Most modern Security Operations Centers (SOCs) are designed from the ground up to protect enterprise IT environments. They ingest endpoints, active directory event logs, web proxies, and email gateways, correlating them with commercial and open-source threat feeds. While this IT-centric framework works well for safeguarding corporate offices, it fails to protect the core network infrastructure of a Mobile Network Operator (MNO).
As carriers transition to 5G Standalone (SA) and manage legacy 2G/3G/4G network interfaces, their security organizations realize that standard threat feeds leave them blind.
To protect vital subscriber communications and prevent global signaling tracking, operators must understand the structural limitations of generic threat intelligence and establish robust criteria for evaluating curated telecom threat intelligence resources.
INTEL CRITERIA
This research paper outlines why classic corporate threat feeds are insufficient for telecommunications infrastructure. It maps out the key cellular protocol interfaces, provides a concrete evaluation framework for selecting a curated intelligence provider, and outlines how to optimize security operations for maximum threat coverage.
KEY TAKEAWAYS:
- Enterprise threat feeds focus on endpoints and common IT vectors, lacking cellular protocol visibility.
- Transitioning to a curated telecom threat feed is vital for proper core network event correlation and filtering.
- Specialized feeds deliver high-fidelity cellular indicators like IMSIs, Global Titles, and GTP Tunnel IDs.
- Evaluation of intelligence sources requires strict validation of real-time update frequencies and interconnect probe captures.
- Seamless integration of curated feeds directly optimizes SOC alert prioritization mechanisms.
Why Standard IT Threat Feeds Fail MNOs
The fundamental architecture of cellular communications relies on protocols that standard IT firewalls and Endpoint Detection and Response (EDR) agents do not understand. Standard enterprise threat intelligence aggregates file hashes, malicious domain names, and corporate phishing IPs. While useful for securing corporate workstations, these feeds provide zero visibility into the transit lines of a telecom core network.
For a telecom security team, this gap translates to complete blindness regarding:
- SS7/Diameter Interconnect Infrastructure: Third-party aggregators and malicious operators query network nodes to track subscriber locations or hijack SMS routing.
- GTP Control Plane Routing: Malicious packets bypass charging systems, execute Denial of Service (DoS) attacks on core elements, or intercept user packets.
- 5G SBA APIs: Containerized Network Functions (NFs) communicate via HTTP/2 REST APIs that require specialized JSON-LD and OpenAPI structure inspection.
Without mobile network operator threat intelligence, SOC analysts are overwhelmed with enterprise workstation malware alerts while critical signaling intrusion attempts go completely undetected.
Technical Indicators: Generic vs. Curated Telecom Threat Intel
To build a reliable defense posture, telecom security teams must replace generic IT indicators with specialized cellular parameters that reflect active inter-operator and RAN attacks:
| Telemetry Data Layer | Generic IT Threat Indicators | Curated Telecom Threat Indicators |
|---|---|---|
| Endpoint / Node Identifiers | IP Addresses, MAC Addresses, Hostnames | International Mobile Subscriber Identity (IMSI), MSISDN, Global Title (GT) |
| Network Interfaces | TCP/80, TCP/443, DNS queries, TLS handshakes | SCTP/M3UA signaling connections, Diameter S6a, GTP-C and GTP-U tunnels |
| RF / Access Networks | Wi-Fi SSIDs, Bluetooth UUIDs | Cell Global Identifier (CGI), Local Area Code (LAC), gNodeB IDs |
| Vulnerability Mapping | CVE-2026-XXXX (Windows/Linux OS flaws) | 3GPP Specification Flaws, Baseband Modem Firmware RWP vulnerabilities |
5 Evaluation Criteria for Curated Telecom Threat Intelligence
When telecom security leaders outgrow basic IT-centric feeds, they must establish structured benchmarks to evaluate a specialized curated threat intelligence subscription.
1. Protocol Ingestion Depth
A specialized feed must provide indicators that cover the entire generational hierarchy of the carrier network:
- Legacy Networks (2G/3G): Tracking malicious Global Titles, SS7 SCCP calling configurations, and MAP message anomalies.
- Current Networks (4G LTE): Ingesting Diameter S6a, S9, and S11 interface vulnerabilities, routing manipulation indicators, and GTP-C tunnel storms.
- Modern Architectures (5G): API parameters, JSON injection profiles targeting SBI endpoints, and authorization failures at the SEPP (Security Edge Protection Proxy).
2. Interconnect Telemetry Sources
The value of threat intelligence is directly tied to where the data is captured. When reviewing resources, MNOs must ask:
- Does the provider capture real-world signaling packets from passive edge probes?
- Is the telemetry gathered from global roaming exchanges (IPX/GRX gateways)?
- Does the feed incorporate data shared within secure carrier communities (like GSMA T-ISAC)? Feeds built on real, passive signaling capture offer drastically lower false-positive rates than those relying on simulated attacks.
3. Threat Model Updates & Maintenance
Telecom attack methods evolve as new standards are implemented. Curated resources must demonstrate structured policies for threat intelligence maintenance and updates:
- Real-Time Feeds: Daily updates for malicious GT lists and active smishing SMS signatures.
- Strategic Updates: Quarterly threat modeling modifications based on emerging 5G network security architecture and findings from private LTE/5G lab research.
4. Machine-Readable Schema Support
The feed must integrate natively with standard threat ingestion tools. This requires compatibility with standard taxonomies extended for telecom entities:
- STIX 2.1 Compatibility: Supporting custom cyber observables that define cellular parameters (IMSIs, GTs, Point Codes).
- MISP Taxonomy Mapping: Seamless synchronization with open-source taxonomies that enable machine-to-machine indicator sharing.
5. SIEM & SOAR Integration Native Features
Ingesting data is only half the battle. The intelligence must map directly to automated defensive systems. Curated resources must provide native logic rules, Snort/Zeek parsing rulesets, and signature files that fit into:
- Signaling Firewalls (STPs & DRAs): Allowing immediate blocking of hostile interconnect transit lines.
- SOAR Playbooks: Enabling automated lookups and dynamic blocklist orchestration without requiring manual intervention for every alert.
Telecom Security Team Use Cases
By integrating a curated telecom threat feed, MNO security organizations unlock highly specialized telecom security team use cases:
- Anti-Smishing & IMSI Swap Verification: Detecting when an external SMS aggregator routes high volumes of smishing links, or checking for IMSI replacement queries preceding financial 2FA logins.
- Inter-Operator Signaling Audit: Discovering when a trusted roaming partner is generating excessive
ProvideSubscriberInfoqueries targeting high-profile subscribers, indicating targeted location tracking. - OpenRAN Interface Protection: Deploying signature rules to detect unauthorized O-Cloud virtualization modifications or massive MIMO configuration drifts on the RAN interfaces.
- Network Slicing Isolation Verification: Validating that resources assigned to private enterprise slices cannot be accessed or manipulated from public consumer network slices.
Operational Impact: Optimizing SOC Alert Prioritization
In a typical MNO environment, corporate IT servers generate millions of standard Windows, Linux, and web application logs daily. Standard SIEM deployments struggle to bubble up high-impact telecom attacks through this mountain of enterprise white noise.
Curated telecom threat intelligence resolves this operational bottleneck by providing the foundation for strict SOC alert prioritization:
By prioritizing alerts that correlate directly with verified curated threat directories, MNO SOC teams can immediately isolate compromised interconnect nodes and active cell-site exploits, ensuring that critical carrier resources remain protected 24/7.



