introducing ivr anti-fraud from rsa conference 2016

11
2016 Pindrop™. INTRODUCING RSA Conference 2016 IVR ANTI-FRAUD

Upload: pindrop

Post on 15-Feb-2017

289 views

Category:

Technology


1 download

TRANSCRIPT

Page 1: Introducing IVR Anti-Fraud from RSA Conference 2016

2016 Pindrop™.

INTRODUCING

RSA Conference 2016

IVR ANTI-FRAUD

Page 2: Introducing IVR Anti-Fraud from RSA Conference 2016

2016 Pindrop™.

COMPLETE CALL CENTER PROTECTION

IVR Anti-fraud

• Call risk scoring and threat detection• Multi-factor analysis engine• Adaptive machine-learning technology

Pindrop Risk Assessment Engine

IVR AF

CC AF

Live Agent Anti-FraudFraud Detection System (FDS)

• Launched in 2011• Protecting 460,000,000 calls

annually• Leading anti fraud solution in

enterprise call centers

• Launched in 2016• Extending protection to entire

enterprise call center• 3 POCs with amazing results

Page 3: Introducing IVR Anti-Fraud from RSA Conference 2016

2016 Pindrop™.

Call Center Fraud Attack Timeline

FRAUD ACTIVITY IN THE IVR

• Account Mining• Tree Mapping• Information Leakage• Fraud Alert Detection• Balance Inquiry

• Brute Force Attacks• PIN Resets

• Toll Free Traffic Pumping

RECONNAISSANCE ACCOUNT TAKEOVER MONETIZATION

Fraud Technology• Caller ID Spoofing

• Robotic Dialing

1 in 2600Calls to the IVR

is fraud

75%Calls stay in the IVR

UNSUPERVISED

33%Live agent fraud calls

pass through IVR

Page 4: Introducing IVR Anti-Fraud from RSA Conference 2016

2016 Pindrop™.

THE IMPORTANCE OF IVR

2014 2016

47%63%

“The average cost of an agent-assisted call was $5.50. This is

compared to $.45 for a touchtone IVR call.”

Gartner

“By 2020, customers will manage 85% of their relationship with the enterprise without interacting with

a human”

Gartner

12X“Fully automated customer

interactions will increase from 47% in 2014 to 63% in 2016”

Frost & Sullivan

Page 5: Introducing IVR Anti-Fraud from RSA Conference 2016

2016 Pindrop™.

CURRENT IVR SECURITY SOLUTIONS

• Blacklisting

• Voiceprinting

• Knowledge Based Authentication

• Only protects against known bad numbers• No protection for first time callers• Defeated by spoofing

• Only works in voice enabled IVRs• Requires opt-in authentication• No protection for first time callers• Defeated by voice distortion

• Limited to multiple choice or numerical answers• Easily guessed or data available on black market• Poor customer experience• Costly

Page 6: Introducing IVR Anti-Fraud from RSA Conference 2016

2016 Pindrop™.

PINDROP IVR FRAUD DETECTION

First Call, Every Call100% coverage for all calls in the call center

TransparentFast, non-intrusive, behind the scenes

Highly AccurateExamine multiple aspects

of call for accuracy

Page 7: Introducing IVR Anti-Fraud from RSA Conference 2016

2016 Pindrop™.

HOW IT WORKS: PATENT PENDING IVR ANALYSIS

NETWORK What does the

signaling tell us?

SS7 CharacteristicsSIP Characteristics

REPUTATIONHow malicious is

this number?

ComplaintsType

GeographyCarrier

BEHAVIORHow does this

caller act?

NavigationalInteraction TimingsDTMF Sequence

STATISTICSDo the calling patterns

make sense?

Calling IntervalsCall Duration

Call DestinationCall Volume

Pindrop Intelligence Network

RISK SCORE

Page 8: Introducing IVR Anti-Fraud from RSA Conference 2016

2016 Pindrop™.

RISK SCORE

CONTINUOUS SCORING

• Highly accurate• Complete coverage• Flexible & Actionable

TREATMENT STRATEGY EXAMPLES

• Passive, alert fraud analyst• Route call to CSR• Drop call• Dynamically change IVR options• Step Up Authentication

Page 9: Introducing IVR Anti-Fraud from RSA Conference 2016

2016 Pindrop™.

KEY BENEFITS

Reduce IVR Fraud Risk• Protect first and every call• Highly accurate and actionable risk scoring

Reduce Call Center Operations Costs• Reduce agent time spent on fraud calls• Reduce robo-dialing in the IVR

Increase IVR Self Service Capabilities• Reduce CSR call handle time• Increase customer satisfaction

Page 10: Introducing IVR Anti-Fraud from RSA Conference 2016

2016 Pindrop™.

CASE STUDY – LARGE BANK

Evaluation of over 2,000,000 calls over a 77 day period• Evaluated calls at both the IVR and CSR legs

Customer was surprised to find…• Extremely long duration calls – 16 hours (Toll-Free Traffic Pumping)• Very long user interactions – 100’s of key presses (Account Mining)• Multiple calls from same ANI targeting different accounts (Account Mining)• Nonsense user interactions (Tree Mapping)• Multiple devices presenting the same ANI (Caller ID Spoofing)• User interaction with extreme regularity (Robotic Dialing)

Impact• 33% of all fraud was first detected in the IVR• Fraud detected at the IVR accounted for over $5M of total annual loss

Page 11: Introducing IVR Anti-Fraud from RSA Conference 2016

2016 Pindrop™.

PINDROPPhone Fraud Stops Here.