Offerings

Matrix Shell offers a comprehensive range of telecom network security services, using a Modern approach to testing. We cover all aspects of telecom signalling, including SS7, Diameter, and GTP. We also assess the security of RAN, VoLTE, VoWIFI, 5G Core, and Radio networks

Matrix Shell Telco Security Wiz

Our SS7 Halconn helps telecom signalling & network security teams perform complete assessments of their SS7 networks. The tool supports the following protocols:

  • SCTP
  • TCAP
  • M3UA
  • SCCP
  • MAP
  • CAP

Our Diameter Halconn helps telecom Signalling and security teams perform complete assessments of their DiaMeter/LTE networks.  Diameter Halconn also follows the GSMA compliance guidelines, including:

  • FS 19: Diameter Interconnect Security.
  • FS 26: Guidelines for Independent Remote Interconnect Security Testing. 

The tool supports the following protocols

  • SCTP
  • Diameter Base
  • 3GPP Extensions (S6a/S6d,Sh,S6c…)

Our GTP Halconn helps telecom signalling and security teams perform complete assessments of their GRX networks. GTP Halconn also follows the GSMA compliance guidelines, including: 

  • FS 19: Diameter Interconnect Security.
  • FS 26: Guidelines for Independent Remote Interconnect Security Testing. 

The tool supports the following protocols: –

                    • GTP-C v0           • GTP-C v1 

                    • GTP-C v2           • GTP-U  

Aero Safe offers improved call quality and lower latency than traditional voice over IP (VoIP) networks. However, as with any new technology, there are also security risks associated with VoLTE.

Aero safe Covers the penetration testing, with scanning for different
signalling issues as follows:

• Incorrect Traffic Policies
• Private VPN using VoLTE/VoWiFi Bearer
• Lack of Transport Security Over VoLTE/VoWiFi
• ICMP tunneling/Private RTP Channel
• Caller ID spoofing.
• Lack of Data Rate Control for RTP
• Lack of rate limits on the signalling bearer
• Data Denial of Service


Aero Safe follows the FS 22 GSMA compliance. The results of a Aero Safe, can be used to improve the security of the VoLTE network. This can be done by patching known vulnerabilities, implementing additional security controls, and changing the vulnerable network architecture to reduce the risk of attack



Aero Safe follows the FS 22 GSMA compliance. results of a Aero Safe can be used to improve the security of the VoLTE Wi-Fi calling feature. This can be done by patching known vulnerabilities, implementing additional security controls, and changing the network architecture to reduce the risk of attack.

VoWiFi calling is a feature that allows users to make and receive calls over a Wi-Fi network. This feature is becoming increasingly popular, as it offers improved call quality and lower latency than
traditional cellular calls. However, as with any new technology, there are also security risks associated with VoLTE Wi-Fi calling. Aero Safe can help to identify and mitigate these risks.

Aero Safe, test the different signalling issues as follows:
             • Incorrect Traffic Policies
             • Private VPN using VoLTE/VoWiFi Bearer
             • Lack of Transport Security Over VoLTE/VoWiFi
             • ICMP tunneling/Private RTP Channel
             • Data Denial of Service
             • Network Discovery
             • Configuration weakness in Network
             • Leak of Information via SIP messages
             • Lack of encryption

In 2017, 2019, and 2022, attackers exploited vulnerabilities in SS7, Diameter, and GTP signaling protocols to launch DDoS, fraud, and eavesdropping attacks against telecom networks around the world. Firewalls can protect the operators from all these attacks. Signaling firewalls are a critical component of telecom network security, and their importance will only grow as telecom networks become more complex and interconnected

Benefits

  • Protect your network from attacks.
  • Improve network visibility.
  • Enforce security policies.
  • Segment networks:

FEATURES

Scalable Data Analytics Platform

Operator-wise and attack-wise reporting

Web-based Management User Interface

Traffic Screening Feature

Cloud-based container-based deployment

Load balanced mode

Attack prevention based on the GSMA category

COMPARISON

PRODUCT FEATURES

ADDITIONAL FEATURES

Multi tenant: You can create new operators, delete existing operators, and change the permissions of existing operators. This allows you to control who has access to the system and what they can do.
Create, delete, and manage the user access control: You can create new user roles, delete existing user roles, and change the permissions of existing user roles. This allows you to control what users can do in the system.
Allocate the number of tests and access duration for each operator: You can specify the number of tests that each operator can run and the duration of each test. This allows you to ensure that the system is not overloaded and that the operators have enough time to complete their tests.

See how Matrix-Shell can help to secure your network