HomeSecuritySpecial tips for preventing attacks - fraud incidents in telecommunications centers

Special advice for preventing attacks - fraud incidents in telecommunications centers

In the context of preventing the phenomenon of telecommunications fraud incidents that occur in business telecommunications centers through "attacks" that exploit possible security gaps, the Cybercrime Prosecution Sub-Directorate recommends the following:

Command-Control

Regarding the security gaps of call centers, the following are suggested:

  • Disabling pre-installed passwords on PBX maintenance ports.
  • Periodic change of access passwords on the maintenance ports of PBXs by certified engineers.
  • Choose codes consisting of at least 7 digits with a combination of alphanumerics, digits and symbols.
  • Each device must have an independent password and not extensions.
  • Installation/Activation of recording of incoming/outgoing files (CDR recording software).
  • In the case where PBX access to the internet is not required, we disable it. If it is necessary for the center to have access to the internet, it is advisable to use Firewalls.
  • If deemed necessary, it is considered appropriate to limit the source IPs that can access the center's open doors.
  • In the case of IP PBX, we allow access from clearly predefined terminals.
  • Proper management of authorized codes for blocking outgoing calls.
  • Configuration of equipment in such a way that no connection to external networks, call forwarding, etc. is allowed except for those that have been determined as absolutely necessary for the operation of the services of each user.
  • Deactivation of the ability to program forwarding to foreign numbers. Creation of groups in the call center with specific capabilities depending on the needs.
  • Disable allow guest in SIP Configuration.
  • Enable remote access only when necessary, otherwise it remains disabled.
  • Informing users about potential risks.
  • With regard to the installation of call centers, security of access to the communications area is important, such as:
  • Security door installation.
  • Granting access keys only to authorized personnel related to equipment maintenance.
  • Keeping entry and exit records on site.
  • Regarding the services provided by the providers:
  • Providers allow their customers, upon their request, to not forward calls to foreign destinations.
  • Providers regularly check the daily unbilled traffic of the current month carried out by each call center in order to identify unusual increased charges in a timely manner, for which customers are then informed.
  • In the event of fraud, the provider gives the customer the option of activating temporary or permanent blocking of outgoing calls to the specific destinations to which the calls in question were identified.

It is noted that the operation, use, management, maintenance and upgrade of telecommunications centers of enterprises is the exclusive responsibility of the enterprises themselves.

 

Source: secnews.gr

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS