This page will soon be deactivated—explore our new, faster, mobile-friendly site, now centralized in MyWorkspace!

Connecting the world and beyond

  •  
Submarine cables

ITU-T Recommendations

Search by number:
Others:
Skip Navigation Links
Content search
Advanced search
Provisional name
Equivalent number
Formal description
Study Groups tree viewExpand Study Groups tree view

ITU-T Q.3066 (01/2026)

عربي | 中文 | English | Español | Français | Русский
Principles for detection and mitigation of signalling attacks in telecommunication networks
Recommendation ITU-T Q.3066 establishes a framework for enhancing the security of telecommunication networks against signalling-based attacks. It defines principles, detection methods, and mitigation strategies applicable to both legacy (e.g., SS7) and modern (e.g., Diameter, SIP, GTP) signalling protocols used across networks.
The Recommendation provides a structured threat model that classifies signalling attacks into four categories: simple single-request, single-protocol multi-request, multi-protocol, and cross-generational attacks. It identifies critical network assets at risk – such as subscriber location, international mobile subscriber identity (IMSI), international mobile equipment identity (IMEI) and call/session data – and specifies their exposure points within the network architecture.
Designed for network operators, equipment vendors and security solution providers, this Recommendation supports the implementation of robust, proactive defences at network interconnection points and internal trust boundaries. It is particularly useful for designing and operating signalling security gateways (SSGs), firewalls and OAM systems to improve network resilience and protect subscriber privacy.
NOTE – This Recommendation does not cover protection against non-signalling cyberattacks, end-to-end content encryption or cryptographic key management, which are addressed in other standards.
Citation: https://handle.itu.int/11.1002/1000/16683
Series title: Q series: Switching and signalling, and associated measurements and tests
  Q.3000-Q.3709: Signalling requirements and protocols for the NGN
  Q.3030-Q.3099: Network signalling and control functional architecture
Approval date: 2026-01-13
Provisional name:Q.DMSA
Approval process:AAP
Status: In force
Maintenance responsibility: ITU-T Study Group 11
Further details: Patent statement(s)
Development history
[13 related work items in progress]