DDoS (Distributed Denial of Service)

A Distributed Denial of Service attack uses many compromised hosts (a botnet) or amplification techniques to overwhelm a target with traffic, exhausting bandwidth or compute and rendering services unavailable. Telecom-specific DDoS targets include SIP servers, DNS resolvers, signalling endpoints, and increasingly 5G control-plane interfaces. Defence relies on upstream scrubbing, anycast, rate limiting, and protocol-aware filtering.

Categories: SignalingThreats and AttacksProtocols and Standards

DDoS in context

Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.

Telecom threats range from opportunistic SMS phishing and SIM swap to nation-state grade location tracking. The common thread is that most attacks exploit the inherited trust model of legacy signaling protocols.

To place DDoS in the wider telecom-security picture, review Denial of Service (DoS), Attack Surface Mapping, Exposure Mapping, Indicators of Compromise (Telecom IoCs), mMTC and Cipher Downgrade Attack: each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • Diameter Attacks S6a IDR/PUR/CLR abuse, subscriber tracking, LTE signaling attacks.
  • Diameter Security 4G/LTE Diameter threats across IPX/roaming and DEA defenses.
  • Signaling Firewall Unified SS7/Diameter/GTP/SMS signaling firewall framework.
  • 5G Security 5G SBA, SEPP, SUCI, 5G-AKA, N32 and service-based interface security.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.