Telecom security topic hubs
35 deep-dive hubs covering SS7, Diameter, GTP, 5G, SEPP, IMS/VoLTE, Open RAN, roaming, signaling firewalls, IMSI catchers, SIM swap, telecom fraud and penetration testing.
- SS7 Security — Vulnerabilities, Attacks & DefensesComplete guide to SS7 security: vulnerabilities, real-world attacks (location tracking, SMS interception, call redirection), and operator defenses.
- 5G Security — SBA, SEPP, Slicing & Threat ModelComplete guide to 5G security: SBA, SEPP/N32, network slicing, private 5G, and the 5G threat model.
- Diameter Security — LTE Signaling Attacks & DefensesGuide to Diameter signaling security in LTE/4G networks: known attacks, GSMA FS.19 categories, and Diameter firewall controls.
- Open RAN Security — O-RAN Threat Model & ControlsOpen RAN (O-RAN) security: threat model, disaggregated interfaces, xApps/rApps, and controls for RAN security.
- Routing Area Update (RAU) — GPRS Mobility ExplainedHow Routing Area Update (RAU) works in GPRS/UMTS mobility management and its security implications.
- Tracking Area Update (TAU) — LTE Mobility ExplainedHow Tracking Area Update (TAU) works in LTE/4G mobility management and the security surface it exposes.
- NAS Security — LTE/5G Non-Access StratumNon-Access Stratum (NAS) security in LTE and 5G: procedures, ciphering, integrity, and known weaknesses.
- SS7 Firewall — Signaling Firewall for SS7 NetworksHow SS7 firewalls work: GSMA FS.11 categories, filtering, monitoring, and deployment guidance for operators.
- Signaling Firewall — SS7, Diameter, GTP, SIPSignaling firewalls across SS7, Diameter, GTP and SIP: architecture, filtering categories, and operational practice.
- Telecom Penetration Testing — Scope, Methods, DeliverablesTelecom penetration testing: signaling, radio, core, IMS/VoLTE, and 5G. Scope, methodology, and typical deliverables.
- SS7 Penetration Testing — Methodology & Test CasesSS7 penetration testing methodology: category-based test cases, GSMA FS.11 mapping, and reporting.
- Telecom Security Training — SS7, Diameter, 5G, IMSStructured telecom security training references: SS7, Diameter, LTE, 5G, IMS.
- Diameter Firewall — LTE Signaling FirewallHow Diameter firewalls work in LTE/4G roaming and interconnect: GSMA FS.19 categories and deployment guidance.
- GTP Firewall — GTP-C / GTP-U FilteringGTP firewalls for GTP-C and GTP-U traffic: attack surface, GSMA FS.20, and deployment models.
- SMS Firewall — A2P Filtering & Anti-FraudSMS firewalls: A2P filtering, SMS fraud (grey routing, smishing), and interoperability with signaling firewalls.
- 5G Penetration Testing — SBA, SEPP, Slicing5G penetration testing methodology across SBA, SEPP/N32, slicing, and private 5G.
- SS7 Security TrainingSS7 security training references: signaling fundamentals, attacks, and defenses.
- LTE Security TrainingLTE (4G) security training references: Diameter, EPC, mobility, and IMS/VoLTE.
- 5G Security Training5G security training references: SBA, SEPP, slicing, and private 5G.
- IMS Security TrainingIMS/VoLTE security training references: SIP, Diameter Cx/Sh, and IMS threat model.
- IMSI Catcher — What It Is, How It Works, DetectionIMSI catchers (fake base stations): how they work, detection methods, and countermeasures across GSM/LTE/5G.
- SIM Swap Attack — How It Works & How to DefendSIM swap attacks: end-to-end mechanics, operator-side controls, and user-side defenses.
- Silent SMS — Type 0 SMS, Tracking & DetectionSilent SMS (Type 0 SMS): how it works, tracking uses, and detection at the network side.
- Private 5G Security — Threat Model & ControlsSecurity for private 5G networks (industrial, campus): threat model, isolation, and operational controls.
- Telecom Security Audit — Scope & MethodologyTelecom security audits: scope, methodology, deliverables, and standards mapping.
- Telecom Red Team — Objectives & Engagement ModelTelecom red team engagements: objectives, scenarios, and engagement model for operators.
- 5G NEF Security — Network Exposure Function5G Network Exposure Function (NEF) security: role, risks, and controls for API exposure to third parties.
- MVNO Security — Threat Model, Roaming Risks & ControlsMVNO/MVNE security: threat model, host-network trust boundary, roaming exposure, IMSI privacy, SS7/Diameter risks, and NIS2/GSMA regulatory posture.
- Roaming Security — SS7, Diameter, GTP & GSMA FS.11/FS.19Roaming and interconnect security: SS7/Diameter/GTP risks, home-routed vs local-breakout, GSMA FS.11/FS.19/FS.20, roaming firewalls, and IPX/GRX defenses.
- VoLTE & VoNR Security — IMS, SIP, Diameter Cx/ShVoLTE and VoNR security: IMS architecture, SIP signaling risks, Diameter Cx/Sh/Rx, media plane (SRTP), IMS-AKA, and 5G voice migration.
- Diameter Attacks — S6a, IDR, PUR, CLR & LTE Signaling AbuseCatalog of Diameter signaling attacks in LTE/4G: S6a abuse (IDR, PUR, CLR), subscriber tracking, interception, DoS, mapped to GSMA FS.19 categories.
- Telecom Fraud — IRSF, Wangiri, SIM Box, PBX HackingFull taxonomy of telecom fraud: IRSF, Wangiri, SIM box bypass, PBX hacking, subscription fraud, CLI spoofing, and A2P SMS grey routing.
- 6G Security — Threat Model, AI/ML, Post-Quantum & ISACForward-looking guide to 6G security: threat model, AI/ML-native risks, integrated sensing and communication (ISAC), post-quantum cryptography, and IMT-2030 standards trajectory.
- GTP Security — GTP-C/GTP-U, GRX/IPX & GSMA FS.20Complete guide to GTP security: GTP-C/GTP-U threats on S5/S8, N3/N9 and GRX/IPX borders, GSMA FS.20 firewall categories, TEID and APN hardening.
- SEPP Security — N32-c, N32-f, PRINS & 5G Roaming EdgeComplete guide to 5G SEPP security: mutual TLS on N32-c, PRINS/TLS on N32-f, JWE-protected sensitive IEs, IPX modification schemas, and OAuth 2.0 authorization.
See also the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.