connected to robocalling and can have legitimate uses. Technology must therefore distinguish malicious impersonation from acceptable calling practices rather than simply block every call with an altered identity.

Q: Are all robocalls spoofed or fraudulent?

No. The presentation emphasizes that not every robocall is spoofed, not every spoofed call is a robocall, and both practices can have legitimate uses. An unwanted robocall involves repeated prerecorded calling without consent, while spoofing concerns the displayed caller number. Their partial overlap makes it difficult for automated defenses to identify and flag only illegitimate calls without affecting acceptable communications.

Q: What happens when STIR/SHAKEN verification fails?

A failed signature verification does not require one universal outcome in the conceptual framework described. The receiving provider can still send the call to the recipient with a warning or flag, or it can drop the call, depending on the configured policy. This allows the authentication result to inform call handling while leaving the final response to the receiving network's rules.

Q: Why have illegal robocalls become so widespread?

Illegal robocalling has expanded because making telephone calls has become significantly cheaper and open source software can generate automated calls with configurable source numbers. According to the presentation, one computer connected to the web can place thousands of calls per hour. About 5.1 billion robocalls were placed in November 2018 alone, with slightly fewer than half related to scams.

Q: How are IRS impersonation scams connected to robocalling?

Criminals combine robocalling with caller ID spoofing to impersonate IRS officials and claim that a victim faces a lawsuit or other legal action over supposed tax fraud. They then pressure the victim to send money for bogus tax bills. Phone scams had appeared on the IRS Dirty Dozen list every year since 2014 at the time of the presentation.

Summary & Key Takeaways

  • Illegal robocalling is a major consumer problem because cheap calling technology and readily available open source software let one internet-connected computer place thousands of calls per hour. Criminals often combine prerecorded calls with caller ID spoofing to impersonate trusted organizations, including the IRS, and demand payments for bogus tax bills.

  • Detecting illegitimate calls is difficult because robocalling and caller ID spoofing are separate behaviors with legitimate as well as malicious uses. Not every robocall uses a spoofed number, and not every spoofed call is automated. Effective defenses therefore need to validate calling identities without automatically treating every automated or altered call as fraudulent.

  • STIR defines SIP protocols for digitally signing calling telephone numbers, while SHAKEN provides implementation guidance for interoperable deployment. An originating authentication server validates the caller's authority to use a number and signs an identity token. The receiving verification service checks that signature through public keys stored in a certificate repository before applying its call policy.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚