Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - GTP And The Evolution Of Roaming
Articles

GTP And The Evolution Of Roaming

Anthony WebbBy Anthony WebbOctober 30, 2019Updated:December 30, 20217 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Mobile traffic using GPRS Tunnelling Protocol (GTP) has exploded over the last couple years, largely due to elimination of international roaming price barriers that previously discouraged subscribers from using the service. Global international roaming traffic – voice and data – is expected to grow 32X by 2022 and to reach over 1.5 Mb per subscriber annually.

How will GTP and roaming change with 5G and what will operators need to do to secure that traffic and their network? This post describes roaming and its use of GTP and discusses the evolution of GTP and roaming in 5G, rise of new threats and utilising a GTP firewall solution.

How will Roaming Evolve with 5G?

The 5G evolution will impact all aspects of “mobile roaming,” including the network requirements, the subscriber usage, and business models.

Roaming Network Requirements

The roaming network specifications were created to enable subscribers to move seamlessly between networks and to provide operators a mechanism to recoup costs from traffic generated by non-subscribers. In 4G networks, roaming partners are connected through the S8 interface using GTP.

According to 3GPP, a global initiative that unites telecommunications standard development organisations, in roaming architectures for 5G standalone networks, the GTP user plane is separated from the control plane. The user plane will still use GTP, but for the control plane, the home roaming partners are connected through a new function, the Security Protection Proxy (SEPP), using http/2 protocol. The embedded application layer encryption at the SEPP will provide additional protection against the known inter-exchange/roaming vulnerabilities that exist in SS7 and DIAMETER protocols, but an L7 firewall will still be required to protect the SEPP control plane. 5G will also add native support for a secure steering of roaming (SoR). The 5G SoR solution enables the home network operator to steer its customers while roaming to its preferred visited partner networks to enhance roaming customers’ experience, reduce roaming charges and preventing roaming fraud.

Subscriber Traffic and Usage

Over the next five years, mobile subscriptions will increase a modest 2 percent annually to 8.9 billion, according to Ericsson, but cellular IoT connections will quadruple to over 4 billion. Data traffic per smartphone will increase six-fold to 21 GB/month (Ericsson Mobility Report, November 2018). This includes all types of cellular devices – smartphones, IoT wearables, tablets and others – which will all roam with the subscriber.

5G is needed to carry the volume and diversity of this traffic, with seamless interconnection everywhere a vital part of every MNO value proposition.

The 2017 EU Roam Like at Home legislation now prohibits excessive roaming fees, and many other non-EU countries are following suit. With worldwide international tourist arrivals (overnight visitors) reaching a 1.4 billion in 2018, mobile operators have realized that their subscribers expect a seamless (and reasonably priced) experience – wherever they travel and whatever devices they use.

Roaming Business Model

Besides the technical interconnection requirements, roaming includes a contractual arrangement between operators who agree to carry traffic for each other’s subscribers through bi-lateral peering agreements or through agreements with GRX/IPX providers.

In roaming scenarios, generally, the subscriber is billed by his home network operator for roaming use and the visited network bills the home network operator for carrying the traffic – per the roaming agreement. If a GRX is used, then there is a settlements process. This type of interconnection model and the mobile charging models (originator or calling party pays) is very different than that adopted by the internet ecosystem. This model is based on bandwidth consumption and uses peering agreements where both origination and termination parties are charged.

There is debate in the mobile industry about the inefficiencies and complexity of the roaming model. Concerns with this model include the high cost of international calls where a home network effectively pays for termination into its own market and the administrative costs for volume forecasts and commitments, base rates, incremental rates and manual accounting that often lead to settlement disagreements. As mobile networks move closer to the all-IP internet model and operators compete with OTT and other service providers for subscribers and traffic, the roaming interconnection model as is can put mobile operators at a competitive disadvantage.

According to the GMSA (“Next-generation Interconnection and Roaming Analysis for Mobile Services”, July 2016), There could be an opportunity to shape a next-generation interconnection model in a less complex way and therefore reduce costs for implementation of charging. The next generation interconnection model could be made to be closer to the existing internet interconnection regimes (IP peering and transit), at least for any service beyond voice

Roaming Security

Roaming was originally designed based on a trust model. That is, it assumes that the operator has at least a moderate trust relationship with any roaming partner. Otherwise, why would they allow that operator’s subscribers to use the network? It was a reasonable assumption since originally, roaming traffic was not that high; the number of potential roaming partners was relatively small, and they were limited to like-minded mobile network operators. Although GTP used in roaming has known vulnerabilities, the authentication mechanisms of each roaming partner plus the roaming agreement were considered adequate by many operators to prevent unintentional or malicious peer activity. As such, many did not deploy a GTP firewall in their 4G implementations.

However, the mobile roaming ecosystem, traffic dynamics and threat landscape have dramatically changed over the last few years and will continue to change as 5G progresses. For 5G, as described earlier, the roaming interconnection model defined by 3GPP includes additional security measures, but GTP will continue to be used.

What is GTP?

GPRS Tunnelling Protocol (GTP) is an IP-based communications protocol, including control and data plane components, that is used to carry general packet radio service (GPRS) within GSM, UMTS (3G) and LTE (4G) networks as specified by 3GPP in various interface points. In LTE networks, these interfaces include roaming (S8), RAN-SGW (S1-U), and between core network elements SGW-PGW (S5), and MME-SGW (S11). GTP includes a user plane component (GTP-U) and a signalling or control plane component (GTP-C). GTP is used to establish a GTP tunnel, or channel between user equipment and mobile network nodes (serving gateways and packet gateways) in order to exchange user and control data.

Risks and Vulnerabilities of GTP

GTP is extremely useful in facilitating the transmission of mobile data traffic within and between mobile networks and it has been used in 2.5G, 3G and 4G networks. However, it was designed when mobile networks were considered unbreachable, and so it has no inherent security. GTP depends instead upon security provided through the authentication or authorization of the UE and subscriber from the home network operator. As a result, GTP has several security vulnerabilities that can be exploited by malicious actors or careless roaming partners.

Most operators have experienced the common GTP attacks. Attackers try to exploit vulnerabilities by abusing GTP interfaces exposed to the network. These attackers can include cybercriminals or malicious peers that have been able to control the GRX/IPX roaming links. These attacks target both mobile subscribers and mobile network infrastructure. Common GTP security issues include confidential data disclosures, denial of service, network overloads, and a range of fraud activities. And as traffic volume and usage has grown in 4G and soon in 5G, so do the risks.

In 5G, additional security measures have been added, but GTP will continue to play an important role, especially in roaming.

As operators move towards 5G, with likely a 4G common core for many years, the risks inherent in GTP continue to grow against a much larger volume of traffic and applications. Roaming traffic, with its high complexity and large number of interconnect partners and hubs, can be an especially vulnerable and attractive target for malicious actors.

A GTP firewall protects networks and subscribers against the GTP vulnerabilities identified by the GSMA. A highly scalable 5G solution is available in physical, virtual, and container forms and so assures operators that they can protect their networks and subscribers, and maintain the high performance demanded by subscribers throughout the entire 4G to 5G journey.

Anthony Webb

EMEA Vice President

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    Visual data is the blind spot in enterprise security: that’s about to change

    May 4, 20267 Mins Read

    Making stolen data worthless: why security must start with the data

    March 30, 20265 Mins Read

    Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

    March 10, 20264 Mins Read
    ISB-Bora-Side-Bar

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}