Routing Area Update (RAU) Security

The Routing Area Update (RAU) is the GPRS/UMTS packet-switched mobility procedure a mobile uses to tell the network it has moved between Routing Areas, that its periodic RAU timer expired, or that its packet-switched context needs to be re-established. It is defined in 3GPP TS 23.060 and the GMM signaling in TS 24.008, and it has direct successors in LTE (Tracking Area Update, TAU) and 5G (Registration procedure), the security questions translate across all three.

This hub aggregates Ultimate Guide coverage of the RAU signaling flow between the UE, SGSN, old SGSN/MME and HLR/HSS over GTP-C and MAP/Diameter; the location-privacy exposure created by P-TMSI/GUTI reallocation and IMSI fallback; the signaling-integrity gaps abused via inter-SGSN RAU and SGSN-spoofing attacks at the GRX/IPX boundary; and the operator-side controls (GTP firewalls, Diameter edge agents, SEPP/PRINS in 5G) that contain RAU-class abuse on a live network.

Frequently asked questions about routing area update (rau) security

What is a Wangiri fraud scam?

Wangiri (Japanese for "one ring and cut") is a fraud where scammers place a very short call from a premium international number, hoping the recipient calls back and incurs charges that route revenue to the fraudsters. It is a variant of IRSF and is countered with the same techniques: destination blocking, callback pattern detection, subscriber education, and coordination between operators via GSMA and CFCA channels.

Are commercial IMSI catcher detection apps reliable?

Mixed. Apps that rely only on unprivileged Android APIs can flag some GSM-era anomalies (unexpected LAC changes, missing neighbor cells, weak ciphering indicators) but cannot inspect the LTE/5G radio stack in depth and often produce false positives. Reliable detection today combines dedicated SDR-based probes, network-side anomaly detection on the RAN and core (unexpected paging, TAU/RAU patterns), and passive sensor networks. Consumer apps are useful as awareness tools but not a substitute for operator-side detection.

What is the difference between GTP-C and GTP-U from a security standpoint?

GTP-C (control plane, TS 29.274) carries session management — Create/Modify/Delete Session Request — between MME/AMF/SMF and SGW/UPF, and between visited and home operators on S8. Its threats are session hijack, TEID prediction, IMSI enumeration and DoS. GTP-U (user plane, TS 29.281) tunnels subscriber data over S1-U/N3/N9. Its threats are overbilling, GTP-in-GTP smuggling, and lateral movement between PDU sessions. GSMA FS.20 defines separate screening for each; GTP firewalls typically enforce both in a single policy engine.

What are fraud management systems (FMS) in telecom?

Fraud management systems analyze CDRs, signaling data, and subscriber behavior patterns to detect revenue fraud such as International Revenue Share Fraud (IRSF), Wangiri (one-ring) fraud, SIM box fraud, and subscription fraud. Modern FMS solutions use machine learning to identify emerging fraud patterns and can trigger automated responses like call blocking or subscriber alerts.

What is IRSF (International Revenue Share Fraud) and how do operators stop it?

International Revenue Share Fraud (IRSF) is a fraud scheme where criminals generate high volumes of calls to premium international numbers whose revenue is shared with them by the terminating carrier. It typically abuses hacked PBXs, compromised SIMs, or subscription fraud to drive traffic. Defenses include real-time call-pattern analytics, destination allow/deny lists, velocity limits on new subscribers, wholesale carrier due diligence, and industry data sharing (e.g. CFCA feeds).

What is a SIM box (interconnect bypass fraud) and why is it a problem?

A SIM box is a device holding many local SIM cards that terminates inbound international VoIP traffic as local mobile calls, bypassing the legitimate international interconnect and its termination fees. It causes revenue loss for the operator, degraded call quality, incorrect CLI presentation, and often coincides with subscription fraud on the SIMs used. Detection relies on test-call generation, traffic analytics on CDRs (unusual call patterns, high outbound-only SIMs), and radio-side fingerprinting.

How big are annual telecom fraud losses globally?

The Communications Fraud Control Association (CFCA) survey estimates industry fraud losses in the tens of billions of USD per year, with IRSF, subscription fraud, PBX toll fraud and Wangiri consistently in the top categories. Loss estimates vary widely by methodology (invoiced-but-unpaid vs. termination-fee leakage vs. downstream fraud enabled), and losses continue to shift toward A2P SMS bypass, flash-call abuse, and OTT bypass as call volumes migrate. Individual operator exposure depends heavily on interconnect footprint and MVNO tenants.

When is 6G expected to be commercially deployed and what should security teams start doing now?

ITU-R IMT-2030 targets 6G specifications around 2028–2030, with first commercial deployments generally forecast for the 2030 window. Security teams should already be tracking three inputs: (1) 3GPP Release 20+ studies on AI/ML-native security, integrated sensing and communication (ISAC), and post-quantum profiles; (2) GSMA PQ.03 for PQC migration in signaling and roaming; (3) ETSI ISG SAI for AI-security threat models that will feed 6G designs. Investment now in PQC hybrid pilots and AI/ML threat modeling will pay off directly against 6G rollout timelines.

See all telecom security FAQs

Related glossary terms

  • GTP GPRS Tunneling Protocol
  • SGSN Serving GPRS Support Node
  • FS.20 GPRS/GTP Security
  • AMF Access and Mobility Management Function
  • AMPS Advanced Mobile Phone System
  • EIR Equipment Identity Register
  • FS.19 GSMA Fraud and Security Group Recommendations
  • GGSN Gateway GPRS Support Node
  • GPRS General Packet Radio Service
  • GTP Firewall

Browse the full telecom security glossary

More on Routing Area Update

Browse all topic hubs, the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.