Skip to content

Latest commit

 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation

Telecommunications & Network Protocol Security Guide: SS7, SIP & DPI Analysis (2026 Update)

Son Güncelleme / Last Updated: Ağustos 2026 / August 2026

🇹🇷 Türkçe içeriğe git | 🇬🇧 Jump to English content


🇹🇷 Türkçe

Kapsam: SS7 sinyalleşme protokolü, 4G/5G geçiş riski, SIP & VoLTE/VoNR güvenliği, STIR/SHAKEN doğrulama çerçevesi, DPI (Derin Paket İnceleme) donanım/yazılım mimarisi, TLS 1.3 / ECH şifreli trafik analizi ve savunma odaklı DPI değerlendirmesi.

📌 İçindekiler (TR)

  1. Giriş ve Genel Bakış
  2. Bölüm 1: SS7 & 4G/5G Sinyalleşme Güvenliği
  3. Bölüm 2: SIP & VoLTE / VoNR Güvenliği
  4. Bölüm 3: DPI & Savunma Odaklı Değerlendirme
  5. Güvenlik ve Sertleştirme Kontrol Listesi (Hardening Checklist)
  6. Kaynaklar ve Referanslar

1. Giriş ve Genel Bakış

Mobil telekomünikasyon ağları (2G/3G/4G/5G) ile veri iletim kanalları, küresel iletişimin ve kritik altyapıların omurgasını oluşturur. Bu rehber, üç temel teknolojik sütunu güncel güvenlik standartları ışığında incelemektedir:

  1. SS7 ve Mobil Sinyalleşme Güvenliği: Telekom operatörleri arasındaki güven varsayımına dayanan SS7 ağlarındaki zafiyetler ve 5G Service-Based Architecture (SBA) evrimi.
  2. SIP ve IP Ses-Görüntü İletişimi: VoLTE (Voice over LTE) ve 5G VoNR (Voice over New Radio) teknolojilerinin temelini oluşturan SIP protokolü, Kimlik Sahteciliği (Caller ID Spoofing) ve STIR/SHAKEN koruma mekanizmaları.
  3. DPI (Derin Paket İnceleme): Ağ trafiğini Katman 3'ten Katman 7'ye kadar inceleyen DPI donanım/yazılım mimarileri, TLS 1.3 / ECH şifreleme zorlukları ve savunma tarafının nasıl konumlanması gerektiği.

Bölüm 1: SS7 (Signaling System No. 7) & 4G/5G Sinyalleşme Güvenliği

1.1. SS7 Mimarisi ve Temel Protokol Katmanları

SS7, 1970'lerde telekom operatörlerinin birbiriyle arama yönlendirme, dolaşım (roaming) ve SMS iletimi amacıyla iletişim kurması için tasarlanmış bir sinyalleşme protokol kümesidir.

+-------------------------------------------------------+
| MAP (Mobile Application Part) / CAP (CAMEL App Part)  |  <-- Uygulama Katmanı
+-------------------------------------------------------+
| TCAP (Transaction Capabilities Application Part)      |  <-- İşlem Katmanı
+-------------------------------------------------------+
| SCCP (Signaling Connection Control Part)               |  <-- Adresleme / Yönlendirme
+-------------------------------------------------------+
| MTP3 / M3UA (SS7 Message Transfer Part 3 / IP Adapt)   |  <-- Taşıma Katmanı (SIGTRAN)
+-------------------------------------------------------+

1.2. Kritik Saldırı Vektörleri

SS7 protokolünde doğrulama (authentication) mekanizmasının bulunmaması nedeniyle, bir saldırgan IPX (IP Exchange) ağına erişim sağladığında aşağıdaki kritik saldırı sınıfları literatürde tanımlanmıştır:

  1. SMS Interception & 2FA Bypass:
    • MAP_SEND_ROUTING_INFO_FOR_SM (SRI-SM) ve MAP_UPDATE_LOCATION mesaj tiplerinin kötüye kullanımı, abone yönlendirme bilgisinin manipülasyonuna yol açabilir.
    • Bu sınıf saldırılar, bankacılık ve servis SMS tabanlı 2FA kodlarının ele geçirilmesiyle ilişkilendirilir.
  2. Konum Takibi (Location Tracking):
    • MAP_PROVIDE_SUBSCRIBER_INFO (PSI) veya MAP_ANY_TIME_INTERROGATION (ATI) sorgu tipleri, yetkisiz kullanıldığında Cell-ID/LAC bilgisinin sızmasına neden olabilir.
  3. Çağrı Yönlendirme ve Dinleme (Call Interception):
    • CAMEL (MAP_INITIAL_DP) parametrelerinin manipülasyonu, çağrı yönlendirme saldırılarının temelini oluşturur.

Bu bölüm, operatörlerin Signaling Firewall ve GSMA FS.11 / FS.19 gibi rehberler doğrultusunda hangi mesaj tiplerini filtrelemesi gerektiğini anlamak için savunma amaçlı bir referans niteliğindedir.

1.3. 4G Diameter & 5G Standalone (SA) HTTP/2 SBA Geçişi

  • 4G LTE (Diameter): SS7 yerini IP tabanlı Diameter protokolüne bırakmıştır. Ancak Diameter ağlarında da benzer güven ilişkisi açıkları bulunmakta, Location-Info-Request (LIR) gibi komutlar yetersiz filtreleme durumunda konum sızıntısına yol açabilmektedir.
  • 5G Standalone (HTTP/2 - SBA): 5G SA mimarisinde sinyalleşme tamamen HTTP/2 ve RESTful JSON API'ler üzerinden Service-Based Architecture (SBA) ile yürütülür.
  • 5G SEPP (Security Edge Protection Proxy): Operatörler arası 5G roaming trafiğinde mesajlar N32 arayüzü üzerinden PRF (Pseudorandom Function) ve TLS 1.3 şifrelemesi ile korunur; legacy SS7/Diameter mesajlarının içeriye sızmasını engeller.

1.4. Çapraz Protokol Saldırıları (SS7-to-Diameter Pivot)

4G/5G geçiş döneminde operatörler çift modlu (dual-stack) çalıştığı için, güvenlik açığı bulunan geçiş noktaları (interworking function) yeterince sıkılaştırılmadığında SS7 tarafından başlayan bir saldırının Diameter/5G tarafına sıçraması (pivot) riski oluşabilir. Bu nedenle GSMA'nın önerdiği Diameter Edge Agent (DEA) ve IPX güvenlik filtreleme kontrollerinin her iki protokolde de eş zamanlı uygulanması önerilir.


Bölüm 2: SIP (Session Initiation Protocol) & VoLTE / VoNR Güvenliği

2.1. SIP Mimarisi ve İletişim Akışı (RFC 3261)

SIP, IP ağları üzerinde sesli ve görüntülü oturumların kurulması, değiştirilmesi ve sonlandırılmasını yöneten uygulama katmanı protokolüdür.

Abonenin Cihazı (UAC)          SIP Proxy / Registrar          Hedef Cihaz (UAS)
        |                               |                              |
        |──── SIP INVITE ──────────────>|                              |
        |<─── 100 Trying ────────────────|                             |
        |                               |──── SIP INVITE ─────────────>|
        |                               |<─── 180 Ringing ─────────────|
        |<─── 180 Ringing ───────────────|                             |
        |                               |<─── 200 OK ───────────────────|
        |<─── 200 OK ─────────────────────|                            |
        |──── SIP ACK ────────────────────────────────────────────────>|
        |                                                              |
        |======== RTP Ses Akışı (SRTP / UDP Doğrudan Medya Akışı) =====|

2.2. SIP Saldırı Yüzeyleri

  1. Digest Authentication Cracking: SIP REGISTER/INVITE isteklerinde gönderilen zayıf MD5-digest yanıtlarının offline kırma araçlarına karşı savunmasızlığı — bu nedenle SIPS/TLS ve güçlü parola politikaları önerilir.
  2. SIP Session Hijacking: Şifrelenmemiş SIP oturumlarında Call-ID, From-tag ve To-tag değerlerinin araya girme (MitM) saldırılarına açık olması.
  3. VoIP Toll Fraud (Ücretli Hat Dolandırıcılığı): Zayıf kimlik doğrulamalı SIP hesaplarının, yüksek ücretli hatlara yönelik yetkisiz aramalar için istismar edilme riski.
  4. SIP INVITE Flooding (DDoS): Yüksek hacimli sahte INVITE trafiğinin Kamailio/OpenSIPS veya PBX sunucularının kaynaklarını tüketmesi.

Bu maddeler, SIP altyapılarının rate-limiting, fail2ban, TLS zorunluluğu ve anomali tespiti gibi savunma katmanlarıyla nasıl sertleştirilmesi gerektiğini planlamak amacıyla listelenmiştir.

2.3. Caller ID Spoofing ve STIR/SHAKEN Doğrulama Çerçevesi (2026 Standartları)

Gelen arayan numara bilgisinin sahtelenmesini (Caller ID Spoofing) önlemek için telekom sektöründe STIR/SHAKEN mimarisi standart hale gelmiştir:

  • STIR (Secure Telephone Identity Revisited): SIP INVITE başlığına dijital imza ekleyen IETF standardı (Identity header).
  • SHAKEN (Signature-based Handling of Asserted information using toKENs): Operatörlerin arama yetkisini doğrulamak için sunduğu 3 seviyeli imza derecesi:
    • Full Attestation (A): Operatör müşteriyi ve numara kullanım yetkisini tam olarak tanıyor.
    • Partial Attestation (B): Müşteri tanınıyor ancak numara yetkisi doğrulanmamış.
    • Gateway Attestation (C): Arama uluslararası/harici bir gateway'den giriyor, kaynak doğrulanamıyor.

2.4. Güvenli VoIP Şifreleme Standartları

  • SIPS (SIP over TLS 1.3): SIP sinyalleşme paketlerinin TLS 1.3 ile uçtan uca şifrelenmesi (TCP Port 5061).
  • SRTP (Secure Real-time Transport Protocol): Ses ve görüntü medya paketlerinin AES-GCM şifreleme algoritması ile korunması.
  • ZRTP / DTLS-SRTP: WebRTC ve VoNR iletişiminde Diffie-Hellman anahtar değişimi ile ortam dinlemesinin (eavesdropping) engellenmesi.

Bölüm 3: DPI (Deep Packet Inspection / Derin Paket İnceleme) & Savunma Odaklı Değerlendirme

3.1. DPI Mimari Yapısı ve Algoritmik Temeller

DPI sistemleri, geleneksel güvenlik duvarlarının aksine paketlerin sadece IP/TCP başlıklarını değil, Katman 7 (Uygulama Katmanı) yükünü (payload) inceler.

[ Ağ Paketi ] ──► [ L3/L4 Parsing (IP/TCP) ] ──► [ L7 Protocol Classification ]
                                                              │
                                                              ▼
[ Engelle / Geçir ] ◄── [ Rule Policy Engine ] ◄── [ Pattern Matching Engine ]
                                                    (Wu-Manber / Aho-Corasick)
  • Aho-Corasick Algoritması: Çoklu sabit kelime/string aramalarında kullanılır (ör. HTTP Host: veya TLS SNI alanı taraması).
  • Wu-Manber Algoritması: Büyük desen kümelerinde yüksek hızlı paket tarama.

3.2. Donanım Hızlandırma Teknolojileri

  1. FPGA & ASIC: Hat hızında (100Gbps+) donanımsal paralel paket işleme.
  2. SmartNICs & Linux eBPF/XDP (eXtended Data Path): Paketleri Linux çekirdeğine (kernel space) ulaşmadan doğrudan ağ kartı sürücüsü seviyesinde işleyerek mikrosaniyelik DPI kararları alma.

3.3. Şifreli Trafik Çağında DPI Zorlukları (TLS 1.3 & ECH / RFC 9849)

  • Geleneksel TLS İnceleme: DPI sistemleri, TLS el sıkışmasındaki (handshake) açık metin Server Name Indication (SNI) alanını okuyarak trafik sınıflandırması yapar.
  • Encrypted Client Hello (ECH / RFC 9849): TLS 1.3 eklentisi olan ECH, ClientHello paketi içerisindeki SNI alanını DoH (DNS-over-HTTPS) üzerinden alınan bir genel anahtarla şifreler (Outer ClientHello ve Inner ClientHello). Bu, orta-adam konumundaki gözlemcilerin hedef alan adını doğrudan okumasını engeller.
  • QUIC / HTTP/3: UDP tabanlı şifreli taşıma protokolü sayesinde bağlantı meta verilerinin büyük bölümü şifrelenir; klasik imza tabanlı DPI yaklaşımlarının etkinliği azalır.

Bu bölüm, ağ operatörlerinin ve güvenlik ekiplerinin şifreli trafik oranı arttıkça trafik sınıflandırma stratejilerini nasıl güncellemesi gerektiğini (ör. davranışsal/istatistiksel analiz, ML tabanlı sınıflandırma) planlaması için genel bir çerçeve sunar.

3.4. DPI Evasion Konusunda Genel Değerlendirme

Literatürde TCP/TLS parçalama (fragmentation), TTL manipülasyonu ve paket sıralama oyunları gibi teknikler DPI atlatma yöntemleri olarak tartışılmaktadır. Bu rehber kapsamında, bu tekniklerin adım adım uygulama detaylarını vermek yerine, savunma tarafının bu tür teknikleri nasıl tespit edip engelleyebileceğine odaklanılması önerilir:

  • Tam TCP/TLS Reassembly: DPI cihazlarının parçalanmış (fragmented) segmentleri güvenilir şekilde yeniden birleştirmesi, parçalama tabanlı atlatmaları büyük ölçüde etkisiz kılar.
  • TTL Tutarlılık Kontrolü: Beklenmeyen TTL sıçramaları veya aynı akışta tutarsız TTL değerleri anomali olarak işaretlenip incelenmelidir.
  • Sıra Dışı (Out-of-Order) Segment İzleme: Anormal segment sıralaması veya tekrar eden ACK/SEQ desenleri, IDS/IPS kurallarında ayrı bir tespit sınıfı olarak tanımlanmalıdır.

Bu maddelerin amacı, saldırı tekniklerinin uygulanabilir bir kılavuzunu sunmak değil, savunma ekiplerinin hangi tespit mekanizmalarına yatırım yapması gerektiğini göstermektir.


Güvenlik ve Sertleştirme Kontrol Listesi (Hardening Checklist)

  • Signaling Firewall: SS7/Diameter ağ girişlerinde Category 1, 2 ve 3 mesaj filtreleme kurallarının uygulanması.
  • 5G SEPP Entegrasyonu: Operatörler arası 5G roaming trafiğinde N32 arayüzünde TLS 1.3 ve PRF şifrelemesi.
  • STIR/SHAKEN: VoLTE/VoNR şebekelerinde A-seviyesi imzalama ile Caller ID Spoofing engelleme.
  • SRTP & SIPS: Tüm VoIP/SIP sunucularında TLS 1.3 ve SRTP zorunluluğu.
  • eBPF/XDP Tabanlı Güvenlik: Ağ kenarlarında eBPF/XDP ile yüksek performanslı zararlı trafik engelleme.
  • ECH & DoH Desteği: İstemci tarafında ECH ve DNS-over-HTTPS aktif edilerek gizliliğin korunması.
  • Tam TCP/TLS Reassembly: DPI/IDS cihazlarında parçalama tabanlı atlatma girişimlerine karşı reassembly kontrolü.
  • TTL & Sıra Anomali Tespiti: Ağ izleme sistemlerinde TTL ve segment sırası anomali kurallarının etkinleştirilmesi.

📄 Kaynaklar ve Referanslar

⬆ Başa dön / Back to top | 🇬🇧 Jump to English content



🇬🇧 English

Scope: SS7 signaling protocol, 4G/5G transition risk, SIP & VoLTE/VoNR security, the STIR/SHAKEN verification framework, DPI (Deep Packet Inspection) hardware/software architecture, TLS 1.3 / ECH encrypted traffic analysis, and a defense-focused DPI assessment.

🇹🇷 Türkçe içeriğe git / Jump to Turkish content

📌 Table of Contents (EN)

  1. Introduction and Overview
  2. Part 1: SS7 & 4G/5G Signaling Security
  3. Part 2: SIP & VoLTE / VoNR Security
  4. Part 3: DPI & Defense-Focused Assessment
  5. Security & Hardening Checklist
  6. Sources and References

1. Introduction and Overview

Mobile telecommunications networks (2G/3G/4G/5G) and their data channels form the backbone of global communication and critical infrastructure. This guide examines three core technology pillars in light of current security standards:

  1. SS7 and Mobile Signaling Security: Vulnerabilities in SS7 networks, which rely on an inter-operator trust assumption, and the evolution toward the 5G Service-Based Architecture (SBA).
  2. SIP and IP Voice/Video Communication: The SIP protocol that underlies VoLTE (Voice over LTE) and 5G VoNR (Voice over New Radio), Caller ID Spoofing, and STIR/SHAKEN protection mechanisms.
  3. DPI (Deep Packet Inspection): DPI hardware/software architectures that inspect network traffic from Layer 3 through Layer 7, TLS 1.3 / ECH encryption challenges, and how defenders should position themselves.

Part 1: SS7 (Signaling System No. 7) & 4G/5G Signaling Security

1.1. SS7 Architecture and Core Protocol Layers

SS7 is a suite of signaling protocols designed in the 1970s to let telecom operators communicate with one another for call routing, roaming, and SMS delivery.

+-------------------------------------------------------+
| MAP (Mobile Application Part) / CAP (CAMEL App Part)  |  <-- Application Layer
+-------------------------------------------------------+
| TCAP (Transaction Capabilities Application Part)      |  <-- Transaction Layer
+-------------------------------------------------------+
| SCCP (Signaling Connection Control Part)               |  <-- Addressing / Routing
+-------------------------------------------------------+
| MTP3 / M3UA (SS7 Message Transfer Part 3 / IP Adapt)   |  <-- Transport Layer (SIGTRAN)
+-------------------------------------------------------+

1.2. Critical Attack Vectors

Because the SS7 protocol lacks an authentication mechanism, once an attacker gains access to the IPX (IP Exchange) network, the following attack classes are documented in the literature:

  1. SMS Interception & 2FA Bypass:
    • Misuse of the MAP_SEND_ROUTING_INFO_FOR_SM (SRI-SM) and MAP_UPDATE_LOCATION message types can lead to manipulation of subscriber routing information.
    • This class of attack is associated with the interception of bank- and service-issued SMS-based 2FA codes.
  2. Location Tracking:
    • The MAP_PROVIDE_SUBSCRIBER_INFO (PSI) and MAP_ANY_TIME_INTERROGATION (ATI) query types can leak Cell-ID/LAC data when used without authorization.
  3. Call Forwarding and Interception:
    • Manipulation of CAMEL (MAP_INITIAL_DP) parameters is the basis for call-redirection attacks.

This section is intended as a defensive reference to help operators understand which message types to filter, in line with guidance such as Signaling Firewalls and GSMA FS.11 / FS.19.

1.3. 4G Diameter & 5G Standalone (SA) HTTP/2 SBA Transition

  • 4G LTE (Diameter): SS7 has been superseded by the IP-based Diameter protocol. However, Diameter networks share a similar trust-relationship weakness — commands such as Location-Info-Request (LIR) can lead to location leakage under insufficient filtering.
  • 5G Standalone (HTTP/2 - SBA): In 5G SA architecture, signaling runs entirely over HTTP/2 and RESTful JSON APIs via the Service-Based Architecture (SBA).
  • 5G SEPP (Security Edge Protection Proxy): In inter-operator 5G roaming traffic, messages are protected over the N32 interface using a Pseudorandom Function (PRF) and TLS 1.3 encryption, preventing legacy SS7/Diameter messages from leaking in.

1.4. Cross-Protocol Attacks (SS7-to-Diameter Pivot)

Because operators run dual-stack during the 4G/5G transition period, if the interworking functions between the two are not sufficiently hardened, an attack that starts on the SS7 side can risk pivoting into the Diameter/5G side. For this reason, applying GSMA-recommended Diameter Edge Agent (DEA) and IPX security filtering controls simultaneously across both protocols is advised.


Part 2: SIP (Session Initiation Protocol) & VoLTE / VoNR Security

2.1. SIP Architecture and Message Flow (RFC 3261)

SIP is the application-layer protocol that governs the setup, modification, and termination of voice and video sessions over IP networks.

Subscriber Device (UAC)        SIP Proxy / Registrar          Target Device (UAS)
        |                               |                              |
        |──── SIP INVITE ──────────────>|                              |
        |<─── 100 Trying ────────────────|                             |
        |                               |──── SIP INVITE ─────────────>|
        |                               |<─── 180 Ringing ─────────────|
        |<─── 180 Ringing ───────────────|                             |
        |                               |<─── 200 OK ───────────────────|
        |<─── 200 OK ─────────────────────|                            |
        |──── SIP ACK ────────────────────────────────────────────────>|
        |                                                              |
        |======== RTP Media Stream (SRTP / Direct UDP Media Flow) =====|

2.2. SIP Attack Surfaces

  1. Digest Authentication Cracking: Weak MD5-digest responses sent in SIP REGISTER/INVITE requests are vulnerable to offline cracking tools — which is why SIPS/TLS and strong password policies are recommended.
  2. SIP Session Hijacking: In unencrypted SIP sessions, the Call-ID, From-tag, and To-tag values are exposed to man-in-the-middle (MitM) interception.
  3. VoIP Toll Fraud: Weakly authenticated SIP accounts can be abused for unauthorized calls to premium-rate destinations.
  4. SIP INVITE Flooding (DDoS): High-volume forged INVITE traffic can exhaust the resources of Kamailio/OpenSIPS or PBX servers.

These items are listed to help plan how SIP infrastructure should be hardened with defensive layers such as rate-limiting, fail2ban, mandatory TLS, and anomaly detection.

2.3. Caller ID Spoofing and the STIR/SHAKEN Verification Framework (2026 Standards)

To prevent Caller ID Spoofing of incoming caller information, the STIR/SHAKEN framework has become standard across the telecom industry:

  • STIR (Secure Telephone Identity Revisited): An IETF standard that adds a digital signature to the SIP INVITE header (the Identity header).
  • SHAKEN (Signature-based Handling of Asserted information using toKENs): A three-tier attestation scale operators use to verify calling authority:
    • Full Attestation (A): The operator fully recognizes the customer and their authorization to use the number.
    • Partial Attestation (B): The customer is recognized, but authorization for the number is not verified.
    • Gateway Attestation (C): The call enters via an international/external gateway and its origin cannot be verified.

2.4. Secure VoIP Encryption Standards

  • SIPS (SIP over TLS 1.3): End-to-end encryption of SIP signaling packets using TLS 1.3 (TCP port 5061).
  • SRTP (Secure Real-time Transport Protocol): Protection of voice and video media packets using AES-GCM encryption.
  • ZRTP / DTLS-SRTP: Prevents eavesdropping in WebRTC and VoNR communication via Diffie-Hellman key exchange.

Part 3: DPI (Deep Packet Inspection) & Defense-Focused Assessment

3.1. DPI Architecture and Algorithmic Foundations

Unlike traditional firewalls, DPI systems inspect not just IP/TCP headers but the Layer 7 (application-layer) payload.

[ Network Packet ] ──► [ L3/L4 Parsing (IP/TCP) ] ──► [ L7 Protocol Classification ]
                                                              │
                                                              ▼
[ Block / Allow ] ◄── [ Rule Policy Engine ] ◄── [ Pattern Matching Engine ]
                                                  (Wu-Manber / Aho-Corasick)
  • Aho-Corasick Algorithm: Used for multi-pattern fixed-string searches (e.g., scanning the HTTP Host: or TLS SNI field).
  • Wu-Manber Algorithm: High-speed packet scanning against large pattern sets.

3.2. Hardware Acceleration Technologies

  1. FPGA & ASIC: Line-rate (100Gbps+) hardware-parallel packet processing.
  2. SmartNICs & Linux eBPF/XDP (eXtended Data Path): Processing packets at the network-card driver level before they reach kernel space, enabling microsecond-scale DPI decisions.

3.3. DPI Challenges in the Encrypted-Traffic Era (TLS 1.3 & ECH / RFC 9849)

  • Traditional TLS Inspection: DPI systems classify traffic by reading the plaintext Server Name Indication (SNI) field during the TLS handshake.
  • Encrypted Client Hello (ECH / RFC 9849): A TLS 1.3 extension that encrypts the SNI field inside the ClientHello using a public key obtained via DoH (DNS-over-HTTPS) (the Outer ClientHello and Inner ClientHello). This prevents on-path observers from reading the destination hostname directly.
  • QUIC / HTTP/3: Because this UDP-based transport encrypts most connection metadata, classic signature-based DPI approaches lose much of their effectiveness.

This section provides a general framework for network operators and security teams on how to update traffic classification strategies (e.g., behavioral/statistical analysis, ML-based classification) as the share of encrypted traffic grows.

3.4. General Assessment of DPI Evasion

The literature discusses techniques such as TCP/TLS fragmentation, TTL manipulation, and packet-ordering tricks as DPI evasion methods. Rather than providing step-by-step implementation detail for these techniques, this guide focuses on how defenders can detect and block them:

  • Full TCP/TLS Reassembly: Reliable reassembly of fragmented segments by DPI devices largely neutralizes fragmentation-based evasion.
  • TTL Consistency Checks: Unexpected TTL jumps or inconsistent TTL values within the same flow should be flagged as anomalies and investigated.
  • Out-of-Order Segment Monitoring: Abnormal segment ordering or repeated ACK/SEQ patterns should be defined as a distinct detection class in IDS/IPS rule sets.

The purpose of these items is not to provide an actionable attack playbook, but to show which detection mechanisms defense teams should invest in.


Security & Hardening Checklist

  • Signaling Firewall: Apply Category 1, 2, and 3 message-filtering rules at SS7/Diameter network entry points.
  • 5G SEPP Integration: TLS 1.3 and PRF encryption on the N32 interface for inter-operator 5G roaming traffic.
  • STIR/SHAKEN: A-level attestation signing on VoLTE/VoNR networks to block Caller ID Spoofing.
  • SRTP & SIPS: Mandatory TLS 1.3 and SRTP on all VoIP/SIP servers.
  • eBPF/XDP-Based Security: High-performance malicious-traffic blocking at the network edge using eBPF/XDP.
  • ECH & DoH Support: Enable ECH and DNS-over-HTTPS on the client side to protect privacy.
  • Full TCP/TLS Reassembly: Reassembly checks on DPI/IDS devices against fragmentation-based evasion attempts.
  • TTL & Order Anomaly Detection: Enable TTL and segment-order anomaly rules in network monitoring systems.

📄 Sources and References

⬆ Back to top / Başa dön | 🇹🇷 Türkçe içeriğe git

About

Comprehensive defense guide on SS7, 4G/5G signaling, SIP/VoLTE/VoNR, STIR/SHAKEN, and DPI analysis in encrypted traffic (TLS 1.3 / ECH).

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors