Telecom 2 min read

Integrating anti-fraud systems in telecom using modern methods

An analysis of modern telecom fraud prevention methods through real-time integration of Softswitch, billing, and anti-fraud systems.

Integrating anti-fraud systems to combat telecom fraud

According to the CFCA Global Fraud Loss Survey, global losses from telecom fraud in 2025 are estimated at $41.82 billion. Traditional CDR analysis with a delay of several hours no longer protects operators from high-speed IRSF (International Revenue Share Fraud) attacks. Effective prevention requires a shift from isolated systems to an integrated, real-time engineering approach.

The architectural triangle: Softswitch, billing, and anti-fraud

Modern telecom network security relies on low-latency interaction (up to 50–100 milliseconds) between three key components:

  • Softswitch: responsible for signaling and directly blocking or terminating calls.
  • Billing system (OCS/BSS): monitors subscriber balances and limits in real time.
  • Anti-fraud platform (FMS): analyzes behavioral factors, number reputation, and detects anomalies.

When a call request is received, the switch must not route traffic without parallel confirmation from both the billing and anti-fraud systems. If signs of fraud are detected, the system instantly triggers a command to terminate the connection.

Technological standards and limitations

To modernize infrastructure, operators adopt TM Forum's Open Digital Architecture (ODA) principles, transitioning from monolithic systems to microservices via API-first interfaces. The STIR/SHAKEN framework is also used for Caller ID authentication. However, since it only protects against spoofing, it must be combined with behavioral analysis to defend against calls from compromised legitimate devices.

What changes for the sector

Failing to transition from delayed CDR analysis to real-time systems exposes operators to devastating high-speed IRSF attacks, contributing to the multi-billion dollar global fraud drain. Without integrated security, telecom businesses face direct financial losses and a severe decline in subscriber trust.

Action plan

  • Establish low-latency interaction (50–100 ms) between the Softswitch, billing, and anti-fraud systems to block fraudulent calls instantly.
  • Transition from monolithic systems to microservices via API-first interfaces using TM Forum's Open Digital Architecture (ODA) principles.
  • Combine the STIR/SHAKEN framework with behavioral analysis to defend against both Caller ID spoofing and compromised legitimate devices.

Prepared by a Software Ukraine member. Original publication.

Sources & materials

Intecracy Group products and solutions referenced in this article.

  1. DooxSwitch — dooxswitch.com