diameter-security-audit

Audit Checklist: Diameter Signaling Security (GSMA FS.19)

Field Security Audit // Node_Operational
Completion_Index0%

I. Transport Layer Security

item_em-0

mTLS / TLS 1.2+: Are all Diameter connections between peers secured using mutual TLS (mTLS) with certificates signed by a trusted CA (e.g., GRU)?

item_em-1

IPsec Tunelling: Is IPsec (ESP) used for inter-operator transport when TLS is not supported?

item_em-2

SCTP Multi-homing: Are multi-homing configurations verified to ensure no unauthorized endpoints can join the association?

item_em-3

Node Isolation: Are signaling nodes (MME, HSS, PCRF) on isolated VLANs/subnets with no direct public access?

II. Edge Protection (DEA / Diameter Firewall)

item_em-4

Topology Hiding: Does the Diameter Edge Agent (DEA) hide internal node identities (FQDNs) in outgoing signaling messages?

item_em-5

AVP Filtering: Is there a blacklist/whitelist for unauthorized AVP (Attribute Value Pair) types at the network perimeter?

item_em-6

Rate Limiting: Are signaling messages (especially ULR, AIR, and CCR) rate-limited to prevent DoS attacks?

item_em-7

Unauthorized Origin: Does the firewall block signaling messages with origin-host/realm that do not match the peer's expected identity?

III. Messaging Security (FS.19 Filtering)

item_em-8

Category 1 (Protocol Validation): Are basic protocol validation checks enabled (message length, AVP format, mandatory AVPs)?

item_em-9

Category 2 (Anti-Spoofing): Are signaling messages with known invalid origin identities (e.g., non-roaming partner claim) blocked?

item_m-10

Category 3 (Session Validation): Is there correlation between signaling messages and active subscriber sessions to prevent rogue detached/profile updates?

item_m-11

Velocity Checks: Are subscribers flagged for impossible movement between VPLMN IDs in a short time frame?

IV. Monitoring & Incident Response

item_m-12

Signaling Logs: Are all failed Diameter authentication and location update attempts logged centrally (SIEM)?

item_m-13

Anomaly Detection: Is there an automated system to detect spikes in signaling traffic from specific roaming partners?

item_m-14

Incident Response: Is there a defined process for blacklisting a misbehaving roaming partner's Diameter identity?

Restricted Mission
You are in Read-Only mode. Sign in to save progress and synchronize audit results across your devices.
TELCOSEC INITIATIVEEST. 2026 // GLOBAL STANDARDS RESEARCH

Independent, non-affiliated security research project dedicated to hardening global telecommunications infrastructure through data-driven auditing.