Roaming Security
Roaming is the mechanism that lets a subscriber use their phone on a network other than their home operator. It also happens to be the single largest external attack surface in a mobile network: interconnect signaling, whether SS7, Diameter, GTP, or 5G HTTP/2 SBI over SEPP, crosses commercial boundaries into networks the home operator does not administer. Historically every generation of mobile network has trusted its roaming partners implicitly, and every generation has paid for that assumption with a documented class of attacks.
This hub aggregates everything the Ultimate Guide covers on roaming security: the interconnect protocols themselves (SS7 MAP/CAMEL, Diameter S6a/S9/S6d, GTP-C over GRX/IPX, HTTP/2 N32 over SEPP), the difference between home-routed and local-breakout architectures and what each implies for signaling exposure, the GSMA countermeasure schemes (FS.11 for SS7, FS.19 for Diameter, FS.20 for GTP, FS.34 for 5G interconnect), roaming firewall deployment models, and the operational monitoring practice that turns a category-1/2/3 signature into an actionable alert.
Roaming security is not just interconnect filtering. It is a full stack: IR.21 data hygiene, IR.77 SS7 practice, roaming steering behaviour, VPLMN selection, subscriber-location-privacy handling, lawful-intercept segregation between HPLMN and VPLMN, and fraud controls (IRSF, Wangiri, roaming premium-rate) all sit inside the roaming perimeter.
Frequently asked questions about roaming security
What is the GRX/IPX and why is it security-relevant?
The GRX (GPRS Roaming Exchange) and its successor IPX (IP Packet Exchange) are private interconnect networks that carry roaming traffic between mobile operators. Because they transport sensitive signaling (Diameter, GTP) between operator boundaries, they are prime targets for interception and injection attacks. Securing IPX requires end-to-end encryption and mutual authentication between roaming partners.
What is GSMA FS.19 for Diameter roaming security?
GSMA FS.19 is the Diameter Interconnect Security recommendations document, structurally analogous to FS.11 for SS7. It defines category-based filtering for Diameter roaming and interconnect messages (S6a, S9, S6d, S13, Rx) covering subscriber tracking, information disclosure, denial of service, and fraud/interception scenarios. Diameter firewalls at the DEA (Diameter Edge Agent) implement these categories at the LTE/4G roaming boundary.
What tools are used for SS7/Diameter security testing?
Specialized tools for telecom security testing include SigPloit (open-source SS7/Diameter/GTP testing framework), P1 Security's assessment platforms, Catapult/Developing Solutions test suites, and custom SCTP/TCAP stacks. These tools can craft and send specific signaling messages to test how network elements respond to malicious or malformed requests.
Do I need a Diameter firewall if I already have an SS7 firewall?
Yes. SS7 firewalls filter at the SCCP/MAP/CAP layer and do not see Diameter traffic, which uses a different transport (SCTP/TCP with TLS/IPsec) and different attack semantics (S6a IDR/PUR, S9, S13). GSMA FS.19 defines category 1/2/3 screening rules that a Diameter Edge Agent (DEA) must enforce independently. Operators running 4G/LTE interconnect need both firewalls; consolidated signaling firewalls implement the FS.11/FS.19/FS.20 rule sets in a single policy engine.
What does GSMA FS.20 require for GTP firewalling?
GSMA FS.20 defines category-based screening for GTP-C and GTP-U at GRX/IPX borders, structured similarly to FS.11 (SS7) and FS.19 (Diameter). It covers cross-plane filtering (GTP-U packets must not carry control-plane commands), source-address validation against IR.21-declared prefixes, TEID sanity checks, IMSI/APN allowlisting for known roaming partners, and rate limits to blunt DoS. The document is periodically revised; the current baseline is a mandatory reference for operators offering LTE roaming.
What are roaming attacks and why are they difficult to prevent?
Roaming attacks exploit the interconnect signaling between operators (SS7, Diameter, GTP) to perform location tracking, call/SMS interception, and fraud while the attacker operates from a remote network. They are difficult to prevent because roaming requires operators to accept certain signaling messages from partner networks, and legitimate roaming traffic can be hard to distinguish from malicious queries.
What is the Diameter protocol and how is it exploited?
Diameter replaced SS7 MAP for 4G/LTE signaling, handling authentication, authorization, and accounting between network functions. Despite using SCTP/TCP transport, Diameter inherits trust-model weaknesses from the interconnect architecture. Attacks include unauthorized subscriber location queries, forced handover to rogue networks, and denial of service via crafted Diameter messages.
What is a Diameter Edge Agent (DEA) and how does it enforce security?
A Diameter Edge Agent is the network element that terminates Diameter roaming and interconnect signaling at the border of an operator's network. It performs message routing, topology hiding, protocol translation, and security enforcement — validating origin realms, filtering Category 1/2/3 messages per GSMA FS.19, rate-limiting suspicious flows, and cross-checking VPLMN plausibility. In practice, most Diameter firewall functionality is deployed as a DEA feature.
How much does an SS7 penetration test typically cost and how long does it take?
A typical SS7 penetration test against a Tier-1 MNO runs 4–8 weeks and covers GSMA FS.11 category 1/2/3 test cases across MAP, CAP and SCCP. Cost varies widely with scope (single-country vs. multi-country, home vs. roaming interfaces, MVNO tenants), STP model, and whether monitoring/PCAP infrastructure is already available. Fixed-scope engagements for a national operator commonly land in the mid five- to low six-figure USD range; a global carrier with dozens of interconnects is a multiple of that.
What is SS7 and why is it considered insecure?
SS7 (Signaling System No. 7) is the signaling protocol suite used by 2G/3G networks for call setup, SMS delivery, and roaming. It was designed in the 1970s with an implicit trust model and no authentication or encryption. Attackers who gain access to the SS7 network—via compromised operators or rogue nodes—can intercept calls, track subscriber locations, and redirect SMS messages.
What is SS7 location tracking and can it track my phone?
SS7 location tracking exploits the SendRoutingInfo and ProvideSubscriberInfo MAP operations to query a subscriber's serving cell, revealing their approximate geographic location. Any entity with SS7 network access—including rogue operators or intermediaries—can perform this attack remotely, without the target's knowledge. While 5G and Diameter partially mitigate this, most networks still have 2G/3G fallback, keeping the risk alive for billions of subscribers worldwide.
What is GSMA FS.11 and why does it matter for SS7 security?
GSMA FS.11 is the SS7 Interconnect Signalling Security Recommendations document. It classifies MAP operations into three categories: Category 1 (operations that should never appear across an interconnect and can be blocked outright), Category 2 (operations that are legitimate only from a subscriber's home network), and Category 3 (operations that require cross-checks such as velocity or plausibility). SS7 firewalls are typically configured against these categories, and telecom security audits verify coverage per FS.11.
Related glossary terms
- Inter-PLMN Security
- IPX IP Packet Exchange
- Roaming
- GRX GPRS Roaming Exchange
- MSSP Managed Security Service Provider
- FS.36 5G Interconnect Security Guidelines
- DEA Diameter Edge Agent
- FASG GSMA Fraud and Security Group
- FS.07 GSMA Reference Document
- GTP Firewall
Related comparisons
Compliance crosswalks
Regulation by jurisdiction
- European Union ENISA + national NRAs (BNetzA, ARCEP, AGCOM, ANACOM, etc.)
- Germany BNetzA + BSI
- India DoT + TRAI + CERT-In
- United Arab Emirates TDRA + UAE Cybersecurity Council
More on Roaming Security
Browse all topic hubs, the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.