The spoofing problem and SIP network vulnerabilities
Global telecom fraud losses reached approximately $41.82 billion in 2025. Caller ID spoofing remains the primary attack vector, as basic signaling protocols lack built-in mechanisms to verify call origin. Attackers exploit this for phishing, impersonating government agencies, and bypassing interconnect billing.
Cryptographic protection with STIR/SHAKEN
To verify number legitimacy, the STIR/SHAKEN standards were developed:
- STIR (RFC 8224): defines the cryptographic signing of call information using a JWT token in the Identity header.
- SHAKEN: regulates certificate management and technology deployment guidelines at the telecom infrastructure level.
The signing carrier assigns one of three attestation levels to the call: full (Level A), partial (Level B), or gateway (Level C). Based on these levels, the terminating carrier can label or block calls.
Technical challenges and solution integration
The main obstacles to technology adoption are metadata loss during transit through legacy TDM segments and the high computational load on session border controllers (SBCs) during request validation.
To effectively combat fraud, cryptographic verification must work in synergy with anti-fraud analytics. Modern carrier platforms, such as DooxSwitch, enable the integration of authentication mechanisms into call routing workflows. Meanwhile, platforms like UnityBase provide reliable certificate registry management and incident logging at the carrier backend level.
Why it matters for the industry
Implementing these standards allows the telecom industry to mitigate multi-billion dollar fraud losses and restore user trust in voice calls. However, carriers must adapt to the increased computational load on session border controllers and address transit issues across legacy network segments to prevent call dropouts.
What to do next
- Integrate authentication: Use modern carrier platforms like DooxSwitch to embed STIR/SHAKEN cryptographic verification directly into call routing workflows.
- Manage certificates: Deploy backend solutions like UnityBase to ensure reliable certificate registry management and comprehensive incident logging.
- Combine defenses: Pair cryptographic verification with anti-fraud analytics to effectively identify and block spoofed calls.
Prepared by a Software Ukraine member. Original publication.