Table of contents:
The prevalence of anti-steering behavior is rarely published as an industry-wide percentage, but operators can see it clearly in their own signalling data: affected destinations show up as abnormal volumes of “anti-steered” roamers, fake update-location patterns or repeated retention on non-preferred networks.
This matters because the impact scales quickly – even a small deviation from the target can result in high charges from the non-preferred network or difficulty in reaching yearly commitments with the preferred partner. Additionally, anti-steering impacts customer experience by creating difficulties with attaching to a network and getting a reliable service.
Read this blog to find out what the most common anti-steering mechanisms include and how telecom operators can protect their roaming services from suspicious behavior.
The most common anti-steering attacks
The most notable anti-steering techniques include the following attacks:
Multiplication of Location Update (LU) messages
Legacy steering of roaming (SoR) platforms use simple customer experience guardrails that are built based on the number of Location Update messages. On top of that, some tools attempt to detect manual network selection by a user through analysis of the pattern of LUs.
Both of these steering of roaming features can easily be exploited by multiplying real Location Update messages. During an actual network attach attempt, a visited public land mobile network (VPLMN) can copy and re-send real Location Update messages towards home PLMN (HPLMN). When a steering of roaming platform with these vulnerabilities intercepts them, it can be tricked into allowing the user to register to the network despite it being non-preferred.
Roaming Not Allowed (RNA) code swapping
Normally, user equipment (UE) should add a network to the forbidden PLMN (FPLMN) list on the SIM card upon receiving Roaming Not Allowed error code in the LU rejection. This stops the UE from any future registration attempts to this network (until it’s cleared from the list) and thus prevents the VPLMN from gaining this roamer.
To bypass this mechanism, a VPLMN can prevent the rejection from reaching the device. Since the UE expects some response, the cleanest execution of this attack is to swap the RNA code to a different one that will allow the device to try again. This alone will not result in an attach but it keeps other possibilities of gaining the user open for the VPLMN.
Kidnap retention
On the technical level, the kidnap retention is a whole category of different attacks. The most known attacks are the ones based on breaking new registration attempts by sending a fake Location Update and on preventing it from happening completely by artificially keeping packet-data sessions active.
On the business level, the goal is always the same – keeping a roamer attached despite the UE, the user or the HPLMN trying to select a new network.
To some extent, a gateway location register (GLR) serves a similar purpose. The key differentiator is in the industry’s definition of anti-steering, which relies on traffic generation or message manipulation. GLR does not fit that description as it limits the flow of inter-network traffic which, on its own, is beneficial.
How to detect and respond to anti-steering behavior
Detection of anti-steering is based on signalling monitoring. The first signals of suspicious behavior can include
- unexpected attach rates,
- low response to steering attempts
- and customers’ issues with service or network re-selection.
Final detection and confirmation of anti-steering attacks require in-depth analysis of the signalling patterns and how they vary from standard UE or network node behavior.
Steering of roaming platforms as well as intelligent signalling firewalls and monitoring solutions are best suited for automating this advanced analysis. In the past, detection was usually based on simple algorithms. These algorithms, although effective in general, were prone either to false positives or to missing a portion of the incidents – depending on how the thresholds were finetuned. The rise of machine learning provides an opportunity for more active detection policies that are able to adjust to various scenarios.
AI-driven traffic analytics offer more flexibility and accuracy than simple algorithms. This more effective anomaly detection helps telecom teams identify suspicious traffic patterns faster, enabling a swifter response to potential attacks.
Modern steering of roaming solutions are equipped with functionalities that support mobile operators in effectively addressing anti-steering attacks. The methods of preventing these frauds that you’ll choose will vary greatly depending on the type of attack, relationship with the VPLMN and approach to customer experience. Some of the attacks mentioned earlier can be managed fully autonomously by the SoR platform without the risk of a significant impact on the business or customer experience. Others require alerting and in-depth reporting functionalities that can be later used in mediation with the perpetrator or act as a basis for implementing a more aggressive steering/firewalling policy.
Ensuring high security of roaming services
As with any security attacks, the risk of anti-steering is an everyday reality for all operators offering roaming services. To avoid potential costs and impact on service quality that come with this malicious behavior, telcos need to implement advanced, proven methods of detecting and preventing anti-steering.
Fortunately, modern SoR platforms, such as Software Mind’s Amplitiv Steering of Roaming solutions, often incorporate anti-steering prevention functionalities to keep telco customers safe from these attacks. Detection powered by advanced AI algorithms and active prevention can help you identify and manage anti-steering, improving the security of your roaming services and roaming partnerships.
If you want to learn more about boosting your roaming solutions, get in touch with our team.
FAQ
What are some common anti-steering attacks?
Common anti-steering mechanisms include the multiplication of Location Update messages, RNA code swapping and kidnap retention.
What are the first signs of potential anti-steering behavior?
When you monitor signalling activity, anti-steering attacks can show up as unexpected attach rates, low response to steering attempts and customers’ issues with service or network re-selection.
How can operators prevent anti-steering behavior?
Mobile operators can use modern steering of roaming platforms that autonomously manage attacks. They can also use in-depth alerting and reporting to create stricter steering and firewalling policies.
About the authorJakub Aleksejczuk
Product Manager
A product manager with over 7 years of experience in the roaming services business, Jakub oversaw the development of the Amplitiv's SMS Welcome platform from scratch. Currently, he manages Amplitiv’s roaming portfolio of products and works closely with roaming managers during implementations. His technical background and cooperation with operators on a global scale enable Jakub to understand the dynamic nature of the roaming services sector.















