Hardening

In telecommunications, Hardening is the process of reducing the attack surface of a network function, host, or signaling node by disabling unused services, enforcing least-privilege accounts, applying secure baselines, and configuring protocol-level controls (for example MAP category filtering, GTP-C rate limits, or SBA OAuth2 scope restrictions). Hardening guidelines are published by 3GPP, GSMA SCAS, and vendors.

Categories: Core NetworkSignalingSecurity Controls

Hardening in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.

To place Hardening in the wider telecom-security picture, review ACL, Core Network Security Assessment, OAM Compromise, 5G SBA, SCP Abuse and SCP: each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • Diameter Security 4G/LTE Diameter threats across IPX/roaming and DEA defenses.
  • GTP Firewall GSMA FS.20 GTP-C/GTP-U screening on GRX/IPX borders.
  • Signaling Firewall Unified SS7/Diameter/GTP/SMS signaling firewall framework.
  • GTP Security GTP-C/GTP-U threats across S5/S8, N3/N9 and GRX/IPX borders under GSMA FS.20.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.