SS7 Penetration Testing
SS7 penetration testing is the practice of exercising the documented and undocumented attack classes against SS7 from a position equivalent to an attacker with interconnect access. The objective is not to confirm that "SS7 is insecure" — that is well-established — but to measure exactly what an attacker reaching the operator's STP can still achieve after the deployed SS7 firewall, home-routing logic and operator hardening. The test answers concrete questions: can subscriber location still be obtained, can IMSI be extracted from MSISDN, can SMS or voice be intercepted via call/SMS routing manipulation, can a subscriber be denied service, can fraud (USSD, supplementary services, billing bypass) be triggered.
The methodology follows the GSMA FS.11 category model. Category 1 cases (e.g. AnyTimeInterrogation, ProvideSubscriberInfo, SendIMSI) verify that messages which should never cross the perimeter are dropped. Category 2 cases exercise legitimate inter-operator messages from the wrong origin (e.g. UpdateLocation, CancelLocation, InsertSubscriberData from a network where the subscriber is not roaming) to confirm the firewall correlates with VLR state. Category 3 cases (e.g. SendRoutingInfoForSM) probe the plausibility, velocity, and SMS home-routing controls that are supposed to neutralise legitimate-looking but abusive traffic. Each case is paired with MAP/CAP fuzzing variants to surface STP and HLR implementation bugs that the policy layer alone cannot catch.
Lab work uses a representative SS7/SIGTRAN stack so destructive cases can be exercised without risk to subscribers; controlled live work runs an agreed subset against the production perimeter from a real or simulated roaming partner. Deliverables list every finding with a reproducible PoC, the FS.11 mapping, the impact on subscribers and on the operator, and the firewall rule or configuration change that closes it. Teams running these engagements typically pair them with the P1 TS-201 SS7 security training for in-house enablement, the SS7 Security hub for the underlying attack theory, and the Telecom Penetration Testing guide for the broader engagement framework.
More on Ss7 Penetration Testing
Browse all topic hubs, the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.