Telecom 2 min read

How to protect signaling protocols when migrating to 5G

An analysis of SS7 and Diameter vulnerabilities in hybrid networks, threats to 5G, and architectural solutions for protecting telecom infrastructure.

Deploying 5G Standalone (SA) architecture forces operators to maintain heterogeneous infrastructures where new solutions coexist with legacy protocols. This creates serious challenges, as legacy signaling vulnerabilities are carried over to new systems through backward compatibility mechanisms.

Vulnerabilities of legacy SS7 and Diameter protocols

The SS7 protocol, developed in the 1970s, lacks built-in authentication or encryption. The Diameter protocol for 4G/LTE, although using IPsec or TLS, inherited trust in messages from adjacent roaming partner networks. If an attacker gains access to the IPX, they can send requests directly to the network core.

According to the ENISA Threat Landscape 2025 report, exploitation of these protocols remains a critical risk: 53.7% of affected organizations are critical entities under the NIS2 directive. According to CFCA, global losses from telecom fraud reach $41.82 billion annually, a significant portion of which is directly related to signaling vulnerabilities.

Hybrid transit and threat vectors

Launching 5G does not automatically eliminate risks. In Non-Standalone (NSA) mode, control is handled via the 4G core and Diameter. The main threats arise from:

  • Downgrade attacks: forcing a device to switch to 3G/2G using an IMSI-catcher, which bypasses 5G security.
  • Cross-protocol transit: IWF gateways translate HTTP/2 messages to Diameter or MAP/SS7, allowing attackers to send malicious requests to the 5G core.

Practical threats include SMS interception to bypass two-factor authentication (2FA), DoS attacks via Diameter (subscriber de-registration), and subscription fraud.

Why it matters for the industry

The vulnerability of legacy protocols during the 5G transition directly threatens business continuity and user trust. Organizations face massive financial losses from telecom fraud and critical security breaches, such as the bypass of two-factor authentication (2FA) via SMS interception. Additionally, failure to secure these hybrid networks exposes critical entities to severe regulatory penalties under the NIS2 directive.

Action plan

To mitigate these risks and secure signaling networks, operators and enterprises must take the following practical steps:

  • Implement Signaling Firewalls: Deploy SS7/Diameter Firewalls to perform deep stateful inspection of sessions in accordance with GSMA recommendations.
  • Enforce 5G SA Security: Mandate the use of Security Edge Protection Proxy (SEPP) on the N32 interconnect interface for mutual authentication (mTLS) and encryption.
  • Modernize Core Infrastructure: Utilize secure platforms like UnityBase (Enterprise and Defence editions) to integrate microservices with legacy systems, ensuring row-level security (RLS), detailed audit logging, and NIS2 compliance.

Prepared by a Software Ukraine member. Original publication.

Sources & materials

Intecracy Group products and solutions referenced in this article.

  1. UnityBase — unitybase.info
  2. Megapolis.DocNet — inbase.com.ua
  3. А5 Персонал — inbase.com.ua
  4. AZIOT Platform — aziot.com.ua