MITRE D3FEND

In telecommunications, MITRE D3FEND is a complementary framework to ATT&CK that catalogs defensive countermeasures and the techniques they neutralize. Applied to telecom, it helps map controls such as signaling firewalling, NF authentication, slice isolation, and OAM bastioning to the specific adversary techniques they are designed to defeat.

Categories: SignalingSecurity ControlsEncryption and Cryptography

MITRE D3FEND in context

Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

To place MITRE D3FEND in the wider telecom-security picture, review ACL, Operational Security (OPSEC), SS7 Interconnect Security, Hardening, MITRE FiGHT and Any-Time Interrogation (ATI): each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • SS7 Firewall GSMA FS.11 category 1/2/3 SS7 message screening at the STP edge.
  • Signaling Firewall Unified SS7/Diameter/GTP/SMS signaling firewall framework.
  • SS7 Security SS7/MAP/CAP/SCCP attacks and defenses across 2G/3G interconnect.
  • Diameter Firewall GSMA FS.19 screening at the Diameter Edge Agent on S6a/S9/S13.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.