Exposure Mapping

Exposure mapping is the continuous discovery, classification, and tracking of every internet-reachable asset, signalling endpoint, API, and service that an operator exposes, intentionally or otherwise. It feeds prioritised hardening, vulnerability management, and red-team scoping, and is increasingly delivered as continuous threat exposure management (CTEM) tooling.

Categories: SignalingThreats and AttacksInternet and Routing

Exposure Mapping in context

Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.

Telecom threats range from opportunistic SMS phishing and SIM swap to nation-state grade location tracking. The common thread is that most attacks exploit the inherited trust model of legacy signaling protocols.

To place Exposure Mapping in the wider telecom-security picture, review CVE, DDoS, Egress, CALEA, Core Network Security Assessment and Insider Threat: each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • 5G NEF Security Network Exposure Function security in the 5G core.
  • SS7 Security SS7/MAP/CAP/SCCP attacks and defenses across 2G/3G interconnect.
  • SS7 Firewall GSMA FS.11 category 1/2/3 SS7 message screening at the STP edge.
  • Diameter Attacks S6a IDR/PUR/CLR abuse, subscriber tracking, LTE signaling attacks.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.