| Cases |
Hubs | Hubbers | Topics | Request |
| #1 in Business | Subscribe Email Print |
|
You are here: Home > Business > Business > Prevent Your Business From Falling Victim To Dial Through Fraud |
|
Cases - Prevent Your Business From Falling Victim To Dial Through Fraud
What steps would you take to protect your business from a burglar coming in after office hours and stealing ?40,000? I suspect that you would make sure that all the doors have very good locks. You would install a burglar alarm and maybe even have CCTV surveillance. That should protect your business. Wrong! The burglar did not break into your office; they broke into your internal phone exchange (P According to USFDA, a combination product is one composed of any combination of a drug and device; biological product and device; drug and biological product BX). Unseen by human or electronic eyes, thousands of pounds are being spent on international telephone calls and your business will pay the bill. How Does It Work? Dial through fraud is not a new problem, it just has limited publicity. It exploits a PBX feature that allows employees to ring in to the switchboard and by keying certain dialling codes, make national and int ; or drug, device, and biological product and fixed dose combination would include two or more combinations of drug. Examples of combination products may in rnational calls for which the company will pay the bill. Many businesses will take an "It will never happen to me" approach to dial through fraud, even though most business PBXs are setup to be maintained remotely. This is to allow engineers from a maintenance company to make changes to the configuration without needing to make a site visit but it exposes the PBX. The administration port on the lude drug-coated devices, drugs packaged with delivery devices in medical kits, and drugs and devices packaged separately but intended to be used together. PBX will be connected to a modem that in turn is connected to an extension on the PBX. Using trial and error, hackers will identify the number that this modem is on. The default passwords like "admin", "0000" or "1234" will be tried first. Even if the password has been changed, there are plenty of free utilities on the Internet that will use brute force to try every number and letter combination here is enormous increase in the number of combination products entering the market in the recent years. Combination products have proven advantages but fixe until the right password is found. It has been known for 16 character passcodes to be cracked in this way. Once the hacker has gained administrative access to your PBX, they will identify unused extension numbers and set them up to allow dial through using the company PSTN lines. For the cost of a local phone call, the hacker can be making calls to the Middle East, Far East, Africa, Australasia, d dose combinations are still in the process of convincing regulatory authority on their advantages over the single ingredient formulations. Combination pro etc. Some of these calls could be costing the business up to ?3 a minute. To compound the problem, the hacker will usually set up a disguised PBX that routes its calls through the company PBX. The hacker will then operate a "Call Sell"; selling international calls to customers at cheap rates. Alternatively they could make calls to their own premium rate revenue share services. It is possible tha ucts have become life saving products for the pharmaceutical companies who doesn’t have many innovative molecules in their product pipeline and have been inc t during the 15 hours when your office is closed, up to 10 simultaneous calls could be occurring. And that is just for one day! The problem is likely to go unnoticed and unresolved until the phone bill arrives at the end of the month. It Will Never Happen To Me A recent report in the easingly used in the product life cycle management. Even the companies having product patents are trying to extend their product life cycle through the combi uardian highlighted the plight of one UK Company that suffered from a fraud attack. The company had secured its PBX with a 16 character password but it was still compromised. The discovery of the fraud was by pure chance when the MD of the company came into the office early one day to find the lights on the telephone switchboard lit up like a Christmas tree, even though he was the only one in nation products and maximize the revenues. But the companies involved in this practice are overlooking that they are burdening the patients both economically the office. The report showed that recovering the losses was not easy. Although the company's Telco admitted that the calls were fraudulent, it was not their responsibility to secure the customer's equipment from attack. Therefore the customer was liable for any calls made through the PBX. It was also discovered that the company's insurance policy had a standard clause exempting it from any "ele and physically. They need to rightly judge the benefits of the combination products and they have to even look at the risks involved when combining the produ ctronic losses". A Matter For The Police Surely if a fraud has been perpetrated, then the police should investigate the matter? This is true. The Regulation of Investigatory Powers Act 2000 (Ripa) gives police the power to request "intercept data" from the Telco that would identify the origin of the inbound calls into the PBX. Under the act, a Telco is allowed to charge u ts. Some of the combination products were well accepted by physicians while others suffered. Companies involved in development of combination products are fi to ?1,500 to cover their costs of retrieving the data asked for by the police. This means that in every case, the police must decide whether the financial losses involved in the fraud justifies the cost of the "intercept data". For big losses, the answer is likely to be yes every time. However, in small cases involving just a few hundred or few thousand pounds, the answer may not be so clear cut ding difficulty in defining their combination products and facing various challenges from selecting a combination to marketing it. Following aspects would a How Can It Be Prevented The most obvious way is not to allow remote access to the administration facilities of the PBX. However this may not be practical and could lead to increased charges from the maintenance company. The second method is to use a very random password on the PBX, up to the maximum number of characters and to lock the modem so that it will only answer c dd to the challenges in developing combination products: Which markets to tap where the combination products can do fairly well? Which combination prod alls from a single phone number. This solution is very inflexible and after a while could be turned off if it becomes impractical. Ideally, you would want a solution that could offer the following benefits:
cts are meaningful and rational? Which therapeutic categories to select? Which Combinations can address unmet needs of the patients? Do combin connection and the PBX. The hardware could then determine through a username/password what level of access to give to the PBX.
Secure Access Modems tions increase the patient compliance? What would be the developing cost? How to tackle the risks encountered during combination product developmen s connected to the PBX, while one or more modems are deployed in the field. The modems use an encrypted secret key and a unique ID to provide a challenge/response to incoming calls. Consequently only a modem with a matching encrypted secret key, using an ID that is allowed by the PBX modem will be able to connect. This provides a more flexible alternative to calling from a single phone number. T t? As combination products don't fit into the traditional categories of drugs, medical devices, or biological products, the USFDA is in the process of devel he modem is self contained and does not require any special software. It is unlikely that a random hacker using a standard modem will be able to breach this initial barrier. Hardware Acting As An Intermediary If you use a hardware appliance, it can act as a gateway between the PBX and the user. It could log all login attempts. It could be configured to send out an alert (as a ping new procedures for reviewing their safety, efficacy and quality. Professional from academic institutions, pharmaceutical industries, health care indust email for example) when it detects multiple login failures. This type of behaviour would occur if a hacker was using a brute force attack to try and discover the password. Different combinations of usernames and passwords could be given different levels of access to the PBX. Users can therefore be restricted to performing only certain actions from a limited menu choice. This prevents the hacker y and representatives from various regulatory agencies are working out to design the regulatory requirements for manufacture and sale of combination products from gaining full unrestricted access to all of the administration functionality. Proactively Monitoring For Dial Through Fraud A dial through fraud solution can proactively monitor the call output from the PBX. It can be set to look for suspicious call activity. In the case of the company featured in the Guardian article, this would use a "ruleset" to look for any call that . As there is an increasing trend of the combination products companies manufacturing such products should be able to tackle the problems involved in the de occurred outside of office hours. When suspicious activity is detected, an alert would be sent out containing the details. This allows an appropriate response to be taken, reducing the potential losses caused by the fraud. Dial through fraud can very quickly and silently cause thousands of pounds worth of losses to a business. The standard security precautions in place to prevent it elopment. They need to be wiser in analyzing the market trends and the regulatory requirements. Companies that provide selfless information through particip are weak, especially compared to those used on IT networks. Trying to recover any loss is as difficult as detecting the fraud in the first instance. Data Track can offer a range of Tracker Solutions that will not only add extra security to your PBX but also provide a means of detecting losses before they progress too far tion in industry events and feedback to regulatory authorities would be able to face the challenges and will be successful in developing combination products
HTTP = HTML link (for blogs, profiles,phorums):
Related Articles:New Requirement for NSAs - Background Check Performance Consulting - What You Should Expect from Your Business Consultant
|