← Back to Guidance Portal

Signaling Security Manual

Hardening SS7, Diameter, and GTP protocols against state-actor tracking, interconnection fraud, and DDoS.

PROTOCOL_STACK // CORE_NETWORK

Interconnection Protocols

Traditional telecom signaling was built on trust. Modern NIS2 compliance requires Zero-Trust at the STP/DRA/SEPP level.

SS7 / MAP2G/3G

Location tracking, SMS intercept, and fraud via remote MSC/VLR spoofing.

Mitigation: Implement MAP-Screening and SMS-Home Routing.
Diameter4G/LTE

HSS tracking, DoS against mobility management nodes via S6a interface.

Mitigation: DRA-based topology hiding and Diameter Edge Agent (DEA) firewalling.
GTP-C / GTP-UGeneral

Traffic interception at the GRX/IPX level and TEID exhaustion attacks.

Mitigation: GTP-C firewalling and mandatory per-session TEID validation.
CONTROLS // GSMA_FS31_ALIGNED

Mandatory Security Controls

Implementing the technical measures specified in GSMA FS.31 and ETSI standards.

SC-01

Topology Hiding

Internal network identifiers (IMSI, MSISDN ranges, node IPs) must be masked at the boundary.

SC-02

Message Screening

Filter incoming packets based on source, op-code, and consistency with traffic patterns.

SC-03

Anti-Spoofing

Verify that the originating node is authorized to request information for the targeted subscriber.

SC-04

Session Integrity

Ensure that signaling state matches the actual user attachment status.

Critical: All Category 3 (Location Tracking) signaling messages must be screened at the network edge via a Signaling Firewall.
TELECOM_SPECIFIC_CONTROLS // SECTOR_ADDITIONS

Telecom Sector Deep Dive

Further guidelines and mitigations for interconnectivity, SIM systems, and legacy transitions.

5G Roaming & SEPP Peering Security

In 5G Standalone (SA) deployments, interconnect traffic goes over HTTP/2 via the N32 interface. Security Edge Protection Proxy (SEPP) must be configured on both sides to provide application-layer security, PRACK filtering, and TLS encryption. PRACK security ensures transit network intermediaries cannot modify critical parameters (e.g. routing information, IMSI).

Legacy Sunsetting Risks (2G/3G/4G)

As networks transition to 5G, operators must manage legacy protocols (SS7, Diameter). During the sunsetting phase, backward compatibility is often exploited by attackers downgrading users from 5G to 2G/3G. Firewalls must be tuned to reject unauthorized cross-protocol mapping requests (e.g. SS7 MAP requests targeting 5G-registered IMSIs).

SIM/eSIM Orchestration & RSP Security

Remote SIM Provisioning (RSP) platforms present critical threat surfaces. Unauthorized profile downloads or subscription changes lead to SIM swapping. Access control to RSP nodes (SM-DP+ and SM-SR) must use continuous Mutual Authentication, TLS 1.3, and strict SMS/OTA message signing.

REGISTRY // PROTOCOL_VULNERABILITY_INDEX

Signaling Security Registry

Cross-reference table mapping protocols, transport ports, and risk classifications as defined by GSMA FS.19 and FS.31.

ProtocolDefault PortsCategory (GSMA)Risk ProfileMitigation Control
SS7 / MAPSCTP 2905 (M3UA)Category 3IMSI tracking, subscriber location spoofing, unauthorized profile mods.SMS Home Routing, MAP op-code filtering
DiameterSCTP/TCP 3868Category 2HSS/MME redirection, registration spoofing, Denial of Service (DoS).DEA topology hiding, SCTP multi-homing filter
GTP-CUDP 2123Category 3GGSN hijacking, session redirection, GTP-U tunnel sniffing.GTP validation, TEID randomization
SIPUDP/TCP 5060, TLS 5061Category 2VoLTE call interception, caller-ID spoofing, media gateway bypass.SIP Digest, SBC edge filtering
HTTP/2 (N32)TCP 443, 80Category 1JSON injection, 5G roaming interface flooding, PRACK interception.SEPP validation, TLS 1.3 encryption

Active Monitoring

Our platform includes real-time telemetry from signaling edge nodes to detect abnormal MAP/TCAP patterns using AI-driven anomaly detection.