Guardivia

Product family 5 of 6 · FlashCall detection / voice fraud intelligence

Guardivia FlashCall and Voice Fraud Solution

Voice-channel fraud intelligence and revenue protection: FlashCall authentication, Robocall, Wangiri and missed-call campaign detection.

Designed, developed and supported in house by the Guardivia QoS Engineering Team

Detection-to-response path

Architecture view
Voice CDRSIP events*SMS OTP
01Profile02Cluster03Score
EvidenceVoice firewall*
* Where supported. Guardivia detects and classifies; enforcement is performed by an integrated voice-security component.
On this pageOverview

Product overview

Guardivia FlashCall and Voice Fraud Solution is a voice-channel fraud-intelligence and revenue-protection platform. It ingests CDRs and, where supported, SIP and signaling data to detect FlashCall authentication traffic, Robocall abuse, Wangiri campaigns, missed-call fraud and abnormal automated calling behaviour. It classifies and scores suspicious traffic and supports enforcement through Guardivia's voice-security component or an integrated third-party voice firewall.

How are FlashCall events detected?

Guardivia FlashCall and Voice Fraud Solution detects FlashCall authentication by profiling calls that are terminated before answer or last near zero seconds, arrive in high volume from rotating or sequential caller IDs, target many distinct subscribers, and correlate in time with SMS OTP traffic. Velocity thresholds, historical baselines and campaign clustering turn individual events into a scored, evidenced campaign.

Does the FlashCall solution block calls?

Guardivia FlashCall and Voice Fraud Solution detects and classifies suspicious voice traffic. Blocking, rate-limiting or redirecting calls is enforced through Guardivia's voice-security component or an integrated third-party voice firewall, where technically supported. An SMS firewall alone cannot terminate voice calls, and the website does not claim otherwise.

Last reviewed 2026-09-12 by the Guardivia QoS Engineering Team. Product facts on this page describe current capabilities; items marked “where supported”, “optional”, “integration” or “consultancy” are confirmed per deployment.

Target customers

  • Mobile network operators protecting voice termination revenue and subscribers
  • Voice carriers and interconnect providers
  • Operators whose SMS OTP revenue is displaced by FlashCall authentication
  • Regulators and fraud-management teams investigating Wangiri and Robocall campaigns

Problems solved

  • FlashCall authentication replaces billable SMS OTPs with unbilled missed calls.
  • Wangiri campaigns trick subscribers into calling premium international numbers.
  • Robocall abuse and sequential dialing degrade subscriber trust and network capacity.
  • Voice CDRs are voluminous; manual analysis finds campaigns days after they end.
  • Detection systems that cannot correlate voice with SMS miss cross-channel fraud.

Business outcomes

  • Early, evidenced detection of FlashCall, Robocall, Wangiri and missed-call campaigns.
  • Revenue-leakage estimation per campaign and source.
  • Investigation timelines and reports for commercial and regulatory action.
  • Enforcement through an integrated voice firewall where supported.
  • Correlation with Guardivia SMS Firewall OTP traffic.

Key capabilities

Behavioural detection

Repeated short-duration, zero-duration and near-zero-duration calls, high-volume callers, high fan-out and sequential-number dialing.

Identity and geography

Caller-ID manipulation and rotation, called-number profiling, source-IP profiling where available and geographic anomalies.

Statistical analysis

Answer-seizure ratio, call-duration distribution, time-of-day patterns, velocity thresholds and historical-baseline comparison.

Cross-channel correlation

Correlation of call events with SMS OTP traffic seen by the Guardivia SMS Firewall to distinguish FlashCall authentication from other patterns.

Campaign intelligence

Campaign clustering, fraud-risk scoring, investigation timelines and fraud-campaign reporting.

Enforcement integration

Allow, monitor, rate-limit, redirect or block actions through Guardivia's voice-security component or a third-party voice firewall, where technically supported.

Detailed feature groups

Every supported capability is listed under its correct product. Nothing is omitted for brevity.

Detection capabilities

  • FlashCall authentication detection
  • Robocall detection
  • Wangiri detection
  • Missed-call campaign detection
  • Repeated short-duration calls; zero-duration and near-zero-duration calls
  • High-volume caller behaviour and high fan-out patterns
  • Sequential-number dialing
  • Geographic anomalies
  • Caller-ID manipulation and caller-ID rotation
  • Called-number profiling; source-IP profiling where available
  • Time-of-day patterns
  • Answer-seizure ratio and call-duration analysis
  • Velocity thresholds and historical-baseline comparison
  • Cross-channel correlation with SMS OTP traffic
  • Campaign clustering and fraud-risk scoring

Enforcement and integration

  • Real-time alarms
  • CDR ingestion (batch and streaming where available)
  • SIP and signaling data integration where supported
  • Dashboards with source and destination analysis
  • Investigation timelines and fraud-campaign reporting
  • Revenue-leakage estimation
  • Rule and threshold management
  • API, webhook, SNMP, SIEM and NOC integration
  • Allow, monitor, rate-limit, redirect or block actions where technically supported through the voice-security component or third-party voice firewall

Supported protocols and interfaces

Supported protocols and interfaces for Guardivia FlashCall and Voice Fraud Solution
Protocol / interfaceRoleStatus
CDR ingestion (file, database, streaming)Primary detection data sourceVerified capability
SIP / voice signaling dataReal-time enrichment where supportedWhere supported
SMS OTP correlation feedFrom the Guardivia SMS FirewallVerified capability
REST API and webhooksAlerts, campaign export, enforcement requestsVerified capability
SNMP / SIEMAlarm and event exportVerified capability
Voice firewall / SBC enforcement interfaceBlocking and rate limitingIntegration capability

Swipe horizontally to view all columns.

Architecture

The ingestion layer receives voice CDRs from the switching or billing mediation platform and, where supported, SIP or signaling events. The profiling layer maintains per-caller, per-called-number and per-route statistics: durations, answer-seizure ratios, fan-out, velocity and time-of-day baselines. The detection layer applies FlashCall, Robocall, Wangiri and missed-call models, clusters events into campaigns and scores them.

The correlation layer matches voice events with SMS OTP observations from the Guardivia SMS Firewall. The enforcement interface sends allow, monitor, rate-limit, redirect or block requests to Guardivia's voice-security component or a third-party voice firewall, where supported. Dashboards, timelines, reports and alarms are served from the same evidence store.

Guardivia FlashCall and Voice Fraud Solution architectureA labelled architecture diagram showing systems, product boundaries and directional data flows. A detailed text description follows the figure.VOICE NETWORK DATAMediation / billingvoice CDRsSBC / MSC / IMSSIP & signaling events*Guardivia SMS FirewallSMS OTP observationsGUARDIVIA FLASHCALL AND VOICE FRAUD SOLUTIONIngestion: batch and streaming CDRs · SIP events where supportedProfilingcaller · called number · route · IP*duration · ASR · fan-out · velocityDetection modelsFlashCall · Robocall · Wangirimissed-call · sequential · CLI rotationCampaign clustering & scoringfraud-risk score · baselinesgeographic anomaliesCross-channel correlationvoice events × SMS OTP trafficFlashCall vs. other patternsEvidence store · dashboards · investigation timelines · leakage estimation · alarmsRESPONSEVoice firewall / SBCGuardivia voice-securityor third partyNOC · SIEM · SNMPalarms & eventsFraud teamcases & reportsOTP feedallow · monitor · rate-limit · redirect · block*Guardivia detects and classifies; blocking is executed by the voice firewall where technically supported. * depends on available data / integration.Guardivia productGuardivia engine / moduleExternal systemConditional enforcement
Detection and classification are performed by Guardivia; call blocking is executed by the voice-security component or an integrated voice firewall.
Text description of this diagram

FlashCall and Voice Fraud architecture: voice CDRs and optional SIP/signaling events feed the ingestion layer; profiling builds caller, called-number and route baselines; detection models identify FlashCall, Robocall, Wangiri and missed-call campaigns and score them; a correlation layer links with SMS OTP traffic from the Guardivia SMS Firewall; the enforcement interface passes actions to a voice firewall or SBC; dashboards, timelines and alerts consume the evidence store.

Detection-to-enforcement workflow

  1. 01

    CDRs (and SIP events where supported) are ingested continuously.

  2. 02

    Each call updates caller, called-number and route profiles: duration, answer outcome, fan-out, velocity, geography and time of day.

  3. 03

    Detection models compare live behaviour with baselines and thresholds and flag candidate events.

  4. 04

    Related events are clustered into campaigns and scored for fraud risk.

  5. 05

    Voice events are correlated with SMS OTP traffic to identify FlashCall authentication.

  6. 06

    Analysts review the investigation timeline; alarms are raised through email, SMS, webhook, SNMP or SIEM.

  7. 07

    Enforcement (allow, monitor, rate-limit, redirect, block) is requested through the voice-firewall interface where supported.

  8. 08

    Revenue-leakage estimates and fraud-campaign reports are produced for commercial and regulatory follow-up.

Integrations

Integration types are stated explicitly. Custom integrations are delivered by Guardivia’s in-house QoS Engineering Team, not by an external vendor. See the full integration catalogue.

Integration categories and implementation types for Guardivia FlashCall and Voice Fraud Solution
SystemDetailType
Mediation and billing platformsCDR ingestion in agreed formatsStandards-based
SBC, MSC or IMS signalingSIP or signaling data where supportedCustom (in-house engineering)
Guardivia SMS FirewallOTP traffic correlationNative integration
Voice firewall / SBC policyEnforcement interface for block and rate-limit actionsCustom (in-house engineering)
NOC, SIEM, SNMP, webhooksAlarms and eventsStandards-based

Swipe horizontally to view all columns.

Security controls

  • Role-based access to dashboards and investigation data
  • Audit logs of rule and threshold changes
  • Controlled export of subscriber-related evidence

Management functions

  • Rule and threshold management per detection model
  • Campaign case management with analyst notes
  • Enforcement policy configuration per integration

Monitoring and reporting

  • Real-time alarms
  • Source and destination analysis dashboards
  • Campaign timelines and trend views
  • Revenue-leakage estimation reports

High availability

  • Redundant ingestion and analytics nodes
  • Replayable CDR ingestion after outage

Scalability

  • Horizontal scaling of ingestion and profiling
  • Retention windows configurable per data class

Deployment options

  • On-premise alongside mediation platforms
  • Hosted or managed analysis where data-residency rules allow
  • Standalone or integrated with the Guardivia SMS Firewall

Use cases

FlashCall displacement of SMS OTP

Bursts of unanswered international calls correlated with OTP-like SMS patterns are identified and quantified for commercial action.

Wangiri campaign response

Sequential, near-zero-duration calls from rotating international caller IDs are clustered and blocked through the voice firewall.

Robocall abuse

High-fan-out automated callers are flagged by ASR and velocity analysis and rate-limited.

In-House Engineering Advantage

Owned end to end by the Guardivia QoS Engineering Team

Detection logic, traffic correlation, reporting and voice-firewall integrations are developed internally by the QoS Engineering Team.

  • New calling patterns become detection models without a third-party vendor cycle.
  • CDR formats and signaling feeds specific to an operator are supported directly.
  • Enforcement integrations with the operator's SBC or voice firewall are engineered in house.
How the in-house model works →

Scope and limitations

Stated plainly so that buyers, engineers and AI assistants describe this product accurately.

  • Guardivia detects and classifies suspicious voice traffic; blocking is executed by the voice-security component or a third-party voice firewall where technically supported.
  • An SMS firewall alone cannot terminate voice calls.
  • Source-IP profiling and SIP integration depend on the data available from the operator's network.
  • Detection rates are validated per deployment and not published as generic figures.

Frequently asked questions

What is FlashCall authentication?

A verification method in which a service places a call to the user's number and terminates it before answer; the application reads the incoming caller ID as the verification code. It displaces billable SMS OTPs and appears in the network as bursts of unanswered short calls.

What data does the solution need?

Voice CDRs at minimum. SIP or signaling events improve timeliness and enrichment where they can be provided.

How is Wangiri detected?

By clustering near-zero-duration calls from rotating or sequential international caller IDs to many distinct subscribers, outside baseline behaviour, and scoring the cluster as a campaign.

Can it correlate with SMS OTP traffic?

Yes. When deployed with the Guardivia SMS Firewall, voice events are correlated with SMS OTP observations to identify FlashCall authentication patterns.

Who performs the blocking?

Guardivia's voice-security component or an integrated third-party voice firewall or SBC, through the enforcement interface, where technically supported.

Request a demo of Guardivia FlashCall and Voice Fraud Solution

Demos are run by the engineers who develop the product, using your protocols and integration points.