SS7 Security

Signaling System No. 7 (SS7) is the legacy signaling protocol suite still used to interconnect mobile networks worldwide. Originally designed for trusted operator-to-operator use, SS7 lacks built-in authentication and encryption, exposing networks to a well-documented class of attacks.

This hub aggregates everything the Ultimate Guide covers on SS7 security: how the protocol works, the most common attack categories (location tracking, SMS interception, call interception, fraud), and the defensive controls, signaling firewalls, GSMA FS.11 categories, and continuous monitoring, that operators deploy.

In-depth chapters

Frequently asked questions about ss7 security

Do I need a Diameter firewall if I already have an SS7 firewall?

Yes. SS7 firewalls filter at the SCCP/MAP/CAP layer and do not see Diameter traffic, which uses a different transport (SCTP/TCP with TLS/IPsec) and different attack semantics (S6a IDR/PUR, S9, S13). GSMA FS.19 defines category 1/2/3 screening rules that a Diameter Edge Agent (DEA) must enforce independently. Operators running 4G/LTE interconnect need both firewalls; consolidated signaling firewalls implement the FS.11/FS.19/FS.20 rule sets in a single policy engine.

What are MAP messages and how are they abused?

MAP (Mobile Application Part) messages are SS7-layer signaling used for location updates, subscriber data retrieval, and SMS routing. Attackers abuse MAP operations like SendRoutingInfo, ProvideSubscriberInfo, and InsertSubscriberData to track locations, intercept SMS (including 2FA codes), and profile subscribers—all without the subscriber's knowledge.

What tools are used for SS7/Diameter security testing?

Specialized tools for telecom security testing include SigPloit (open-source SS7/Diameter/GTP testing framework), P1 Security's assessment platforms, Catapult/Developing Solutions test suites, and custom SCTP/TCAP stacks. These tools can craft and send specific signaling messages to test how network elements respond to malicious or malformed requests.

What is a signaling firewall and how is it different from a network firewall?

A signaling firewall inspects and filters mobile network control-plane traffic — SS7 (MAP, CAP), Diameter, GTP-C, and SIP — at the interconnect and roaming boundaries. Unlike an IP firewall, which operates on L3/L4 headers, a signaling firewall parses telecom-specific protocol stacks and enforces category-based rules (GSMA FS.11 for SS7, FS.19 for Diameter, FS.20 for GTP) that reflect legitimate roaming and interconnect behavior. It blocks operations such as unauthorized SendRoutingInfo, cross-PLMN IDR abuse, or GTP-C tunnel injection that a generic firewall cannot see.

How much does an SS7 penetration test typically cost and how long does it take?

A typical SS7 penetration test against a Tier-1 MNO runs 4–8 weeks and covers GSMA FS.11 category 1/2/3 test cases across MAP, CAP and SCCP. Cost varies widely with scope (single-country vs. multi-country, home vs. roaming interfaces, MVNO tenants), STP model, and whether monitoring/PCAP infrastructure is already available. Fixed-scope engagements for a national operator commonly land in the mid five- to low six-figure USD range; a global carrier with dozens of interconnects is a multiple of that.

What is SS7 and why is it considered insecure?

SS7 (Signaling System No. 7) is the signaling protocol suite used by 2G/3G networks for call setup, SMS delivery, and roaming. It was designed in the 1970s with an implicit trust model and no authentication or encryption. Attackers who gain access to the SS7 network—via compromised operators or rogue nodes—can intercept calls, track subscriber locations, and redirect SMS messages.

What is SS7 location tracking and can it track my phone?

SS7 location tracking exploits the SendRoutingInfo and ProvideSubscriberInfo MAP operations to query a subscriber's serving cell, revealing their approximate geographic location. Any entity with SS7 network access—including rogue operators or intermediaries—can perform this attack remotely, without the target's knowledge. While 5G and Diameter partially mitigate this, most networks still have 2G/3G fallback, keeping the risk alive for billions of subscribers worldwide.

What is GSMA FS.11 and why does it matter for SS7 security?

GSMA FS.11 is the SS7 Interconnect Signalling Security Recommendations document. It classifies MAP operations into three categories: Category 1 (operations that should never appear across an interconnect and can be blocked outright), Category 2 (operations that are legitimate only from a subscriber's home network), and Category 3 (operations that require cross-checks such as velocity or plausibility). SS7 firewalls are typically configured against these categories, and telecom security audits verify coverage per FS.11.

What is HTTP/2 signaling in 5G and how is it secured?

In 5G SBA, network functions communicate via HTTP/2 over a service-based interface. Security is provided through TLS 1.3 for transport encryption, OAuth 2.0 tokens for service authorization, and the NRF for service discovery and access control. This represents a significant security improvement over the binary protocols used in previous generations.

See all telecom security FAQs

Related glossary terms

Browse the full telecom security glossary

Related comparisons

Compliance crosswalks

More on Ss7 Security

Browse all topic hubs, the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.