Known Fraudster Detection overview

Gatekeeper Known Fraudster Detection lets customers protect their contact centers by automatically generating alerts to fraud analysts and contact center agents when a customer-identified fraudster or bad actor voice is detected.

The biometric engine performs a 1:many lookup, comparing the caller’s voice against a customer-owned and maintained watchlist of fraudsters. When a match occurs, the engine generates a fraud decision with the corresponding fraudster profile associated to it.

The fraud decision results are generated in real-time and depending on the system configuration the following outputs are created:

  • Fraud analyst alert: Fraud decision engagement creation in the Gatekeeper admin console
  • Contact center agent alert: Fraud decision returned to the Gatekeeper Web Agent Console
  • Alert for external system: Fraud decision output through webhook or Gatekeeper Data Export Service

How do customers populate their fraudster watchlist?

The customers can populate the fraudster watchlist with known fraudsters using the following methods:

  • Gatekeeper biometric clustering

    Many to many search capabilities are available in Gatekeeper in the Analyst Overview section. By setting up, running, and reviewing clustering results, new fraudsters can be identified based on their calling behavior and frequency. Calls with similar voices are grouped together and ranked for fraud analyst review. If a repeat caller is determined to be a fraudster, a fraudster voiceprint is created using the Gatekeeper call audio, which is then added to the fraudster watchlist. The fraudster voiceprint is then compared to subsequent calls when Known Fraudster Detection is configured.

  • External fraud detection tools

    Fraudulent behavior is detected using information, processes and systems outside Gatekeeper, such as fraud transaction monitoring tools. Once fraud has been identified, the fraud analyst validates if an interaction occurred in the contact center as a part of the fraudster’s reconnaissance, social engineering, attack preparation, or exploit. Examples of such activities include calling to check an account balance, validating victim credentials, changing account details, or executing a monetary transfer.

    A fraud analyst would typically search Gatekeeper using the customer identifier, ANI, or call correlation ID to find the fraudster calls.

  • Fraud victim complaints

    When a client reports that they have been a victim of fraud, it’s recommended that customer fraud operations include a Gatekeeper search in their processes to identify if the fraud was perpetrated in their contact center. Gatekeeper is particularly useful in differentiating between victim, first-party and third-party fraudster callers by providing fraud analysts biometric decisions for individual calls.

How is Known Fraudster Detection performance assessed?

There are four dimensions when assessing fraud detection performance of Known Fraudster Detection decisions, which are categorized by fraud analysts by using Gatekeeper Verdicts.

  • True positive

    • Known Fraudster Detection decision = Fraud
    • Confirmed third-party fraud attack
    • Engagement Verdict = Fraud
  • False positive

    • Known Fraudster Detection decision = Fraud
    • Confirmed true user interaction
    • Engagement Verdict = Authentic or Someone Else
  • False negative

    • Known Fraudster Detection decision = No Risk Detected
    • Confirmed third-party fraud attack
    • Engagement Verdict = Fraud
  • True negative

    • Known Fraudster Detection decision = No Risk Detected
    • Confirmed true user interaction
    • Engagement Verdict = Authentic or Somone Else or Not Set

What affects the performance of Known Fraudster Detection?

The following factors affect the performance of Known Fraudster Detection:

  • Audio quality

    Only audio obtained from your Gatekeeper production environment should be used for fraudster voiceprint enrollment.

    • Higher quality audio = fewer false positives

    Use of external audio to create fraudster voiceprints is highly discouraged. External audio is often compressed, encrypted/decrypted, mono-summed, edited, or obtained from sources where the underlying audio characteristics are fundamentally different than that of the Gatekeeper production environment.

    Using more than one audio segment to create a fraudster voiceprint is discouraged. Combining audio segments is an advanced strategy that is error prone. Only biometric clustering or Known Fraudster Detection biometric scores should be used to assess if the same speaker is present on more than one fraudster voiceprints. Human listening or judgement can be unreliable when trying to assess if different calls are made by the same person.

    Fraudster voiceprints containing more than one speaker within a single audio segment or different speakers in different audio segments shouldn’t be used as they generate a high volume of false positives.

    When a fraud analyst is assessing an audio segment to enroll a fraudster voiceprint, they should pay particular attention to background noise, garbled audio, music, electronic noise, clipping, and packet loss. The presence of any of these audio characteristics lowers the quality of the fraudster print, resulting in higher false positive rates.

  • Amount of net speech

    Known Fraudster Detection runs on calls with 3 to 15 seconds of net speech. The more audio, the higher the performance. More net speech can be used; however, diminishing performance gains are observed past 15 seconds on NVSL 10+ engine versions.

    There is a minimum quantity of net speech required to create a fraudster voiceprint. This is dependent on the engine version and configuration parameters. Creation of a fraudster voiceprint with insufficient net speech generates an error message.

  • Call flow and factor configuration

    Known Fraudster Detection can be configured to run on all or a subset of calls.

  • NVSL engine version

    Newer versions of NVSL provide higher-performing Known Fraudster Detection.

  • NRSL risk engine calibration

    Gatekeeper technology is highly adaptable to a multitude of use cases, large range of customer fraud and risk tolerances, watchlist size, and operational constraints. These variables are managed through risk engine calibration.

    NRSL risk engine calibrations are trained to meet a target fraud alert rate. There is a distinct tradeoff between the number of true positives and false negatives that must be considered.

    • Low fraud alert rate = higher true positive rate + higher false negative rate
    • High fraud alert rate = lower true positive rate + lower false negative rate

    Fraud decision thresholds are established as a part of the risk engine calibration. Thresholds can be fine-tuned in the Gatekeeper configuration settings by +/- 15%. For threshold adjustments greater than this, a different risk engine calibration is recommended.

Fraudster watchlist maintenance

Customers should routinely review and assess the performance of individual fraudster voiceprints by consulting the Watchlist page in the Gatekeeper admin console. A small number of poorly performing fraudster voiceprints can decrease the overall system performance.

Low-performing fraudster prints should be assessed for removal as part of an ongoing fraud operational process. For example, if a fraudster voiceprint generates 50 false positives with 0 true positives, removal of that fraudster voiceprint from the watchlist should be considered.