q.3066

๐Ÿ“‹ Audit Checklist: itu-t Q.3066 (Signaling Firewall)

Field Security Audit // Node_Operational
Completion_Index0%

Section 1 โ€” Infrastructure and Connectivity

item_em-0

Physical / Logical Isolation: Signaling gateway / STP is isolated from the OAM/management plane (X.805 Management Plane separation)

item_em-1

SCTP/M3UA Access Control: ACLs on SCTP associations limit origination to known PLMN IP blocks; wildcard "any" associations are not in use

item_em-2

Signaling VLAN / Segment: SS7 and Diameter signaling is carried on dedicated VLANs or segments isolated from corporate/internet-accessible networks

item_em-3

Management Interface Security: STP/DEA management console requires MFA; no Telnet; SNMPv3 enforced; management access logged

2a โ€” SS7 MAP Category Filtering

item_em-4

Category 1 (Address Spoofing): Messages with source Global Title (GT) not in the allowed PLMN GT whitelist are blocked and logged

item_em-5

Category 2 (Internal-only operations): Messages that should only traverse home network internals (e.g., MAP UpdateLocation from foreign PLMNs targeting internal VLR) are blocked

item_em-6

Category 3 (Subscriber data manipulation): High-risk operations (MAP DeleteSubscriberData, MAP RegisterSS from external peers) are blocked

item_em-7

ATI (AnyTimeInterrogation) blocking: MAP ATI from external peers is rejected unless a bilateral roaming agreement with specific GT authorization is in place

item_em-8

SRI-SM filtering: MAP SendRoutingInfo for SM from unauthorized sources is blocked; logging is enabled and alerts are reviewed

2b โ€” Diameter (DEA) Filtering

item_em-9

Origin-Host / Origin-Realm validation: All Diameter messages from external peers are validated against a provisioned whitelist of authorized Origin-Host / Origin-Realm pairs

item_m-10

S6a ULR from unauthorized peers: Update-Location-Requests from unrecognized Diameter hosts are rejected with DIAMETER_UNABLE_TO_DELIVER

item_m-11

S6a SAR (Server Assignment): Unauthorized SAR messages from external DEAs are blocked to prevent subscriber profile manipulation

item_m-12

Diameter category filtering per Q.3066: Category 1/2/3 filtering equivalent is applied at the DEA level for the Diameter protocol

2c โ€” Signaling Authentication (Q.3062)

item_m-13

mTLS for Diameter peers: All external Diameter peers authenticate via mutual TLS (certificates); anonymous TLS connections are rejected

item_m-14

Q.3062 HMAC / token enforcement: Where supported, signaling messages include authentication tokens (HMAC-SHA or equivalent) that are verified before message processing

item_m-15

SEPP (N32) mTLS for 5G: All inter-PLMN 5G signaling transits the SEPP; N32 interface uses mutual TLS with operator-issued certificates

Section 3 โ€” Vulnerability Verification (Penetration Test Items)

item_m-16

SS7 ATI spoofing test: Send MAP AnyTimeInterrogation from a test peer with spoofed source GT โ†’ Expected: Blocked and logged by signaling firewall; no MSISDN/IMSI location returned

item_m-17

SS7 SRI-SM intercept test: Send MAP SRI-SM from unauthorized source GT โ†’ Expected: Rejected; no routing number returned to unauthorized peer

item_m-18

SS7 RegisterSS hijacking test: Send MAP RegisterSS (call forwarding) from external peer for a local subscriber โ†’ Expected: Rejected by Category 3 filter

item_m-19

Diameter ULR injection test: Send Update-Location-Request from an unauthorized Diameter host โ†’ Expected: DIAMETER_UNABLE_TO_DELIVER; no authentication vectors leaked

item_m-20

Replay protection test: Capture and replay a valid MAP UpdateLocation message โ†’ Expected: Detected and blocked (sequence number / timestamp validation)

item_m-21

Resource exhaustion test: Simulate signaling storm (SCTP flood) at 10ร— normal BHCR โ†’ Expected: CPU/Memory within acceptable bounds; critical services unaffected; alarm triggered

Section 4 โ€” 5G Signaling (Q.3057 / TS 33.501)

item_m-22

SEPP is deployed on all N32 interfaces: No direct HTTP/2 SBA API exposure to external PLMNs without SEPP mediation

item_m-23

N32 TLS version: TLS 1.3 with PFS cipher suites enforced on all SEPP N32 connections; TLS 1.2 only if TLS 1.3 is unavailable with agreed cipher suite

item_m-24

OAuth2 access tokens: All SBA API calls between internal NFs carry valid OAuth2 access tokens issued by the NRF

item_m-25

Token scope enforcement: NFs verify that received OAuth2 tokens have explicit scope for the requested operation (e.g., AMF โ†’ UDM: nudr-dr scope only)

item_m-26

NAS security: AMF enforces NIA0 (null integrity) prohibition; NAS integrity protection is mandatory for all UEs per TS 33.501 ยง6.7

Section 5 โ€” Compliance Evidence

item_m-27

Log retention: Signaling transaction logs (SS7, Diameter, SEPP N32) are retained for โ‰ฅ90 days in a tamper-proof, access-controlled log store

item_m-28

Alert integration: Signaling Firewall alerts are forwarded to the NOC/SOC SIEM; runbooks exist for SS7 ATI, SRI-SM, and ULR alert categories

item_m-29

Firewall ruleset versioning: Current signaling firewall ruleset is version-controlled in an SCM system; change approval process is documented

item_m-30

GSMA FS.11 / FS.19 compliance: Signaling firewall configuration is cross-referenced against GSMA FS.11 (SS7) and FS.19 (Diameter/GTP) baseline requirements

item_m-31

Incident response drills: SS7 signaling attack simulation has been conducted within the past 12 months; results documented and remediation tracked

Restricted Mission
You are in Read-Only mode. Sign in to save progress and synchronize audit results across your devices.
TELCOSEC INITIATIVEEST. 2026 // GLOBAL STANDARDS RESEARCH

Independent, non-affiliated security research project dedicated to hardening global telecommunications infrastructure through data-driven auditing.