In short
Detection combines content patterns, URLs, domains, Sender IDs, source reputation, campaign behaviour, message similarity, traffic velocity and operator-defined policies. No single signal is reliable on its own, so a firewall scores the combination and escalates campaigns rather than individual messages wherever possible.
Signal layers
Content analysis looks at the message body: known phishing phrasing, urgency markers, credential requests, and multilingual variants of each. URL analysis extracts links and evaluates the domain, its age, its reputation and whether it resolves somewhere inconsistent with the brand being claimed.
Sender analysis checks the claimed identity against the registry and against near-miss variations. Route analysis asks whether this source has any business sending traffic for this brand at all.
Clustering turns messages into campaigns
The decisive technique is similarity clustering. Individual messages in a smishing campaign differ — a name, an amount, a reference number — but their structure is nearly identical. Grouping near-duplicate messages across senders, routes and time reveals a campaign that no per-message rule would catch.
Once clustered, the campaign can be actioned as a unit: block the domain, quarantine the sender, and alert the impersonated brand.
Where indicators come from
Three sources feed the detection layer. The operator's own live traffic provides the baseline and the clusters. Threat-intelligence data provides known malicious domains and patterns.
The third source is distinctive to Guardivia: trap numbers in the Honeypot SMS Testing platform receive unsolicited messages directly, capturing campaigns as subscribers actually receive them, including the Sender ID and content after any downstream modification. Confirmed indicators from those captures can be exported to the firewall after analyst review.
Keeping false positives survivable
Banking alerts and OTPs share vocabulary with the phishing messages that imitate them, so an aggressive classifier will eventually block the real thing at the worst possible moment. This is why enforcement runs through the governance sequence: proposals from the classifier, evidence attached, an authorised engineer confirming the change, and quarantine used in preference to silent dropping so that mistakes remain recoverable.