MITRE D3FEND

In telecommunications, MITRE D3FEND is a complementary framework to ATT&CK that catalogs defensive countermeasures and the techniques they neutralize. Applied to telecom, it helps map controls such as signaling firewalling, NF authentication, slice isolation, and OAM bastioning to the specific adversary techniques they are designed to defeat.

Categories: SignalingSecurity ControlsEncryption and Cryptography

MITRE D3FEND in context

Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

To place MITRE D3FEND in the wider telecom-security picture, review 1G, 5G SBA, AAA, ACL, Any-Time Interrogation (ATI) and AP — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.