Egress

Egress refers to traffic leaving a network or system. Egress filtering blocks unauthorised outbound flows and is a critical control against data exfiltration, command-and-control communication by malware, and the operator becoming a source of spoofed traffic (per BCP 38). Mature egress policy combines firewall rules, DNS filtering, and DLP tooling.

Categories: Security ControlsThreats and AttacksInternet and Routing

Egress in context

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

Telecom threats range from opportunistic SMS phishing and SIM swap to nation-state grade location tracking. The common thread is that most attacks exploit the inherited trust model of legacy signaling protocols.

To place Egress in the wider telecom-security picture, review BGP Hijacking, IDS, SCP Abuse, N6, ASN and LAN: each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • Diameter Attacks S6a IDR/PUR/CLR abuse, subscriber tracking, LTE signaling attacks.
  • SS7 Firewall GSMA FS.11 category 1/2/3 SS7 message screening at the STP edge.
  • Diameter Security 4G/LTE Diameter threats across IPX/roaming and DEA defenses.
  • Diameter Firewall GSMA FS.19 screening at the Diameter Edge Agent on S6a/S9/S13.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.