SMS Honeypot and Grey Route Detection
Our honeypot places controlled trap numbers in the SMS market and records exactly how messages reach them: which route, which originating network, which sender ID. It turns suspicion about grey routes into evidence.
What is an SMS honeypot?
An SMS honeypot is a set of controlled test numbers, also called trap numbers, on a mobile network, used to observe how SMS traffic reaches that network. Messages sent to the trap numbers are captured with their full delivery details, such as the originating SMSC, Global Title, sender ID and timing. Comparing that evidence with what each route claims to be reveals grey routes, SIM box termination and sender ID manipulation.
How trap numbers capture traffic
- Trap numbers are set up. Controlled numbers on the operator's network receive messages exactly like ordinary subscribers.
- Test traffic is sent through routes. Messages go through the commercial SMS routes being examined, as any sender would buy them.
- Every delivery is captured. For each message: the originating SMSC and Global Title, the sender ID as delivered, timestamps, and the route it was sent on.
- Evidence is compared. Delivery details are compared with what each route claims, and with the operator's agreements.
- Results feed action. Findings become SMS firewall rules, partner disputes and revenue claims.
What each captured message reveals
- Originating SMSC and Global Title
- Which network actually delivered the message, and whether it is a partner with an A2P agreement.
- Sender ID as delivered
- An alphanumeric sender ID replaced by a local mobile number usually means SIM box termination.
- Delivery path
- Messages that should arrive as A2P but arrive over a P2P interconnect expose a grey route.
- Timing
- Delays and bursts typical of SIM farms and blended routes.
- Delivery report honesty
- Whether the route's delivery report matches what actually reached the handset.
Continuous route monitoring
Grey routes change quickly: a path blocked today is replaced next week. The honeypot runs continuously, so operators see new routes as they appear rather than in a one-off audit.
Sender ID monitoring
Captured traffic shows which brand and bank sender IDs reach subscribers, and through which routes. This supports sender ID protection on the SMS firewall and helps identify phishing campaigns that impersonate trusted senders.
Turning evidence into firewall rules and disputes
Honeypot results are most useful when acted on. Confirmed grey sources become blocking rules on the SMS firewall. Partners whose interconnects deliver A2P traffic as P2P can be shown the captured messages. Revenue assurance teams use the same evidence to quantify losses; see SMS revenue assurance.
Honeypot vs active route testing
Route testing asks whether a specific route delivers well. A honeypot asks how traffic reaches a specific network. They use similar techniques but answer different questions; operators need the second. Our guide to SMS grey routes explains the detection methods side by side.
What a honeypot does not do
A honeypot does not inspect live subscriber traffic and does not block anything on its own. It shows the routes that deliver to its numbers, which is a sample, not the whole network. Used with an SMS firewall and regular audits, it closes the gaps each tool leaves on its own.
Frequently asked questions
How is a telecom honeypot different from a security honeypot in IT?
Both are decoys that attract activity so it can be observed. An IT honeypot imitates a vulnerable server. A telecom honeypot uses phone numbers that look like ordinary subscribers, so that messages and calls routed to them show how traffic actually travels.
Does the honeypot detect every bypass?
No. A honeypot sees the routes that deliver to its trap numbers. Bypass that targets other numbers, or that changes quickly, may not be captured. That is why honeypot evidence is combined with SMS firewall inspection of live traffic and with revenue assurance audits.
Is the traffic sent to trap numbers real?
Messages are sent through commercial SMS routes in the normal way, as any sender would. The difference is that we control the receiving numbers and capture every detail of delivery.
How is honeypot evidence used?
It supports SMS firewall rules, discussions with interconnect partners whose traffic arrives on grey paths, and revenue claims under A2P agreements. Each capture is stored with its route, timestamp and delivery details.
Related
See which routes reach your subscribers
Tell us your network, the problems you suspect and whether you already run an SMS firewall. We will propose a honeypot pilot.
- Email: sales@wisenetwork.co
- Phone: +961 3 085 999