Fraud monitoring: blacklists & scores

Six of the MONITORING menu items work together as one system: a manual number blacklist/whitelist, a dynamic scoring engine with three thresholds, and four score tables that feed it.

This is separate from Blocked IPs, blocked countries and the whitelist, which block by network address before a call is even routed. Everything on this page works on the numbers in a call (source and destination) once it is already in the system.

Blocked numbers

In the sidebar, go to Monitoring > Blocked numbers. This points the system at a number pool (the same pools used for DIDs and CID pools elsewhere) to use as the global source and destination blacklist or whitelist.

Blocked numbers: which number pool acts as the global blacklist or whitelist, for source and destination separately.
FieldMeaning
Source list (type) / Destination list (type)Whether the chosen pool acts as a Blacklist (numbers in it are blocked) or a Whitelist (only numbers in it are allowed) — set separately for the caller's number and the number being called.
Source number pool / Destination number poolWhich number pool to use for that list.

Dynamic blacklist settings

In the sidebar, go to Monitoring > Settings. This is the global on/off switch and tuning for automatic scoring — separate from the manual list above.

Dynamic blacklist settings: enable switch, three thresholds with their own reroute LCR, and default scores.
FieldMeaning
Dynamic blacklist enabledMaster switch. With this off, the score tables below are kept but have no effect on routing.
Use default blacklist rulesUse the system's built-in scoring rules on top of the tables below.
Disable ChanSpyTurns off the listen-in feature described in Call tracing / listen in system-wide.
Threshold 1 / 2 / 3A score level, each with its own dropdown to pick the LCR a call is rerouted through once it reaches that level — see LCR / Routing.
Default source score / Default destination score / Default IP scoreThe score used when a source number, destination number or IP has no specific row in the tables below.

Prefix & number scores

Four near-identical pages under Monitoring — Source prefix scores, Destination prefix scores, Source number scores and Destination number scores — are the actual score tables the thresholds above measure against. Each is a simple editor: filter, add a row, edit a row inline, delete one row or delete all.

Source prefix scores: score a whole prefix (a dialling code range) rather than one number.
Source number scores: the same editor for individual numbers, plus a CSV import for bulk lists.
FieldMeaning
Prefix / NumberWhat this row scores — a dialling prefix on the prefix pages, one full number on the number pages.
ScoreAdded to a call's running score when it matches. Higher usually means more suspicious; it is compared against the three thresholds on the Settings page.
CSV import (number, score)Bulk-load rows into a number score table (source or destination) from a two-column CSV file. Prefix score pages do not offer this.
Delete allClears every row in that one table — not the other three.
Note

All four score tables were empty on this test system, so the screenshots above show the editor, not real scored entries. The Destination prefix scores and Destination number scores pages use the exact same layout as their source counterparts, just keyed on the number being called instead of the caller.

Check

Open Monitoring > Settings and confirm Dynamic blacklist enabled is checked before expecting the score tables to have any effect; open Blocked numbers to see which pool is currently the source/destination blacklist or whitelist.