Signaling Attacks: ss7 signaling security, diameter vulnerabilities, gtp-u hijacking
Analysis of signaling vulnerabilities across SS7, Diameter, and 5G HTTP/2. Research on location tracking, call redirection, and signaling storms.
SS7 (Signaling System No. 7), despite being designed in the 1970s without security assumptions, continues to interconnect global mobile networks through roaming agreements that cannot be unilaterally decommissioned. The core attack surface is the MAP (Mobile Application Part) protocol layer, where unauthenticated message injection by any SS7-connected entity can enable precise subscriber location tracking, SMS interception, voice call redirection, and targeted denial of service — all without the subscriber's knowledge.
Diameter, introduced as the successor to SS7 for 4G/LTE interconnects, corrected some authentication gaps but retained a trusted-network model that is actively exploited. The S6a interface between the MME and HSS is particularly sensitive, exposing authentication vectors and subscriber profile data to every interconnect partner. The Gx and Gy interfaces, used for policy control and online charging, also present fraud vectors when routing anomalies allow unauthorized PCRF or OCS impersonation.
GTP (GPRS Tunneling Protocol) governs user-plane traffic encapsulation across core network interfaces. GTP-C control-plane vulnerabilities — through crafted Create Session and Modify Bearer messages — allow session hijacking, user-plane traffic redirection, and billing fraud. The 5G Service Based Architecture (SBA) introduces HTTP/2 REST API abuse as a new class of signaling attack, enabling NRF poisoning and cross-function token theft.
Defense standards for this domain include GSMA FS.11 (SS7 Security Guidelines), GSMA FS.19 (Diameter Security Guidelines), and 3GPP TS 33.117. Signaling firewalls from vendors such as Cellusys, Mobileum, and P1 Security implement rule-based detection for known SS7 and Diameter attack categories. Monitoring for anomalous inter-PLMN messaging patterns — especially AnyTimeInterrogation and SendRoutingInfo messages — is the primary detection mechanism for active location tracking attacks.
:: KEY THREAT VECTORS
:: INTELLIGENCE FEED













:: RELATED RESOURCES
READY TO MASTER SIGNALING ATTACKS?
Access hands-on simulation environments, protocol fuzzers, and specialized labs mapping specifically to signaling attacks vulnerabilities.