Henning Schulzrinne IETF 97

Slides:



Advertisements
Similar presentations
August 2, 2005SIPPING WG IETF 63 ETSI TISPAN ISDN simulation services Roland Jesske Denis Alexeitsev Miguel Garcia-Martin.
Advertisements

SIP, Presence and Instant Messaging
Fall IM 2000 Introduction to SIP Jonathan Rosenberg Chief Scientist.
Fall VoN 2000 SIP for IP Communications Jonathan Rosenberg Chief Scientist.
Early Media Authorization Under what conditions should negotiated media flow prior to 200 OK (INVITE)? Richard Ejzak.
Lab Telemàtica II: VoIP 2008/2009 Anna Sfairopoulou Page 1 Advanced services with SIP.
Session Initiation Protocol (SIP) By: Zhixin Chen.
A Generic Event Notification System Using XML and SIP Knarig Arabshian and Henning Schulzrinne Department of Computer Science Columbia University
Numbering Update HENNING SCHULZRINNE JUNE 4, 2015.
PREVENTING CALLERID SPOOFING Henning Schulzrinne FCC draft-peterson-secure-origin-ps-00.
Pro Exchange SPAM Filter An Exchange 2000 based spam filtering solution.
1 Kommunikatsiooniteenuste arendus IRT0080 Loeng 8 Avo Ots telekommunikatsiooni õppetool, TTÜ raadio- ja sidetehnika inst.
Instructore: Tasneem Darwish1 University of Palestine Faculty of Applied Engineering and Urban Planning Software Engineering Department Requirement engineering.
RPIDS - Rich Presence Information Data Format for Presence Based on the Session Initiation Protocol (SIP) Henning Schulzrinne (ed.) Vijay Gurbani Krisztian.
1 © NOKIA 1999 FILENAMs.PPT/ DATE / NN SIP Service Architecture Markus Isomäki Nokia Research Center.
The Internet 8th Edition Tutorial 2 Basic Communication on the Internet: .
Session Initiation Protocol (SIP). What is SIP? An application-layer protocol A control (signaling) protocol.
NO-CALL LAW ENFORCEMENT SUMMIT Technology Update: The Future of Call Blocking and Caller ID Authentication Henning Schulzrinne – FCC & Columbia University.
CP-a Emergency call stage 2 requirements - A presentation of the requirements from 3GPP TS Keith Drage.
November 2005IETF64 - ECRIT1 Emergency Service Identifiers draft-ietf-sipping-sos-01 draft-schulzrinne-sipping-service-01 Henning Schulzrinne Columbia.
SIP:Session Initiation Protocol Che-Yu Kuo Computer & Information Science Department University of Delaware May 11, 2010 CISC 856: TCP/IP and Upper Layer.
Omar A. Abouabdalla Network Research Group (USM) SIP – Functionality and Structure of the Protocol SIP – Functionality and Structure of the Protocol By.
SIP and MMS Jonathan Rosenberg Chief Scientist. SIP What Is It? European Technology for Enhanced Messaging Specified by 3GPP, WAP Forum Different.
Detection and Mitigation of Spam in IP Telephony Networks using Signaling Protocol Analysis MacIntosh, R Vinokurov, D Advances in Wired and Wireless Communication,
Outlines Overview Defining the Vision Through Business Requirements
S Postgraduate Course in Radio Communications. Application Layer Mobility in WLAN Antti Keurulainen,
Postech DP&NM Lab Session Initiation Protocol (SIP) Date: Seongcheol Hong DP&NM Lab., Dept. of CSE, POSTECH Date: Seongcheol.
ECRIT - IETF 62 (March 2005) - Minneapolis 1 Requirements for Emergency Calling draft-schulzrinne-sipping-emergency-req-01 draft-ietf-sipping-sos-01 Henning.
Paypal PayPal is an e-commerce business allowing payments and money transfers to be made through the Internet. With a PayPal account, you can send and.
I Travel Booking Training
Timeline – Standards & Requirements
Presented by: Rebekah Johnson CEO/President Gloria-Mac
THIS IS THE WAY ENUM Variants Jim McEachern
User Needs Group (UNG) Status Report to the Commercial Mobile Service Alert Advisory Committee September 19, 2007 Gary K Jones, UNG Deputy Chair.
Timeline - ATIS Involvement
PAYMENT GATEWAY Presented by SHUJA ASHRAF SHAH ENROLL: 4471
SIX MONTHS INDUSTRIAL TRAINING REPORT
Kumiko Ono End-to-middle Security in SIP draft-ietf-sipping-e2m-sec-reqs-04 draft-ono-sipping-end2middle-security-03 Kumiko Ono.
Session Initiation Protocol
Deploying IP Telephony
STIR WG / IETF 97 Seoul, Nov 2016 Jon
Session Initiation Protocol (SIP)
Requirements and Implementation Options for the Multiple Line Appearance Feature using the Session Initiation Protocol (SIP) draft-johnston-bliss-mla-req-00.
Chris Wendt, David Hancock (Comcast)
Timeline - ATIS Involvement
OUT OF THE BOX HOW TO USE THE SYSTEM
Membership/Post Processing - Process Membership
Verstat Related Best Practices
Presented by: Rebekah Johnson CEO/President Gloria-Mac
Hannes Tschofenig Henning Schulzrinne M. Shanmugam
Digital $$ Quiz Test your knowledge.
Henning Schulzrinne Columbia University
draft-ipdvb-sec-01.txt ULE Security Requirements
RFC PASSporT Construction 6.2 Verifier Behavior
RFC PASSporT Construction 6.2 Verifier Behavior
HOW DO I KEEP MY COMPUTER SAFE?
SIP RPH and TN Signing Cross Relationship
What is BankMobile? A process to select how to receive student refunds and student payroll payments It is fast, secure, and convenient. Go to:
Communications Relationships
Change Proposals for SHAKEN Documents
Website Usage Guide for Patient
SIP RPH Signing Use Cases
RPIDS and tuple issues Henning Schulzrinne with help from Paul Kyzivat
It’s a Scam Prepared by Lamanda Weston
Henning Schulzrinne Columbia University
Robocalling Blocking Cause and Effect
Policy enforcement and filtering for geospatial information
Calling Party Identity
STIR / SHAKEN for 911 use of SHAKEN 8/7/2019
Partner Portal Training document
Presentation transcript:

Henning Schulzrinne IETF 97 Robocall signaling draft-schulzrinne-dispatch-callinfo-spam-00 draft-schulzrinne-dispatch-status-unwanted-00 Henning Schulzrinne IETF 97

Background (for the un-STIRed and un-SHAKEN) Unwanted calls are typically some are illegal, some are just unwanted (by many) example: “this is the Internal Revenue Service; pay $2,000 or you will be arrested”; followed by “this is your local police department; did you pay?” typical scams and illegal telemarketing: tech support, ”you won a trip” (for a small fee), competitive utility sign-up, annoying to many, but possibly legal: charity, political, survey Some robocalls are actually wanted (and helpful) “your prescription is ready”, “doctor’s visit tomorrow”, “snow day”, “boil your water” but may be confused with unwanted calls Enabled by cheap VoIP – particularly international calls hard-to-track programmable SIP end systems including calling party (caller ID) spoofing anonymous money transfer

STIR + SHAKEN Chris Wendt, SIPNOC 2016

Architecture “analytics” “big data” check 4474bis signature look up category based on number (optional) indicate probability(spam) carrier ”signature valid” ( verstat) ”survey” SIP proxy external service 4474bis 666 Unwanted

Motivation & assumptions Some carriers will do their own filtering, but … Some carriers may need/want to leave that to third-party tools May also want on-device handling: forward to voice mail display information and leave decision to called party consult app for decision consult address book make time-of-day dependent: no surveys or charity while I’m sleeping (in Korea) Simple user interface for reporting similar to spam button that exist on most email clients

draft-schulzrinne-dispatch-callinfo-spam Conveys information from carrier (SBC, CSCF) to UA Parameters: spam: estimated likelihood of spam (0-100%), i.e., measure of uncertainty could be related to what fraction of called parties label it as spam type: type of caller for VoIP home gateways, could be displayed via caller ID (CNAM) reason: source of data mostly, for debugging; similar to some email headers source: domain of entity inserting data Example: Call-Info: <http://wwww.example.com/5974c8d942f120351143> ;source=carrier.example.com ;purpose=info ;spam=85 ;type=fraud ;reason="FTC list"

Call categories Category Description business placed by businesses, i.e., an entity or enterprise entered into for profit. This type is used if no other, more precise, category fits. debt-collection collecting of debt owed or alleged to be owed by the called party emergency-alert provide the recipient warnings and alerts regarding a pending or on-going emergency. (unrelated to emergency calls to 9-1-1 or 1-1-2. Includes alerts related to weather-related school closings.) fraud considered to be fraudulent. government government entity, if no more specific label such as "health" or "debt-collection" is known or applies. health informational calls by health plans, … health care provider, … informational information about a transaction: package delivery, appointment reminder, order confirmation not-for-profit not-for-profit organization, including for soliciting donations or providing information

Call categories Category Description personal A non-business, person-to-person, call, e.g., from a residential line or personal mobile number political elections or other political purposes public-service Calls that provide the recipient information regarding public services, e.g., school closings spam likely unwanted, if not otherwise classified spoofed calling number for this call has been spoofed survey solicits the opinions or data of the called party telemarketing placed in order to induce the purchase of a product or service to the called party trusted The call is being placed by a trusted entity and falls outside the other categories listed. This may include call backs, e.g., from a conferencing service, or messages from telecommunication carriers and utilities.

SIP Global Feature-Capability Indicator Must avoid insertion by malicious entities Thus, UA ignores unless “sip.call-info.spam” is a feature tag in REGISTER response If supported, proxy must strip Could be part of PASSPorT claim in the future if end systems validate RFC4474bis Q: Right label & registry?

Non-editorial changes to be made for -01 “prisons” as a category meant to be mutually exclusive

draft-schulzrinne-dispatch-status-unwanted Signal ”not wanted anywhere” – 666 Calling SBC/proxy actions: ignore unwanted[“202-555-1234”]++  labeling algorithm place on personal block/blacklist for user details are (intentionally) not specified by draft (just like spam button) Special cases: call forwarding: Alice handles Bob’s call while Bob is on vacation policy problem – Alice can already report spam calls (e.g., via FTC/FCC web site) similar to email with SMTP-level mail redirection forking diversity of opinion on spaminess – seems unlikely to be a problem

Non-editorial changes to be made for -01 More discussion of user interface? More elaborate feedback options?