Product family 5 of 6 · FlashCall detection / voice fraud intelligence
Guardivia FlashCall and Voice Fraud Solution
Voice-channel fraud intelligence and revenue protection: FlashCall authentication, Robocall, Wangiri and missed-call campaign detection.
Detection-to-response path
Architecture viewInputs
Voice CDRSIP events*SMS OTPGuardivia processing
Outputs
EvidenceVoice firewall*On this pageOverview
Product overview
Guardivia FlashCall and Voice Fraud Solution is a voice-channel fraud-intelligence and revenue-protection platform. It ingests CDRs and, where supported, SIP and signaling data to detect FlashCall authentication traffic, Robocall abuse, Wangiri campaigns, missed-call fraud and abnormal automated calling behaviour. It classifies and scores suspicious traffic and supports enforcement through Guardivia's voice-security component or an integrated third-party voice firewall.
How are FlashCall events detected?
Guardivia FlashCall and Voice Fraud Solution detects FlashCall authentication by profiling calls that are terminated before answer or last near zero seconds, arrive in high volume from rotating or sequential caller IDs, target many distinct subscribers, and correlate in time with SMS OTP traffic. Velocity thresholds, historical baselines and campaign clustering turn individual events into a scored, evidenced campaign.
Does the FlashCall solution block calls?
Guardivia FlashCall and Voice Fraud Solution detects and classifies suspicious voice traffic. Blocking, rate-limiting or redirecting calls is enforced through Guardivia's voice-security component or an integrated third-party voice firewall, where technically supported. An SMS firewall alone cannot terminate voice calls, and the website does not claim otherwise.
Last reviewed 2026-09-12 by the Guardivia QoS Engineering Team. Product facts on this page describe current capabilities; items marked “where supported”, “optional”, “integration” or “consultancy” are confirmed per deployment.
Target customers
- Mobile network operators protecting voice termination revenue and subscribers
- Voice carriers and interconnect providers
- Operators whose SMS OTP revenue is displaced by FlashCall authentication
- Regulators and fraud-management teams investigating Wangiri and Robocall campaigns
Problems solved
- FlashCall authentication replaces billable SMS OTPs with unbilled missed calls.
- Wangiri campaigns trick subscribers into calling premium international numbers.
- Robocall abuse and sequential dialing degrade subscriber trust and network capacity.
- Voice CDRs are voluminous; manual analysis finds campaigns days after they end.
- Detection systems that cannot correlate voice with SMS miss cross-channel fraud.
Business outcomes
- Early, evidenced detection of FlashCall, Robocall, Wangiri and missed-call campaigns.
- Revenue-leakage estimation per campaign and source.
- Investigation timelines and reports for commercial and regulatory action.
- Enforcement through an integrated voice firewall where supported.
- Correlation with Guardivia SMS Firewall OTP traffic.
Key capabilities
Behavioural detection
Repeated short-duration, zero-duration and near-zero-duration calls, high-volume callers, high fan-out and sequential-number dialing.
Identity and geography
Caller-ID manipulation and rotation, called-number profiling, source-IP profiling where available and geographic anomalies.
Statistical analysis
Answer-seizure ratio, call-duration distribution, time-of-day patterns, velocity thresholds and historical-baseline comparison.
Cross-channel correlation
Correlation of call events with SMS OTP traffic seen by the Guardivia SMS Firewall to distinguish FlashCall authentication from other patterns.
Campaign intelligence
Campaign clustering, fraud-risk scoring, investigation timelines and fraud-campaign reporting.
Enforcement integration
Allow, monitor, rate-limit, redirect or block actions through Guardivia's voice-security component or a third-party voice firewall, where technically supported.
Detailed feature groups
Every supported capability is listed under its correct product. Nothing is omitted for brevity.
Detection capabilities
- FlashCall authentication detection
- Robocall detection
- Wangiri detection
- Missed-call campaign detection
- Repeated short-duration calls; zero-duration and near-zero-duration calls
- High-volume caller behaviour and high fan-out patterns
- Sequential-number dialing
- Geographic anomalies
- Caller-ID manipulation and caller-ID rotation
- Called-number profiling; source-IP profiling where available
- Time-of-day patterns
- Answer-seizure ratio and call-duration analysis
- Velocity thresholds and historical-baseline comparison
- Cross-channel correlation with SMS OTP traffic
- Campaign clustering and fraud-risk scoring
Enforcement and integration
- Real-time alarms
- CDR ingestion (batch and streaming where available)
- SIP and signaling data integration where supported
- Dashboards with source and destination analysis
- Investigation timelines and fraud-campaign reporting
- Revenue-leakage estimation
- Rule and threshold management
- API, webhook, SNMP, SIEM and NOC integration
- Allow, monitor, rate-limit, redirect or block actions where technically supported through the voice-security component or third-party voice firewall
Supported protocols and interfaces
| Protocol / interface | Role | Status |
|---|---|---|
| CDR ingestion (file, database, streaming) | Primary detection data source | Verified capability |
| SIP / voice signaling data | Real-time enrichment where supported | Where supported |
| SMS OTP correlation feed | From the Guardivia SMS Firewall | Verified capability |
| REST API and webhooks | Alerts, campaign export, enforcement requests | Verified capability |
| SNMP / SIEM | Alarm and event export | Verified capability |
| Voice firewall / SBC enforcement interface | Blocking and rate limiting | Integration capability |
Swipe horizontally to view all columns.
Architecture
The ingestion layer receives voice CDRs from the switching or billing mediation platform and, where supported, SIP or signaling events. The profiling layer maintains per-caller, per-called-number and per-route statistics: durations, answer-seizure ratios, fan-out, velocity and time-of-day baselines. The detection layer applies FlashCall, Robocall, Wangiri and missed-call models, clusters events into campaigns and scores them.
The correlation layer matches voice events with SMS OTP observations from the Guardivia SMS Firewall. The enforcement interface sends allow, monitor, rate-limit, redirect or block requests to Guardivia's voice-security component or a third-party voice firewall, where supported. Dashboards, timelines, reports and alarms are served from the same evidence store.
Text description of this diagram
FlashCall and Voice Fraud architecture: voice CDRs and optional SIP/signaling events feed the ingestion layer; profiling builds caller, called-number and route baselines; detection models identify FlashCall, Robocall, Wangiri and missed-call campaigns and score them; a correlation layer links with SMS OTP traffic from the Guardivia SMS Firewall; the enforcement interface passes actions to a voice firewall or SBC; dashboards, timelines and alerts consume the evidence store.
Detection-to-enforcement workflow
- 01
CDRs (and SIP events where supported) are ingested continuously.
- 02
Each call updates caller, called-number and route profiles: duration, answer outcome, fan-out, velocity, geography and time of day.
- 03
Detection models compare live behaviour with baselines and thresholds and flag candidate events.
- 04
Related events are clustered into campaigns and scored for fraud risk.
- 05
Voice events are correlated with SMS OTP traffic to identify FlashCall authentication.
- 06
Analysts review the investigation timeline; alarms are raised through email, SMS, webhook, SNMP or SIEM.
- 07
Enforcement (allow, monitor, rate-limit, redirect, block) is requested through the voice-firewall interface where supported.
- 08
Revenue-leakage estimates and fraud-campaign reports are produced for commercial and regulatory follow-up.
Integrations
Integration types are stated explicitly. Custom integrations are delivered by Guardivia’s in-house QoS Engineering Team, not by an external vendor. See the full integration catalogue.
| System | Detail | Type |
|---|---|---|
| Mediation and billing platforms | CDR ingestion in agreed formats | Standards-based |
| SBC, MSC or IMS signaling | SIP or signaling data where supported | Custom (in-house engineering) |
| Guardivia SMS Firewall | OTP traffic correlation | Native integration |
| Voice firewall / SBC policy | Enforcement interface for block and rate-limit actions | Custom (in-house engineering) |
| NOC, SIEM, SNMP, webhooks | Alarms and events | Standards-based |
Swipe horizontally to view all columns.
Security controls
- Role-based access to dashboards and investigation data
- Audit logs of rule and threshold changes
- Controlled export of subscriber-related evidence
Management functions
- Rule and threshold management per detection model
- Campaign case management with analyst notes
- Enforcement policy configuration per integration
Monitoring and reporting
- Real-time alarms
- Source and destination analysis dashboards
- Campaign timelines and trend views
- Revenue-leakage estimation reports
High availability
- Redundant ingestion and analytics nodes
- Replayable CDR ingestion after outage
Scalability
- Horizontal scaling of ingestion and profiling
- Retention windows configurable per data class
Deployment options
- On-premise alongside mediation platforms
- Hosted or managed analysis where data-residency rules allow
- Standalone or integrated with the Guardivia SMS Firewall
Use cases
FlashCall displacement of SMS OTP
Bursts of unanswered international calls correlated with OTP-like SMS patterns are identified and quantified for commercial action.
Wangiri campaign response
Sequential, near-zero-duration calls from rotating international caller IDs are clustered and blocked through the voice firewall.
Robocall abuse
High-fan-out automated callers are flagged by ASR and velocity analysis and rate-limited.
In-House Engineering Advantage
Owned end to end by the Guardivia QoS Engineering Team
Detection logic, traffic correlation, reporting and voice-firewall integrations are developed internally by the QoS Engineering Team.
- New calling patterns become detection models without a third-party vendor cycle.
- CDR formats and signaling feeds specific to an operator are supported directly.
- Enforcement integrations with the operator's SBC or voice firewall are engineered in house.
Scope and limitations
Stated plainly so that buyers, engineers and AI assistants describe this product accurately.
- Guardivia detects and classifies suspicious voice traffic; blocking is executed by the voice-security component or a third-party voice firewall where technically supported.
- An SMS firewall alone cannot terminate voice calls.
- Source-IP profiling and SIP integration depend on the data available from the operator's network.
- Detection rates are validated per deployment and not published as generic figures.
Frequently asked questions
What is FlashCall authentication?
A verification method in which a service places a call to the user's number and terminates it before answer; the application reads the incoming caller ID as the verification code. It displaces billable SMS OTPs and appears in the network as bursts of unanswered short calls.
What data does the solution need?
Voice CDRs at minimum. SIP or signaling events improve timeliness and enrichment where they can be provided.
How is Wangiri detected?
By clustering near-zero-duration calls from rotating or sequential international caller IDs to many distinct subscribers, outside baseline behaviour, and scoring the cluster as a campaign.
Can it correlate with SMS OTP traffic?
Yes. When deployed with the Guardivia SMS Firewall, voice events are correlated with SMS OTP observations to identify FlashCall authentication patterns.
Who performs the blocking?
Guardivia's voice-security component or an integrated third-party voice firewall or SBC, through the enforcement interface, where technically supported.
Request a demo of Guardivia FlashCall and Voice Fraud Solution
Demos are run by the engineers who develop the product, using your protocols and integration points.