Telecom 3 min read

New techniques for defending telecom networks from signaling fraud

An overview of key vulnerabilities in SS7, Diameter, and SIP signaling protocols, and architectural solutions to protect corporate telecom networks.

Global telecom fraud losses have reached an unprecedented $41.82 billion, driven by vulnerabilities in legacy signaling protocols like SS7 and Diameter. As digital infrastructure accounts for over a quarter of all data breaches, businesses and operators are forced to urgently modernize their network protection architectures to secure customer communications and prevent massive financial losses.

Vulnerabilities of legacy signaling protocols and business threats

Modern intelligent contact centers and AI-powered customer service systems often run on top of legacy signaling infrastructure. According to the CFCA Global Fraud Loss Survey 2025, global losses from telecom fraud reached $41.82 billion. Specifically, subscription fraud causes $5.31 billion in losses annually, while International Revenue Share Fraud (IRSF) accounts for $6.23 billion. The ENISA Threat Landscape 2025 report indicates that digital infrastructure accounted for about 27.7% of all recorded data breaches.

Anatomy of signaling threats

  • SS7: Due to the lack of mutual cryptographic authentication of nodes, attackers can intercept SMS messages, track geolocation, and redirect calls.
  • Diameter: In 4G/LTE networks, interconnects between operators are often misconfigured, allowing DoS attacks and retrieval of user profiles.
  • Unsecured SIP: In the absence of signaling encryption (SIPS) and media traffic encryption (SRTP), eavesdropping and caller ID spoofing are possible.

What is at stake for the industry

For businesses and contact centers, relying on unencrypted legacy protocols leads to direct financial damage through IRSF and subscription fraud. Moreover, security breaches in signaling networks compromise user data privacy, leading to severe regulatory penalties and a loss of customer trust in digital communication channels.

Architectural methods of telecom network protection

To combat Caller ID Spoofing, the STIR/SHAKEN suite of standards is being implemented. According to the IETF RFC 8224 standard, the originating operator adds a digital signature (PASSporT token) to the SIP INVITE message, which is verified by the receiving party using a public key. The transition to 5G Standalone (SA) architecture also improves security through the use of HTTP/2 and mandatory interface encryption via SEPP.

Specialized solutions are used for the practical protection of corporate communications and carrier transit. For example, the carrier-grade VoIP platform DooxSwitch by Intecracy Group provides SIP header control, unauthorized traffic blocking (IRSF protection), and internal telephony isolation. To build reliable administrative interfaces (OSS/BSS) and monitoring systems, the UnityBase low-code platform is used, which supports strict access control (RLS/ACL) and detailed user action auditing.

Security of modern telecommunication networks is not a matter of installing separate software, but the architectural resilience of the core. Only a combination of robust identification, secure routing, and strict access control will allow services to scale safely.

What to do next

  • Implement cryptographic verification: Deploy the STIR/SHAKEN framework to prevent Caller ID spoofing by digitally signing SIP INVITE messages.
  • Upgrade to modern standards: Transition to 5G Standalone architecture to leverage HTTP/2 and mandatory interface encryption via SEPP.
  • Deploy specialized security platforms: Use carrier-grade solutions like DooxSwitch for SIP header control and IRSF protection, and UnityBase for secure administrative interfaces with strict access control.

Prepared by a Software Ukraine member. Original publication.

Sources & materials

Intecracy Group products and solutions referenced in this article.

  1. UnityBase — unitybase.info
  2. Megapolis.DocNet — inbase.com.ua
  3. А5 Персонал — inbase.com.ua
  4. DooxSwitch — dooxswitch.com