Skip to content

Standard vs Telecom Flavor

Telovix ships two sensor flavors. The standard flavor covers Linux and Kubernetes runtime security. The telecom flavor builds on standard and adds protocol-aware monitoring for 5G Core and Open RAN workloads. Both use the same enrollment process, the same mTLS trust model, and the same heartbeat delivery path.

The flavor is embedded in the binary. You select it at install time, and it cannot be changed without reinstalling. Sensor identity (mTLS certificates, sensor ID, existing policy assignments) is preserved across a flavor change.


Choosing a flavor

ScenarioFlavor
Standard Linux servers, VMs, edge nodesstandard
Kubernetes worker nodes (no 5G workloads)standard
Kubernetes nodes running 5G Core NFs (AMF, SMF, UPF)telecom
O-RAN nodes (O-DU, O-CU-CP, O-CU-UP, gNB)telecom
Near-RT RICtelecom
Mixed node where you are unsuretelecom with observe-only pack

The telecom flavor adds work in proportion to the protocol traffic it observes. Measure Standard and Telecom on a representative canary before a broad rollout; workload traffic, enabled capture, protocol mix, and policies determine active resource use. See Requirements for deployment starting points.


Capability comparison

Core eBPF collection (both flavors)

CapabilityStandardTelecom
Process execution (kprobe sys_execve)YesYes
Process fork and exitYesYes
File open and write (kprobe openat, sys_write)YesYes
Privilege change (sys_setuid, sys_setgid)YesYes
Namespace creation (sys_clone with CLONE_NEW*)YesYes
Kernel module load (sys_init_module)YesYes
ptrace attachYesYes
Network connections (TCP outbound, inbound, listen)YesYes
DNS queries and resolution correlationYesYes
TCP flow tracking (duration, state, bytes)YesYes
BPF map access detectionYesYes
File Integrity Monitoring (SHA-256 baseline)YesYes
Process ancestor chain enrichmentYesYes
Kubernetes workload context (pod, namespace, workload)YesYes
Container image software inventory and vulnerability scanningYesYes
Behavioral anomaly scoring (per-binary baselines)YesYes
Kernel guard monitoringYesYes

Telecom-specific collection (telecom flavor only)

CapabilityProtocols / StandardsNotes
NF role detection5G SA, EPC, O-RANProtocol, process, workload, service, and configured identity evidence with confidence scoring
NG-RAN signalingNGAP, NRPPa, NAS 5GProcedure, outcome, positioning metadata, nested NAS security metadata, and decode status
E-UTRAN signalingS1AP, NAS EPSS1 procedure, session-relevant information elements, nested NAS EPS metadata, and decode status
PFCP session tracking3GPP TS 29.244, port 8805 UDPSession creation latency, session churn, SEID collision, dropped packets
GTP-U tunnel monitoring3GPP TS 29.281, port 2152 UDPTEID reuse, invalid TEID, encapsulation loop, payload size anomaly
GTP control and chargingGTPv2-C, GTPv1-C, GTP PrimeControl-session, PDP-context, and charging-transfer metadata where observed
F1AP monitoring3GPP TS 38.473, port 38472 SCTPDU registration, RRC context setup, setup failures
E1AP monitoring3GPP TS 38.463, port 38462 SCTPCU-UP registration, bearer setup latency
XnAP monitoring3GPP TS 38.423, SCTPInter-gNB handover, neighbor registration
E2 monitoringE2AP, E2SM-RC, E2SM-KPM, E2SM-CCCRIC procedures, targeted service-model container formats, and decode status
Fronthaul metadataeCPRIMessage type, size, series, sequence, event metadata, and decode status; IQ payload is not retained
O1 interface monitoringO-RAN Alliance, NETCONFManagement peers plus bounded RPC, reply, notification, operation, datastore, and error metadata
O2 interface monitoringO-RAN Alliance, REST/OpenAPIResource exhaustion, orphaned containers
xApp monitoringO-RAN WG3Rogue RIC peer detection, non-standard E2 port
SCTP association trackingRFC 9260Association churn, chunk loss rate, RTT, abort reason codes
SIGTRAN and SS7 signalingM3UA, SCCP, TCAP, MAP, CAPTransport lifecycle, routing, transaction, application-context, and supported operation metadata
Diameter peer monitoringRFC 6733, 3GPP TS 29.230, port 3868CER failure, auth success rate, accounting data loss
RADIUS monitoringRFC 2865/2866, ports 1812/1813 UDPAccess-reject rate spikes, accounting data loss
SIP session monitoringRFC 3261, port 5060 UDP/TCPInvitation rejection rate, session count anomaly
SBI / HTTP2 monitoring3GPP TS 29.501, port 7777 / 29500-29599NF-to-NF API calls, unexpected service call matrix
Media metadataRTP, RTCPHeader, endpoint, stream, sequence, timing, and decode metadata; media payload is not retained
Gateway controlH.248, MGCPTransaction, command, endpoint, response, and decode metadata
Interworking and locationSGsAP, LCS-APMessage or procedure, association, endpoint, and decode metadata
IKEv2RFC 7296IPsec tunnel setup monitoring
TLS uprobe (OpenSSL, GnuTLS, Go TLS, BoringSSL)3GPP TS 29.501 mTLS requirementsSBI plaintext detection, TLS posture per NF
NF SLO monitoring3GPP TS 22.261Per-role availability targets (5-nines for AMF/UPF/SMF)
NF privilege escalation detectionUnexpected setuid to root or cross-NF boundary
Rogue process detectionNF spawning unexpected child binaries
Configuration drift detectionNF config file changes outside maintenance windows
Timing analysisNF response latency distribution per interface
Visibility gap detectionAF_XDP, VFIO, DPDK bypass detection on GTP-U port
Telecom anomaly scoringProtocol violations, SLO breaches, integrity issues combined into risk score (0-100)

Console UI differences

The Telovix Console vertical (selected during initial setup) must match the sensor flavor in use. A standard Console with telecom sensors will store telecom heartbeat data in the database but will not surface it in the UI.

Console sectionstandard verticaltelecom vertical
Telco navigation sectionHiddenVisible
5G Core NF inventory viewNot shownActive
NGAP KPI chartsNot shownActive
O-RAN interface statusNot shownActive
SLO dashboardNot shownActive
Supported telecom protocol analytics and evidenceNot shownActive
Telecom compliance frameworks (3GPP TS 33.117, O-RAN WG11)Not shownAvailable in reports
AI assistant telecom contextNot availableTelecom inventory, signaling, O-RAN, and SLO context

NF role detection

The Telecom Sensor combines several observed signals when identifying a network-function role:

  1. protocol and service-port activity;
  2. process and executable identity;
  3. container image and Kubernetes workload identity;
  4. SBI, SCTP, PFCP, GTP, O-RAN, and configured service evidence.

Auto-detection uses a confidence score combining all signals. The Console can promote a generic_linux declared role to telecom_core or telecom_ran based on detected evidence, but it never downgrades an already-set telecom role.

Roles detected:

CategoryRoles
5G CoreAMF, SMF, UPF, NRF, UDM, UDR, PCF, AUSF, NEF, CHF, BSF, NSSF, NWDAF, SMSF, SEPP, LMF, GMLC, AF
4G/EPCMME, SGW, PGW, HSS, PCRF
RANgNB (variants), eNB, E2Node, Near-RT RIC, xApp
InfrastructureOAM endpoint, PTP/SyncE node, Diameter node, RADIUS server, IMS node, SIGTRAN gateway

SLO monitoring

The Telecom Sensor reports network-function availability, interface latency, resource, timing, and protocol-health evidence to the SLO workspace. Configure targets that match the operator's service objectives and deployment role. Treat a short or incomplete observation window as partial evidence rather than a proven SLO breach.


Visibility gaps

If a GTP-U user plane uses a kernel-bypass mechanism such as AF_XDP, VFIO, SR-IOV, or DPDK, normal kernel packet observation may not see that traffic. Telovix reports detected capture gaps in the Console so operators can distinguish missing visibility from an absence of traffic.

Control-plane coverage must be evaluated separately. A kernel-bypass user plane does not by itself hide ordinary kernel-visible control-plane traffic, but closed appliances, unsupported encryption paths, separate namespaces, interfaces, or bypass paths can still limit observation.


Installing with the correct flavor

Sensors > Deploy generates the install command with the selected flavor, node role, node name, and enrollment token. Review the values before running the command on the target node.

Sensors > Deploy showing the sensor flavor selection for the install command.
Sensors > Deploy showing the sensor flavor selection for the install command. Click to enlarge

For Kubernetes, set flavor: telecom in the Helm values file. This deploys the registry.gitlab.com/telovix/sensor:<version>-telecom image tag instead of <version>.


Further reading

Released under the Telovix Commercial License.