Skip to main content
  • Mobile & telco

Telco Security

Interconnect, RAN, SIM, IMS and the core, across legacy networks, 5G, NFV and private cloud.

Why we test it this way

Operator networks differ enormously, so an industry benchmark tells you very little about yours. We measured live networks through gsmmap.org and scored each on interception, impersonation and tracking separately instead of as one composite, and none protected well in all three dimensions. The individual protections were rare: A5/3 encryption appeared in 5 of 107 networks, strict per-call authentication in 8, home routing in 12. We refreshed that infrastructure in 2023 but have published no new network-population figure since, so we test your network.

Each bar is the count of networks with that one protection, out of the 107 we measured. The three were counted separately, so the figure does not show how often they occur together.

5
8
12

107 live networks, measured through gsmmap.org

An operator has two perimeters: the internet-facing one, and the subscriber-facing one over LTE. Behind them sit the interfaces that carry the risk: SS7 and Diameter interconnect, SIM and binary SMS, RAN configuration over the air, IMS/RCS/VoLTE, and the core. Mobile networks have been our subject since 2010. A5/1 fell to rainbow tables: a 2TB table set recovers a call key from recorded traffic in seconds, about nine times in ten. SIM cards proved rootable over binary SMS, their 56-bit DES keys recovered in roughly two minutes. SIMtester and gsmmap went out publicly so operators could run the tests themselves. Those are the tests we bring to your interfaces.

What we found

Of 800 SIM cards collected over several years and tested with SIMtester, our own public tool, 9.4% carried the S@T applet and 10.7% the WIB applet, with 9.1% exploitable through one or the other. The WIB attack was a second bug class, previously unreported, and it surfaced while the first was being investigated. Eight SnoopSnitch users reported 29 real attack SMS going back to 2016.

New SIM attacks de-mystified, protection tools now available

Where engagements usually start

Three shapes these engagements take, scoped to the interfaces you run. Most operators start with the two perimeters and add interfaces from there.

Exposure scan

We find which telco systems are reachable from the internet and from a subscriber handset over LTE.

  • Both perimeters: internet (IP) and subscriber (IP over LTE)
  • Network segregation between them
  • Architecture review against what the segregation is supposed to achieve

Interconnect pentest

We test SS7 and Diameter for the remote attacks they still carry: fraud, tracking and interception.

  • SS7 and Diameter message-level testing
  • Interconnect firewall rule coverage against the attacks it claims to stop
  • Remote fraud, location tracking and interception paths

RAN, SIM and over-the-air

We collect your RAN configuration over the air and test the SIM and binary-SMS paths behind it.

  • RAN parameters collected over the air, compared to GSMA and 3GPP practice
  • SIM file-system permissions and applications
  • Whether binary SMS is correctly blocked
  • IMS, RCS and VoLTE configuration

Also available: telco platform pentesting against legacy, 5G, NFV and private-cloud nodes, with end-to-end attack testing per node.

How we work

We start from the outside and work inward, because that is the order an attacker has available: both perimeters first, then each internal interface behind them. A protection you believe is in place is not the same as the one running. Scoring 107 networks separately on interception, impersonation and tracking is what showed that, because the composite score every operator quotes hid it. Where we find a gap we say which of interception, impersonation or tracking it enables, and what it would cost to close, using the technology you already own before anything new.

Send us the problem

Tell us what you are building and what you need looked at. You will get an answer from the people who would run the engagement, and if another firm is the better fit for what you are asking, we will name one.

Get in touch

Security Research Labs is a member of the Allurity family. Learn more(opens in a new tab)