Global telecom networks face critical security threats as vulnerabilities in legacy signaling protocols (SS7 and Diameter) are projected to cause $41.82 billion in fraud losses by 2025, forcing operators to urgently modernize their defense architectures.
Vulnerabilities of SS7 and Diameter signaling protocols
According to the CFCA report, global losses from telecom fraud are estimated at $41.82 billion in 2025. The main cause remains the exploitation of vulnerabilities in legacy signaling protocols used for roaming and routing.
The SS7 network was designed without sender authentication mechanisms, allowing attackers to send spoofed service messages. The Diameter protocol in 4G networks inherited this trust model. The ENISA report recorded 4,875 incidents in a year, confirming the critical nature of these risks. Key threats include SMS traffic interception to bypass two-factor authentication, geolocation tracking, and DoS attacks.
Financial losses from IRSF and Wangiri schemes
Technical network flaws translate into financial losses through fraudulent schemes:
- IRSF scheme: unauthorized traffic to premium-rate numbers. Losses from this scheme reached $6.23 billion in 2023. Subscription fraud is often used to facilitate this.
- Wangiri scheme: mass calling of users with immediate disconnection to trick them into calling back premium-rate numbers.
What it means for companies
For telecom operators and businesses, these vulnerabilities mean escalating financial losses from fraudulent traffic and premium-rate scams. For end-users, the flaws compromise personal security through intercepted two-factor authentication codes and unauthorized location tracking, ultimately damaging trust in mobile communications and forcing compliance with stricter regulations like NIS2.
Defense methods and hybrid architecture
The transition to 5G Standalone and the HTTP/2 protocol does not automatically solve the problem, as operators must maintain backward compatibility with 3G and 4G. Attackers can still send malicious requests through legacy networks.
The following tools are used for protection:
- Signaling Firewalls: analyze incoming traffic, block suspicious packets, and verify subscriber velocity (speed of movement).
- SIP Identity mechanisms (RFC 8224): STIR technology allows signing Caller ID with a cryptographic certificate to prevent caller ID spoofing.
Integrated security perimeter and technological solutions
Effective counteraction requires real-time monitoring. Various solutions are available on the market to modernize telecom infrastructure. In particular, the DooxSwitch VoIP platform combines switching, route optimization, and billing functions, enabling the detection of anomalous traffic spikes and the blocking of compromised channels.
To build related incident management systems and integration layers, the UnityBase low-code platform is used. Thanks to role-based access control and audit mechanisms, it allows building solutions that comply with ISO/IEC 27001 standards and NIS2 directive requirements.
What to do next
To protect networks and mitigate fraud, operators should take the following practical steps:
- Deploy Signaling Firewalls to analyze incoming traffic and verify subscriber velocity.
- Implement SIP Identity mechanisms (STIR technology) to cryptographically sign Caller IDs and prevent spoofing.
- Utilize integrated platforms like DooxSwitch for real-time monitoring, billing, and blocking anomalous traffic spikes.
- Build robust incident management systems using low-code solutions like UnityBase to ensure compliance with ISO/IEC 27001 and NIS2.
Prepared by a Software Ukraine member. Original publication.