geedge.lantern.io
detection confidence: high public

TSG maintains a dynamic runtime table (TSG_DYN_IPPORT_SUBSCRIBER_MAPPING) that correlates each network session's IP/port tuple with a subscriber's IMSI and phone number, loaded via incremental Redis-backed updates into the policy-matching engine — i.e. blocking/monitoring decisions can be attributed to a specific subscriber identity, not just an IP.

table[TSG_DYN_IPPORT_SUBSCRIBER_MAPPING] ... entries pair each flow's IP/port tuple with fields including imsi and phone_number, loaded incrementally via Redis into the policy runtime (7.9M+ entries observed in one deployment's table).

Defense implications

capabilitysubscriber-correlation

extracted_by: claude-sonnet-5 · added 2026-08-26 · id: 2026-ompub-1221-imsi-subscriber-session-correlation-table