Telecom Security FAQ
Answers to the most common questions about telecom and mobile network security: SS7, Diameter, 5G, IMS, IMSI catchers, SIM swap, signaling firewalls, and more.
About the TelcoSec Glossary
What is the TelcoSec Glossary?
The TelcoSec Glossary is a comprehensive, open-access reference of telecommunications and telecom security terminology maintained by P1 Security. It covers over 500 terms spanning protocols like SS7, Diameter, GTP, SIP, and 5G, as well as telecom fraud, lawful interception, roaming security, and mobile network architecture.
Who maintains the TelcoSec Glossary?
The glossary is maintained by P1 Security, a company specializing in telecom and mobile network security since 2011. P1 Security's research team continuously adds and updates definitions based on evolving standards from 3GPP, GSMA, ETSI, and ITU-T.
How often is the glossary updated?
The glossary is updated regularly as new terms emerge from 3GPP releases, GSMA guidelines, and real-world security research. New protocol versions, attack techniques, and defense mechanisms are added as they become relevant to the telecom security community.
Can I use the glossary definitions in my own work?
Yes, the glossary is freely accessible for educational and professional use. If you reference definitions in publications, presentations, or reports, we ask that you credit P1 Security and link back to the relevant glossary page.
SS7 and Legacy Signaling Security
What is SS7 and why is it a security risk?
SS7 (Signalling System No. 7) is the set of signaling protocols used by traditional telephone networks worldwide since the 1980s. It was designed in a trusted, closed-network era with no built-in authentication or encryption. Attackers who gain access to the SS7 network, through compromised operators, leased global titles, or SS7-as-a-service providers, can intercept calls and SMS messages, track subscriber locations in real time, and perform fraud such as premium-rate number redirections.
What is an IMSI catcher and how does it work?
An IMSI catcher (also known as a Stingray or cell-site simulator) is a surveillance device that mimics a legitimate cell tower to trick nearby mobile devices into connecting to it. Once connected, the device reveals its IMSI (International Mobile Subscriber Identity) and IMEI, allowing the operator of the IMSI catcher to track the phone's location, intercept communications, and in some cases inject messages. Modern 5G networks introduce SUPI/SUCI encryption to mitigate this, but legacy 2G/3G devices remain vulnerable.
IMSI definitionIMEI definition
How can operators protect against SS7 attacks?
Operators can deploy SS7 firewalls that filter and monitor signaling messages based on GSMA IR.82 and FS.11 recommendations. Key measures include: implementing category-based filtering to block unauthorized MAP operations, deploying SMS home-routing to prevent interception, monitoring for anomalous location queries (ATI/PSI), and conducting regular SS7 security assessments. P1 Security provides tools and expertise for SS7 vulnerability assessment and monitoring.
Diameter and 4G/LTE Security
What is the Diameter protocol in telecom?
Diameter is the signaling protocol used in 4G/LTE and IMS networks, succeeding RADIUS for authentication, authorization, and accounting (AAA). It handles subscriber authentication (via S6a interface between MME and HSS), policy control (Gx interface to PCRF), and charging (Gy/Ro interfaces). Despite being newer than SS7, Diameter has its own set of security vulnerabilities when interconnect links between operators are not properly secured.
Diameter definitionHSS definition
What are the main Diameter security threats?
Key Diameter security threats include: unauthorized subscriber information disclosure via S6a queries, subscriber denial of service through spoofed Cancel Location Requests (CLR), fraudulent session manipulation on Gx/Gy interfaces, and location tracking through interconnect probing. GSMA document FS.19 provides recommendations for Diameter interconnect security, including the deployment of Diameter Edge Agents (DEA) and Diameter Routing Agents (DRA) with security filtering capabilities.
What is the difference between SS7 and Diameter?
SS7 and Diameter are both telecom signalling protocol families, but they belong to different generations and architectures. SS7 (1980s) is a circuit-switched, MTP/SCCP/TCAP-based stack used in 2G/3G voice, SMS and roaming, designed for a closed club of trusted operators with no built-in authentication or encryption. Diameter (introduced with 4G/LTE and IMS) is an IP-based AAA protocol that runs over SCTP/TCP, supports TLS/IPsec, and uses a request/answer model with explicit Application IDs. Diameter improves transport security and extensibility, but its interconnect (between operators, over IPX) inherits the same trust model problems as SS7 if Diameter Edge Agents are not properly hardened. Both remain in production today and both must be protected by signalling firewalls.
5G Security
How is 5G more secure than previous generations?
5G (as defined by 3GPP) introduces several security improvements: SUPI/SUCI mechanism that encrypts subscriber identity over the air (preventing IMSI catching), a Security Edge Protection Proxy (SEPP) for inter-operator signaling using HTTP/2 with TLS and JSON Web Encryption (JWE), a service-based architecture (SBA) with mutual authentication between network functions, and enhanced subscriber authentication via 5G-AKA and EAP-AKA' protocols. However, non-standalone 5G deployments that rely on 4G core infrastructure may still inherit legacy vulnerabilities.
SEPP definitionSUPI definition5G-AKA definition
What is a SEPP in 5G networks?
A Security Edge Protection Proxy (SEPP) is a mandatory network function in 5G that secures all signaling traffic between different operators' 5G core networks. It sits at the perimeter of each operator's network and applies message filtering, topology hiding, and end-to-end encryption using the PRINS (Protocol for N32 Interconnect Security) protocol. The SEPP replaces the unprotected Diameter interconnect model used in 4G, providing a much stronger security posture for roaming and inter-operator communication.
What is network slicing and what are its security implications?
Network slicing allows operators to create multiple virtual networks on a shared physical 5G infrastructure, each tailored for specific use cases (e.g., IoT, ultra-reliable low latency, enhanced mobile broadband). Security implications include: ensuring proper isolation between slices so a compromise in one doesn't affect others, applying slice-specific access control and authentication policies, and monitoring for cross-slice attacks. The NSSAI (Network Slice Selection Assistance Information) and S-NSSAI parameters control slice selection and must be properly validated.
GTP and Mobile Packet Core Security
What is GTP and why does it matter for security?
GTP (GPRS Tunnelling Protocol) is used to carry user data and signaling across mobile packet core networks and between operators for roaming. GTP-C (control plane) manages sessions and bearer contexts, while GTP-U (user plane) tunnels actual user traffic. GTP was designed without strong security controls, making it vulnerable to attacks such as: session hijacking through GTP-C spoofing, data interception via GTP-U tunnel manipulation, and denial of service through malformed GTP messages. Operators should deploy GTP firewalls at network borders, especially on the GRX/IPX interconnect.
What is the difference between GRX and IPX?
GRX (GPRS Roaming Exchange) is the legacy IP interconnect network used by mobile operators for data roaming, carrying GTP traffic between operators' packet cores. IPX (IP Packet Exchange) is its successor, offering a managed, quality-of-service-aware interconnect that supports not just GTP but also Diameter signaling, IMS/VoLTE traffic, and other services. IPX providers typically offer cascaded hub-based routing and may provide security services such as GTP filtering and Diameter screening at the interconnect level.
Telecom Fraud and Lawful Interception
What are the most common types of telecom fraud?
Common telecom fraud types include: International Revenue Share Fraud (IRSF), where attackers generate calls or SMS to premium-rate numbers they control; Wangiri fraud (one-ring scam), where victims are tricked into calling back expensive international numbers; SIM swap fraud, where attackers socially engineer operators into transferring a victim's number to a new SIM; roaming fraud exploiting delayed CDR processing; and PBX hacking, where enterprise phone systems are compromised to generate unauthorized calls.
IRSF definitionSIM Swap definition
What is lawful interception in telecommunications?
Lawful Interception (LI) is the legally authorized process by which law enforcement agencies can intercept telecommunications (calls, SMS, data sessions) with a court order or equivalent legal authorization. Telecom operators must implement LI capabilities as mandated by national regulations, typically following ETSI LI standards (ETSI TS 102 232 series). The architecture includes: an Administration Function (ADMF) for managing interception requests, Delivery Functions (DF2/DF3) for delivering intercepted content and metadata to Law Enforcement Monitoring Facilities (LEMF), and Mediation/Delivery Functions for format conversion.
Lawful Interception definition
How does roaming fraud work?
Roaming fraud exploits the delay between a subscriber using a service while roaming abroad and the visited network reporting Call Detail Records (CDRs) back to the home network. Fraudsters typically use stolen, cloned or test SIMs in a high-tariff destination (often paired with International Revenue Share Fraud numbers) and burn through huge volumes of calls or data before the home operator's billing system sees the usage and can block the SIM, sometimes hours or even days later. Mitigations include Near-Real-Time Roaming Data Exchange (NRTRDE), high-usage thresholds, GSMA BCE/TAP3 monitoring, machine-learning-based velocity checks, and tighter cooperation between roaming partners.
SIM and Authentication Security
What is a SIM swap attack?
A SIM swap attack (also called SIM hijacking) occurs when an attacker convinces a mobile operator to transfer a victim's phone number to a SIM card they control. This is typically done through social engineering of operator customer service or by exploiting weak identity verification processes. Once successful, the attacker receives all calls and SMS meant for the victim, including two-factor authentication codes, enabling account takeovers for banking, email, and social media. Countermeasures include multi-factor authentication that doesn't rely solely on SMS, carrier-level SIM swap detection, and customer notification systems.
What is eSIM and how does it affect security?
eSIM (embedded SIM) is a reprogrammable SIM built directly into a device, defined by GSMA's SGP.22 specification. Instead of physical SIM card swaps, profiles are downloaded over the air via SM-DP+ (Subscription Manager Data Preparation). Security implications include: elimination of physical SIM theft/cloning risks, but introduction of new attack vectors around remote provisioning, profile management server security, and QR code-based activation flows. eSIM also enables potential privacy improvements through easier profile switching and temporary profiles.
5G Core, SBA and Open RAN
What is the 5G Service-Based Architecture (SBA) and why is it security-sensitive?
The 5G Service-Based Architecture (SBA) replaces the point-to-point Diameter/SS7 model with HTTP/2-based APIs between Network Functions (AMF, SMF, UPF, AUSF, UDM, NRF, SCP, SEPP, etc.). This makes the core look more like a microservices cloud, which brings cloud-native attack surface: API abuse, OAuth 2.0 token forgery, NRF poisoning, SCP routing manipulation, and Kubernetes/container weaknesses. Operators must apply zero-trust principles, mTLS between NFs, strict OAuth scopes, and continuous monitoring of N32 / SBI traffic.
5G SBA definitionSCP definitionNRF definition
What is an SCP in 5G and how can it be abused?
The Service Communication Proxy (SCP) is the 5G core component that brokers signalling between Network Functions, providing indirect communication, load balancing and message routing. Because every NF-to-NF call can flow through it, a compromised or misconfigured SCP becomes an extremely high-impact pivot point: it can re-route requests, strip security headers, forge source identities, or amplify denial-of-service. Hardening requires mTLS, strict OAuth 2.0 token validation (audience, scope, expiry), topology hiding between operators, and SCP-aware monitoring.
SCP definitionSBA Token Forgery
What new attack surface does Open RAN introduce?
Open RAN disaggregates the radio access network into Central Unit (CU), Distributed Unit (DU) and Radio Unit (RU), connected by open interfaces (F1, E1, E2, A1, O1, O2) and managed by a RAN Intelligent Controller (RIC) running xApps and rApps. The benefits are vendor diversity and programmability, but the attack surface grows: open interfaces must be authenticated and encrypted, third-party xApps/rApps need a software supply-chain story (signing, SBOM), and the RIC itself becomes a high-value target. The O-RAN Alliance Security Working Group publishes hardening guidance every release.
Modern Telecom Attacks
What is a SUPI catcher in 5G?
A SUPI catcher is the 5G evolution of the IMSI catcher, a rogue base station or signalling probe that tries to recover a subscriber's permanent identifier (SUPI). 5G mitigates classic IMSI catching by transmitting only the encrypted SUCI over the air, but bidding-down attacks that force the device back to 4G or 2G, weak operator key configurations, or implementation bugs can still expose the SUPI. Defences include disabling 2G fallback where possible, validating null-scheme rejection, and monitoring for anomalous registration patterns.
SUPI Catcher definitionBidding-Down Attack
What is a bidding-down attack on a mobile subscriber?
A bidding-down (or downgrade) attack tricks a 5G or 4G handset into falling back to a weaker generation, typically 3G or 2G, where signalling is unencrypted, authentication is one-way, or known protocol weaknesses can be exploited. It is usually delivered by a rogue base station that advertises better signal on a lower band, or by jamming higher bands. Once downgraded, the attacker can run classic IMSI catching, SMS interception, or call interception. Mitigations include 5G-only / 4G-only device modes, network-side anomaly detection, and operator policy that limits 2G/3G fallback in regions where it is no longer needed.
Bidding-Down definitionIMSI Catcher
How does NRF poisoning work in a 5G core?
The Network Repository Function (NRF) is the 5G service-discovery directory: every NF registers its profile so that others can find it. NRF poisoning is the act of registering a malicious or attacker-controlled NF profile (or tampering with an existing one) so that legitimate NFs are steered to a hostile endpoint, where signalling can be intercepted, modified or dropped. Defences include mTLS-authenticated registration, strict OAuth 2.0 scopes on NRF write APIs, profile signature validation, and continuous monitoring for unexpected NF profile changes.
Regulation, Assurance and the Telecom Security Ecosystem
What is NIS2 and how does it impact telecom operators?
NIS2 (Directive (EU) 2022/2555) is the European Union's updated cybersecurity directive that significantly expands the scope and obligations of the original NIS Directive. It classifies electronic communications providers as essential entities, requires risk-management measures, mandates 24-hour incident notification, and introduces personal liability for management bodies. Telecom operators in the EU must align their security programmes with NIS2 controls, including supply-chain security, vulnerability handling, encryption, and continuous risk assessment.
What are GSMA NESAS and SCAS?
NESAS (Network Equipment Security Assurance Scheme) is a GSMA / 3GPP framework for evaluating the security of telecom equipment vendors and their products. SCAS (Security Assurance Specifications) are the 3GPP-defined test cases that NESAS evaluators run against specific Network Functions (e.g. AMF, SMF, gNB) to verify they meet baseline security requirements. Together they give operators an industry-standard way to compare vendor security posture and are increasingly referenced in operator RFPs and national regulations.
What is GSMA T-ISAC?
GSMA T-ISAC (Telecommunications Information Sharing and Analysis Centre) is a trusted community where mobile operators and ecosystem partners share intelligence about telecom-specific threats, fraud campaigns, signalling attacks, malware affecting subscribers, and emerging vulnerabilities. Membership gives operators early visibility on threats other carriers are seeing, plus a coordinated channel to GSMA Fraud and Security working groups (FASG, FS-series documents).
How does P1 Security help operators secure their networks?
P1 Security has specialised in mobile network security since 2011, covering the full telecom stack: SS7 and Diameter signalling, GTP, IMS/VoLTE, 5G SBA, Private 5G, RAN and NFV. Engagements typically combine deep-dive audits and red-team exercises (using P1's own tools), continuous threat management and monitoring, incident response, training for operator security teams, and supply-chain assessments of network equipment. P1 is a GSMA member, ISO 27001 certified, and contributes to GSMA fraud and security workstreams.
AI, Automation and the Future of Telecom Security
How is AI being used by telecom attackers and defenders today?
On the attacker side, AI is industrialising what used to be manual work: automated SS7 and Diameter probing to map operator interconnect surface, AI-crafted smishing and voice phishing at scale, deepfake vishing aimed at carrier customer-care to drive SIM swaps and number ports, and LLM-assisted reconnaissance of leaked OSS/BSS documentation. On the defender side, machine learning powers anomaly detection on signalling traffic (catching unusual MAP/Diameter/HTTP-2 patterns that rule-based firewalls miss), ML-based fraud scoring on CDRs and roaming events to stop IRSF and Wangiri in near real time, and LLM-assisted triage in telecom SOCs to summarise alerts, correlate threat intelligence, and accelerate incident response. The attacker–defender gap is closing, operators that don't add ML to their signalling firewalls and fraud platforms are falling behind.
SS7 definitionDiameter definitionIRSF definition
What is GenAI's role in 5G operations and what new risks does it introduce?
Generative AI is being embedded across 5G operations: intent-based network configuration (operators describe a desired state in natural language and a copilot generates the AMF/SMF/UPF config), RAN optimisation through ML-driven parameter tuning and energy savings, customer-care copilots on top of OSS/BSS data, and AI-assisted SOC analysts. The new attack surface is significant: prompt injection in OSS/BSS copilots can be used to exfiltrate subscriber data or push unauthorised network changes, hallucinated configurations can silently weaken security posture (open ACLs, disabled firewalls, weak crypto), training pipelines that ingest live operator data create a brand-new data-leakage path, and the model supply chain (third-party foundation models, fine-tuning datasets, plugins) becomes a high-value target. Mitigations include strict input/output filtering on copilots, human-in-the-loop approval for any configuration change, isolated training environments, signed and SBOM-tracked models, and treating GenAI components as critical Network Functions in NESAS / SCAS-style assurance.
Private 5G, Enterprise and Network Architecture
What is the difference between a private 5G network and a public one, and what are the security trade-offs?
A public 5G network is operated by a mobile network operator (MNO) and shared across millions of subscribers, with spectrum licensed nationally and roaming, lawful interception, and interconnect built in. A private 5G network is deployed for a single organisation, a factory, port, mine, hospital, military base, or campus, typically using locally licensed or shared spectrum (CBRS in the US, the 3.7–3.8 GHz band in Europe, n77/n78 elsewhere), with the core network either on-premises, hosted by a system integrator, or delivered as a network slice from an MNO. The security trade-offs cut both ways. On the upside: traffic stays on-site, the attack surface is smaller, no roaming or interconnect exposure to SS7/Diameter/GTP from foreign networks, and the operator (the enterprise itself) has full control over policy, patching, and SIM provisioning. On the downside: the enterprise inherits responsibilities it has never had before, running an HSS/UDM, managing AKA credentials, securing the N2/N3/N4 interfaces, hardening the gNB and UPF, monitoring signalling, handling lawful interception where required, and patching telecom-grade software. Most enterprises underestimate this and end up with default credentials, exposed O&M interfaces, weak segmentation between IT and OT, and no signalling visibility. P1 Security audits private 5G deployments end-to-end against 3GPP, GSMA NESAS/SCAS and O-RAN security specifications.
5G SBA definitionNetwork Slicing definition
What is a signalling firewall and how is it different from an IT firewall?
An IT firewall enforces policy on IP packets, it inspects source/destination addresses, ports, and increasingly application-layer payloads (HTTP, TLS SNI, DNS) to allow or block traffic between zones. It has no understanding of telecom signalling. A signalling firewall sits on the operator's interconnect borders (STP for SS7, DEA for Diameter, SEPP for 5G SBA, and equivalent nodes for GTP and SIP) and inspects telecom protocol messages: MAP operations, Diameter commands and AVPs, GTP-C messages, SIP methods, HTTP/2 service requests on N32. It enforces GSMA-recommended categorisation (FS.11 for SS7, FS.19 for Diameter, FS.36/FS.37 for 5G), validates that the originating network is allowed to send a given message for a given subscriber, detects velocity anomalies (the same IMSI updating location in two countries seconds apart), prevents SMS interception and location tracking, and blocks fraud patterns like SIMjacker, MAP-AnyTimeInterrogation abuse, or Diameter Update-Location injection. An IT firewall in front of an STP would let all of this through, it sees only valid SCTP/IP. Operators need both layers, and the signalling firewall must be tuned per-roaming-partner, continuously updated as new attacks emerge, and monitored by analysts who understand telecom protocols.
Browse the glossary for definitions, the guide for structured explanations, and the comparisons section for head-to-head breakdowns.