← All insights
roaming analytics5 min read

Roaming fraud in the NR era: new vectors, new detection requirements

Roaming fraud is not a new problem, but 5G NR roaming has introduced characteristics that make existing detection approaches less effective. NRTRDE was designed for 4G traffic profiles: session sizes were bounded, the relationship between time and volume was predictable, and the service types were well understood. NR changes each of these parameters in ways that benefit fraudsters and challenge detection.

What changes with NR roaming

NR sessions can generate data volumes in minutes that would have taken hours on LTE. A fraudulent NR session can therefore accumulate a large chargeable volume before the NRTRDE reporting cycle surfaces it. The detection window that existed under LTE — where session volume grew slowly enough for threshold alerts to catch fraud before significant loss — compresses substantially on NR.

Network slicing introduces an additional complication: sessions on different slices may have different IOT rates, and slice manipulation — routing traffic through a lower-cost slice than the session type justifies — is a fraud vector that did not exist in the pre-slicing architecture. Detection requires visibility into slice assignment alongside traffic volumes.

Detection architecture for NR fraud

Effective NR fraud detection requires near-real-time session monitoring, not batch NRTRDE processing. The visited network needs to surface active session volume as it accumulates, not just in the NRTRDE record after the session closes. This requires either real-time interfaces to the SMF or a probe-based monitoring layer that can alert before the session reaches the loss threshold.

Threshold-based alerting needs to be recalibrated for NR. Volume thresholds set for LTE typical sessions will generate excessive false positives on NR, which carries 10–50x the throughput. Effective NR fraud detection uses per-session rate of volume accumulation as a signal, not absolute volume, and applies ML-based anomaly detection against the NR session profile baseline rather than fixed thresholds.

Coordination with partners

Roaming fraud ultimately requires cooperation between the HPLMN and VPLMN to resolve. The VPLMN detects the anomalous session; the HPLMN has the subscriber context to determine whether the session is fraudulent or legitimate. GSMA IR.21 and IR.71 define the information exchange mechanisms, but in practice the speed of bilateral communication is the limiting factor in loss limitation.

Operators with automated, API-based communication channels for fraud alerts — rather than manual email-based processes — are limiting losses significantly more effectively than those relying on traditional bilateral communication workflows. The NR fraud window is too short for manual processes to be effective.

Yaana Technologies

Ready to audit your intercept stack?

Talk to the Yaana team about secure-by-design infrastructure for your network.

Request a Meeting →