Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • Securitygen highlights hidden threat to 5G networks from GTP-based cyber attacks

Security

Securitygen highlights hidden threat to 5G networks from GTP-based cyber attacks

Founded last year and based in London's Regent Street, Securitygen Ltd - a provider of security solutions and services for the telecom sector - has today highlighted the need for mobile operators to reassess security vulnerabilities in the key GTP (GPRS Tunnelling Protocol) protocol and bolster GTP security within their networks, as they continue to invest in and roll out 5G.

Image courtesy Securitygen

In its latest report - entitled 'GTP vulnerabilities: A cause for concern in 5G and LTE networks' - which is based on 150 telecom security assessments of 39 live mobile networks during 2022 and 2023, Securitygen has found that nearly 77% of networks had no cyber security measures in place against GTP-based attacks. Only 23% had a high level of cyber-security measures to keep successful GTP-based test attacks to a minimum.

Advertisement
ODU RT

Dmitry Kurbatov (above), co-founder and CTO of SecurityGen said: "Despite its widespread use, the GTP mobile network protocol is not entirely secure and opens up opportunities for attackers to intercept sensitive user data, engage in fraudulent activities, or disrupt network services.

 "As we explored and examined GTP's security vulnerabilities, it became apparent that the protocol requires in-depth consideration and robust mitigation strategies to block the potential threats – more so in the 5G set-up."

The study is based on the results of over 150 telecom security assessments by SecurityGen during the last 12 months involving 39 mobile operators in 24 countries across the SEA, LATAM, and MEA regions. It highlights the most critical GTP-related threats to raise awareness among mobile operators and stakeholders of the hidden vulnerabilities within the protocol.

The SecurityGen assessments found that all of the tested networks exhibited some vulnerabilities in their management of the GTP protocol:

  • In 71% of networks assessed, GTP-based test attacks on subscriber information disclosure were successful. Which can be used to impact subscribers, perform other attacks, target other interfaces, radio interfaces and OS and network vulnerabilities.
  • 62% of networks assessed were vulnerable to fraudulent activity involving the GTP protocol.
  • 85% of networks were susceptible to targeted attacks on subscribers aimed at impeding or completely interrupting the functionality of data transmission services.
  • 46% were vulnerable to network equipment denial-of-service attacks. Using this vulnerability, an attacker can simultaneously hinder network (Internet) connection for individual subscribers and many users via network equipment denial.

User traffic interception was successful in 69% of the networks tested. By exploiting this vulnerability, an attacker can direct all incoming traffic to their equipment by altering the nodes that process the user traffic.

Kurbatov said: "Throughout our assessments, we were surprised that not a single network was protected with a GTP firewall. Even when mobile operators claimed to have a GTP firewall deployed, we could carry out test attacks successfully, as there was no functional GTP firewall in place. This suggests that either the GTP firewall was not actively operational, or its filtering rules were not correctly configured or enabled.

"Some mobile operators employ IP address filtering from non-roaming partners to incoming traffic as a counter-measure – however, our simulated test attacks were still able to bypass this technique. The deployment of a fully functional GTP firewall could significantly improve these statistics and provide more robust protection against potential threats. Adopting advanced GTP firewall solutions undoubtedly enhances the overall security of mobile networks and protects them against multiple GTP attack vectors.

Advertisement
ODU RT

"The interconnected nature of 3G, 4G and now 5G mobile networks across different generations amplifies the risks posed by GTP security vulnerabilities. Our research highlighted a worrying lack of robust security measures across a significant proportion of the mobile networks we examined. Despite ongoing efforts by the GSMA and individual mobile operators since 2017, we found that comprehensive cyber-security measures are still not in place for the most part.

"The increasingly vital role of mobile technology in nearly every aspect of how we live and work means that operators must regard effective cyber-security measures and policies that protect their networks and mobile users as a commercial and operational priority. This includes a comprehensive GTP protection strategy encompassing deployment of functional GTP firewalls, the application of GSMA-recommended protections, the integration of intrusion detection systems, and the regular monitoring of all network communication interfaces.

"The findings of this study should serve as a wake-up call that spurs operators and the wider telecoms industry to take action necessary to secure our interconnected digital future."

The SecurityGen White Paper, 'GTP vulnerabilities: A cause for concern in 5G and LTE networks', is available to download here: https://secgen.com/SecurityGen-whitepaper-gtp-firewall.pdf

 

 


 

Advertisement
SPX Comms 2 SPX Comms 2
HMP Highpoint expanded to create UK

Security

HMP Highpoint expanded to create UK's largest public sector jail

10 March 2025

More dangerous criminals will be taken off the streets thanks to a 700-place expansion which will turn a Suffolk jail into the UK’s largest public sector prison.

AAUK relaunches APPGAA for Air Ambulances

Aerospace Security

AAUK relaunches APPGAA for Air Ambulances

7 March 2025

Air Ambulances UK (AAUK) has relaunched the All-Party Parliamentary Group on Air Ambulances (APPGAA), reaffirming its commitment to advocating for the lifesaving work of air ambulance charities across the UK.

Blighter hosting overseas delegations at Security & Policing

Security Events

Blighter hosting overseas delegations at Security & Policing

7 March 2025

Blighter will be hosting delegations from Estonia, Iraq, Latvia and Lithuania at this year’s Security & Policing (S&P) exhibition - the global security event organised by the UK Government - taking place at the Farnborough International Exhibition and Conference Centre, 11th to 13th March 2025.

Schiebel selected for UK police trials

Security

Schiebel selected for UK police trials

6 March 2025

The National Police Air Service (NPAS) has selected global manufacturer Schiebel to support its most ambitious trial so far of ‘Beyond the Visual Line of Sight’ (BVLOS) uncrewed aircraft operations.

Advertisement
ADS S&P RT
D-Fend Solutions opens London office

Security

D-Fend Solutions opens London office

6 March 2025

D-Fend Solutions today announced the expansion of its global operations with the launch of a new UK entity, D-Fend Solutions AD UK Ltd. and the opening of a new office in London.

SPX Communication Technologies showcasing capabilities at Security & Policing 2025

Defence Security Events

SPX Communication Technologies showcasing capabilities at Security & Policing 2025

6 March 2025

SPX Communication Technologies, formed by TCI and ECS, will be showcasing its Data Links, COMINT and Counter-UAS capabilities and solutions at this year's Home Office Security & Policing Global Security Event, being held at the Farnborough International Exhibition and Conference Centre, 11th-13th March 2025.

Advertisement
ODU RT