Generated by All in One SEO v4.9.5.1, this is an llms.txt file, used by LLMs to index the site. # The Telecom Defense Limited Company Keeping mobile networks safe ## Posts - [Blog](https://www.telecomdefense.com/blog/) - [SS7-based attacks still used to fraudulently deplete bank accounts](https://www.telecomdefense.com/2019/02/05/ss7-based-attacks-still-used-to-to-fraudulently-deplete-bank-accounts/) - We had previously discussed real-world for-profit SS7 attacks that successfully helped deplete consumer bank accounts in Germany in an article in early 2017. The SS7 part of the attack consists in intercepting 2FA tokens that are being sent by the bank to the customer's phone via SMS, so that these tokens can be used by - [Of the importance of ONT vulnerability testing](https://www.telecomdefense.com/2018/07/30/of-the-importance-of-ont-vulnerability-testing/) - Many operators who provide not only mobile but also fixed services to their subscribers are deploying FTTH (Fiber To The Home) services where the subscriber connects to the operator's fiber network using an operator provided ONT (Optical Network Terminal). From a logical point of view, the ONT is similar to a DSL modem connected to - [How "IT" vulnerabilities can contribute to SS7 vulnerability exposure](https://www.telecomdefense.com/2018/02/14/how-it-vulnerabilities-can-contribute-to-ss7-vulnerability-exposure/) - In a recent blog post, we explained how it wasn't sufficient to block SS7 attacks that allow attackers to obtain a subscriber's IMSI (GSMA Category 1 vulnerabilities) in order to keep a network secure from further SS7 attacks. This is because many other ways exist to obtain a subscriber's IMSI besides obtaining it via SS7. - [The Telecom Defense Limited Company launches SS7 Cloud Scanner](https://www.telecomdefense.com/2018/01/23/the-telecom-defense-limited-company-launches-ss7-cloud-scanner/) - The Telecom Defense Limited Company, a leading mobile network security consulting firm based in USA, launches the SS7 Cloud Scanner, a web-based SS7 penetration testing tool allowing mobile operators to easily test their SS7 defenses. When mobile operators worldwide assess their networks for SS7 vulnerabilities, remediation work usually begins swiftly, starting with simple filtering rules - [US Senate turning up the heat on US mobile operators to secure SS7 vulnerabilities](https://www.telecomdefense.com/2017/09/19/us-senate-turning-up-the-heat-on-us-mobile-operators-to-secure-ss7-vulnerabilities/) - As reported by the the Daily Beast, Senator Ron Wyden of Oregon sent letters to all 4 US mobile operators last week inquiring on the steps they have taken to secure their networks against SS7 based vulnerabilities. In the letter, Senator Wyden presents SS7 penetration testing as an effective way to learn the extent of - ["Security by obscurity" not viable when it comes to SS7 vulnerabilities](https://www.telecomdefense.com/2017/12/20/security-by-obscurity-not-viable-when-it-comes-to-ss7-vulnerabilities/) - As the awareness around SS7 vulnerabilities in mobile networks increases, thanks in good part to the work of the GSMA's Fraud and Security Group (FASG), we find in the last few SS7 vulnerability tests that we conducted, that more operators are blocking Category 1 SS7 vulnerabilities, while not blocking anything else. Category 1 vulnerabilities cover, - [Google pushing users away from insecure SMS two factor authentication](https://www.telecomdefense.com/2017/07/17/google-pushing-users-away-from-insecure-sms-two-factor-authentication/) - Google recognized some time ago that two factor authentication by SMS is insecure, due to the possibily of the SMS being intercepted, in particular using SS7-based attacks. Google had introduced an alternative 2FA system based on software built into its Android operating system (or via the Google Search app on IOS) some time ago. According - [SS7 access now sold to the public on Tor](https://www.telecomdefense.com/2017/06/14/ss7-access-now-sold-to-the-public-on-tor/) - According to a recent article from The Verge, services using SS7 vulnerabilities, as well as a full unlimited SS7 connection, are now available for sale to anyone on Tor, . While geolocation services have long been sold on a per query basis by companies like Verint or Circles, these companies were making a legitimate effort - [FCC releases long awaited CSRIC WG10 report on SS7 vulnerabilities](https://www.telecomdefense.com/2017/03/24/fcc-releases-long-awaited-csric-wg10-report-on-ss7-vulnerabilities/) - The report on vulnerabilities and risks inherent to the Signaling System #7 (SS7), which was ordered by the FCC from a specially formed group (CSRIC Working Group 10) thanks to the efforts, amongst other, of Congressman Ted Lieu, has finally been released. A copy of the report can be downloaded here. The working group aknowledges - [First reported for-profit SS7 attacks](https://www.telecomdefense.com/2017/05/04/first-reported-for-profit-ss7-attacks/) - Security experts agree that malicous attacks are more likely to be perpetrated when a potential financial gain exists for the attackers. This is why our remote SS7 vulnerability assessments and SS7 vulnerability trainings make a point to show operators the gain that attackers can derive from each attack vectors, including the possibility to steal SMS-based - [World-First SS7 Intelligence Report](https://www.telecomdefense.com/2017/03/14/world-first-ss7-intelligence-report/) - While 2016 has seen a lot of attention from telecom regulators on the subject of SS7-based vulnerabilities, and some mobile operators have begun securing their networks, the vast majority of worldwide mobile networks remain vulnerable to SS7-based attacks against their subscribers. Using the SS7 network, an attacker can accurately geo-locate mobile phone, intercept text messages, - [Forward Defense and The Telecom Defense Limited Company sign regional strategic partnership](https://www.telecomdefense.com/2017/01/26/forward-defense-and-the-telecom-defense-limited-company-sign-regional-strategic-partnership/) - 2016 has seen a lot of media attention towards SS7-based vulnerabilities that exist in worldwide mobile networks. These vulnerabilities allow attackers, including bad actors and foreign intelligence agencies, to accurately geo-locate nearly any mobile phone, intercept text messages, record phone conversations and much more. Pushed by regulators and public attention, mobile network operators in several - [World's first independent certification for SS7 firewalls](https://www.telecomdefense.com/2016/11/30/worlds-first-independent-certification-for-ss7-firewalls/) - 2016 has seen a lot of media attention towards SS7-based vulnerabilities that exist in worldwide mobile networks. These vulnerabilities allow attackers, including bad actors and foreign intelligence agencies, to accurately geo-locate nearly any mobile phone, intercept text messages, record phone conversations and much more. Pushed by regulators and public attention, most mobile network operators around - [Why a mobile network needs to be retested for SS7 vulnerabilities after installing an SS7 firewall](https://www.telecomdefense.com/2016/10/10/why-a-mobile-network-needs-to-be-retested-for-ss7-vulnerabilities-after-installing-an-ss7-firewall/) - The Telecom Defense Limited Company recently completed a SS7 vulnerability assessment for a mobile operator in Europe who had just deployed an SS7 firewall. The operator wanted to ensure, through an independent third party test, that the firewall is doing its job and that no vulnerabilities were left unprotected. While we found that the firewall - [Can an entire mobile network be taken down via SS7?](https://www.telecomdefense.com/2016/05/16/can-an-entire-mobile-network-be-taken-down-via-ss7/) - Recently I was asked if it was really possible to take an entire mobile network down simply by sending a few clever SS7 messages to it, and whether there was any documented occurrence of such an event. Long network wide "outages" do happen from time to time, for example in France in summer 2012, or in - [Listening to a Congressman's calls. Is it real?](https://www.telecomdefense.com/2016/04/23/listening-to-a-congressmans-calls-is-it-real/) - A recent episode of the American show 60 Minutes showed German hackers listening to calls of a US Congressman, from the other side of the world, using a vulnerability found in SS7. Are you wondering if this type of attack would be possible in your network? Chances are, yes it would be. In other words, if ## Pages - [Home](https://www.telecomdefense.com/) - The Telecom Defense Limited Company has one mission: keeping mobile networks worldwide safe from threats against privacy of subscribers, fraud and denial of service attacks that have emerged recently over signaling networks such as SS7 and Diameter. Our unique off-premises SS7, Diameter and GTP penetration tests and security audits can tell you quickly if your network is - [Defense against SMS blaster attacks](https://www.telecomdefense.com/defense-against-sms-blaster-attacks/) - A new type of attack that has plagued mobile network recently if the deployment of SMS blasters — rogue devices that mimic legitimate network infrastructure to deliver fraudulent or malicious SMS messages. These devices may appear to end users as legitimate eNodeBs, thereby exploiting trust in the network and damaging operator reputation. These threats can - [Fraud investigations](https://www.telecomdefense.com/fraud-investigations/) - We can assist operators with investigating complex fraud scenarios that are affecting their network, and developing sucessful countermeasures . For example network in emerging countries have been faced with data fraud, where users are able to consume data without charge by using advances curcumvention techniques. Key circumvention techniques include: DNS Tunneling: This is one of - [Anti CLI Spoofing Test](https://www.telecomdefense.com/cli-spoofing-test/) - In the realm of telecommunication, Caller Line Identification (CLI) has long been a critical feature, allowing recipients to see the number of the incoming caller. This capability is fundamental to various services, from personal call management to business operations, and is integral to the security and trustworthiness of telecommunication networks. However, as technology evolves, so - [On-premise SS7 Firewalls](https://www.telecomdefense.com/ss7-firewalls/) - Many operators are wondering if they should install an on-premises SS7 firewall to protect their network. Some have already done so, while others are in the process of conducting RFPs. So is it a good idea to install an SS7 firewall into your network? Absolutely, we think so! ... but, not all SS7 firewalls are created - [Signaling Penetration Tests](https://www.telecomdefense.com/signaling-penetration-tests/) - Our remote signaling penetration tests, using external roaming connectivity, are the most reliable way to test signaling-based vulnerabilities on your mobile network, using the same external attack surface as a foreign bad actor would use. These tests can be conducted before or after the installation of signaling firewall, or on a periodic basis. Learn more - [GTP penetration test](https://www.telecomdefense.com/gtp-penetration-test/) - The GTP protocol is used to transport subscribers’ mobile data traffic between network nodes (SGSNs and GGSNs or SGWs and PGWs), both when at home and while roaming. The architecture is very similar to that of SS7 and Diameter, in the sense that a private but shared network is used to transport packets between home - [IMS / VOLTE infrastructure penetration test](https://www.telecomdefense.com/ims-volte-infrastructure-penetration-test/) - In a VOLTE network, voice calls are transported as IP packets using the SIP protocol, instead of the traditional circuit switched way. New nodes are used in this process, such as the P-CSCF or the VOLTE-to-CS gateway, part of the IMS infrastructure. The MEs access these nodes through special data bearers, one used for signaling - [Hardware tests](https://www.telecomdefense.com/hardware-tests/) - Many operators provide DSL, fiber and TV services to their customers, which involves CPE with priviledged access into the operator's core network. Some operators also provide femtocells for use by their customers at home. These devices provide an additional attack surface and when compromised, provide various attack vectors into an operator's network. As modern CPE - [ONT hardware vulnerability assessment](https://www.telecomdefense.com/ont-hardware-vulnerability-assessment/) - More and more operators are deploying fiber to the customer’s premise, which allows them to offer their customers a combination of data, voice and content services in attractive bundles. These services typically rely on an Optical Network Terminal, or ONT, deployed at the customer’s premise. The ONT device often plays a role in securing access - [Signaling Intelligence](https://www.telecomdefense.com/ss7-intelligence/) - We provide various services to help you understand who is attacking your subscribers via SS7 and other signaling protocols, and for what purpose. Please see: Monthly SS7 intelligence report SS7 traffic audit SS7 forensics - [SS7 Penetration Test](https://www.telecomdefense.com/ss7-penetration-test/) - What is an SS7 penetration test? You might be familiar with IP based "pen testing", such as the tests performed on e-commerce websites in the USA to achieve PCI compliance as required by credit card companies. These tests are typically quick, inexpensive, and can be performed remotely over the Internet without physical presence or any physical - [SS7 Vulnerabilities](https://www.telecomdefense.com/ss7-vulnerabilities/) - (If you don't know what SS7 is, you may want to start here.) Although SS7 networks have been vulnerable since inception, the risk of SS7 based attacks on mobile networks have been gaining a lot of attention in the public media, both in the United States and overseas. The GSM Association's (GSMA) Fraud and Security - [Signaling Firewalls](https://www.telecomdefense.com/ss7-firewalls-2/) - Without a signaling firewall, your network is, by default, exposed to countless SS7 vulnerabilities and Diameter vulnerabilities. We can assist with the selection and deployment of the right signaling firewall solution. Learn more about: - On-premise SS7 firewalls - Cloud-based SS7 firewalls And if you have already deployed a signaling firewall, remember that not all firewalls are - [Contact Us](https://www.telecomdefense.com/contact-us/) - We are based in Las Vegas, USA, but perform off-premises SS7 penetration tests and SS7 security audits worldwide thanks to our partnership with multiple mobile operators that provide us with worldwide SS7 connectivity. Trainings are usually delivered onsite. Most SS7 penetration tests can be performed within a short time. For special on-premises projects such as traffic audits, our security - [SS7 Cloud Scanner](https://www.telecomdefense.com/ss7-cloud-scanner/) - The Telecom Defense Limited Company’s SS7 Cloud Scanner service is a web based SS7 penetration testing tool allowing properly trained operator and regulator staff to generate adhoc SS7 signaling messages towards a mobile network, in order to test defenses against common SS7-based threats. The solution includes access to a user interface (which can be accessed - [Diameter Penetration Test](https://www.telecomdefense.com/diameter-penetration-test/) - (If you don't know what Diameter is, you may want to start here.) What is a Diameter penetration test? You might be familiar with IP based "pen testing", such as the tests performed on e-commerce websites in the USA to achieve PCI compliance as required by credit card companies. These tests are typically quick, inexpensive, and can - [Malicious SS7 traffic audit](https://www.telecomdefense.com/ss7-traffic-audit/) - If your mobile network is not protected from SS7 signaling attacks and leaks, it is very likely that malicious SS7 traffic is running through your STPs in both directions. Besides SS7 attacks coming from outside bad actors, we have also discovered rogue mobile nodes from various vendors that generate malicious SS7 traffic targeting outside mobile - [SS7 intelligence report](https://www.telecomdefense.com/ss7-intelligence-report/) - Using anonymized SS7 data shared by our mobile operator partners around the world, we prepare a monthly SS7 intelligence report which helps you better understand who the bad actors are that are attacking your subscribers over SS7, and how the attackers and attacks evolve over time. The unique report, available monthly by annual subscription, includes: - [CDMA Penetration Test](https://www.telecomdefense.com/cdma-penetration-test/) - (If you don't know what CDMA is, you may want to start here.) Vulnerabilities for CDMA operators are very similar than those found on GSMA networks. CDMA signalling also use SS7, just a different flavor of it. Our CDMA penetration test is currently in R&D and we are looking for CDMA networks interested in this subject - [Training / Course](https://www.telecomdefense.com/training-course/) - We provide training / courses that covers various aspects of signaling-based telecom network security and fraud, for your security, engineering, fraud prevention and billing teams, as well as any managers interested in familiarizing themselves with the subjects. The courses contains many real life examples of security breaches and fraud cases and are very interactive. We - [Telecom Defense firewall certification](https://www.telecomdefense.com/telecom-defense-firewall-certification/) - As an operator who is looking to protect its network, how can you know if the firewall vendor selected during your RFP process will in fact defend your network from all the vulnerabilities that it claims to protect against, until the firewall is actually deployed and it is too late to go back to another - [SS7 Forensics](https://www.telecomdefense.com/ss7-forensics/) - Has your network been attacked or hacked via SS7? Or perhaps an attack is ongoing? We can help with a forensic analysis of SS7 traces (or setup traps, probes, decoys or honeypots to capture information on ongoing attacks and mislead attackers) to determine the target of the attack, the goal, and possibly shed some information - [Cloud-based SS7 firewalls](https://www.telecomdefense.com/cloud-based-ss7-firewalls/) - Several SCCP carriers are working on cloud-based SS7 firewall solutions which will be offered to their SCCP clients for and additional fee. We will provide additional information on these solutions as they become available on the market. While waiting for your SCCP carrier to offer a cloud-based SS7 firewall, why not consider an off-premises SS7 ## Categories - [Uncategorized](https://www.telecomdefense.com/category/uncategorized/)