Thank you for Subscribing to Telecom Business Review Weekly Brief
Telecom Business Review | Friday, March 04, 2022
The increasing volume of data transmissions, legacy technology, signaling protocols, the more significant role of cloud technologies, and “old-fashioned” DNS and DDoS attacks are among the most usual “bullets” telcos need to dodge daily.
FREMONT, CA: Communication networks need to be flexible. The scope, variety, and complexity of present cybersecurity threats are growing exponentially. The increasing volume of data transmissions, legacy technology, signaling protocols, the more significant role of cloud technologies, and “old-fashioned” DNS and DDoS attacks are among the most usual “bullets” telcos need to dodge daily.
The Primary Types of Cyber Threats and how to Mitigate Them
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
1.SS7 and Diameter Signalling Threats
Many core telecommunication services are backed by flawed protocols, particularly SS7 (Signalling System No. 7) or Diameter. SS7 protocol, especially, has become a major cyber threat to the banking industry since hackers can easily block 2FA authentication codes and drain users’ accounts.
Newer protocols like SIP (Session Initiation Protocol) can also be highly vulnerable to cyber threats without proper controls.
Still, implementing better signaling controls is proving to be a challenge for most telecoms due to the following:
• Overall complexity
• Privacy concerns
• Global title leasing
• Supply chain issues
• Network misconfigurations
•Traffic integrity
Cybersecurity Best Practices For SS7 and Diameter Protocols
• Comprehensive monitoring that involves all interconnect and outgoing traffic, as well as heart network elements.
• Harden network nodes by applying better firewall configuration rules.
• Lead regular external network protection assessments and penetration tests.
• Implement real-time irregularity detection systems to identify more sophisticated attacks and their prequels.
2. SIP Hacking
Session Initiation Protocol (SIP), used in most voice-over-IP (VoIP) communications, is another prime target for malicious parties. Without a proper telecom security system, hackers can smoothly tap into encrypter calls, circulate SIP malware and otherwise tamper with the VoIP services you are provisioning.
Here’s a list of cybersecurity threats:
• SIP trunk hacking
• SIP toll fraud
• Eavesdropping
• Caller ID spoofing
• DDoS attacks on PBX systems
Utility suppliers in the US encountered a series of VoIP attacks last year. An attacker initially targeted 1,500 unique gateways tied to 600 businesses but later focused on a single company and injected a malicious web shell into the company’s server outgoing directory using a command-injection technique over HTTP. Allowed, the hack was discovered in time before much harm had been done.
Best Practices for Protecting SIP Signalling
• Constrain strong encryption over your Transport Layer Security (TLS) and Real-Time Protocol (RTP) to protect all data transmissions.
• Implement anti-spoofing for SIP messages. Guarantee that you have correct in-built mechanisms for difficult messages and authenticating SIP clients.
• Keep strong Session Border Controller (SBC) controls that perform deep packet inspection of all SIP messages and prevent unauthorized SIP traffic.
3. DNS Attacks
DNS (Domain Name Security) attacks remain a major sore point for telcos. What’s terrible is that the cost of such attacks is growing yearly. As per the Global DNS Threat Report, about 79% of the organizations experienced DNS attacks in 2020. On average, the price of a security incident was 924,000 USD. Nevertheless, these stats are slightly better than a year before: the source’s report for 2019 denotes that 82% of companies experienced DNS attacks that amounted to 1.1 million USD on average.
Telecom and media became the most favored industries by attackers: averaging 11.4 attacks, with 8% incurring losses of more than 5 million USD per attack. This data tells us that most telecoms are utterly unprepared for the latest cyber threats from this group.
DNS Attack Prevention Best Practices
• Exchange from a reactive to a proactive approach to cybersecurity. Start applying adaptive countermeasures.
• Improve your firewalls with ML-driven response policies on traffic to suspicious hostnames.
• Implement query monitoring and logging for all doubtful endpoints. Implement real-time analytics for DNS transactions and slowly build up a behavioral threat detection suite capable of detecting known and emerging cyber threats and protecting against data theft/leaks.
More in News