Signaling Firewall for SS7, Diameter and GTP
Our signaling firewall screens the control traffic that roaming partners and interconnect carriers send into your network, and blocks messages that should never arrive from outside.
What is a signaling firewall?
A signaling firewall inspects the control-plane messages that mobile networks exchange over interconnects: SS7 (MAP) and its IP transport SIGTRAN for 2G and 3G, Diameter for 4G, and GTP for data roaming. It blocks messages that a foreign network has no legitimate reason to send, such as location queries or profile changes for subscribers who are at home, and so protects subscribers from tracking, interception and fraud, and the network from denial of service.
SS7 SMS security is one part of this: preventing attackers from spoofing, faking or intercepting SMS by abusing signaling.
What attackers do over signaling
- Location trackingQueries that return a subscriber's serving cell, sent by parties with no roaming relationship to that subscriber.
- InterceptionChanging a subscriber's profile or forwarding settings so calls or SMS are redirected.
- SMS spoofing and fakingMessages whose origin is forged in the signaling, used for fraud and grey routing.
- Subscriber data disclosureRequests that reveal a subscriber's IMSI or profile.
- Denial of serviceMessages that cancel a subscriber's registration or overload network elements.
- Data roaming fraudGTP messages that hijack or create data sessions without a valid roaming relationship.
SS7 and SIGTRAN protection
SS7 carries MAP operations between core elements such as the HLR, MSC and SMSC. SIGTRAN carries the same protocols over IP, through STPs and signaling gateways. The firewall sits at the signaling edge and screens each operation by its type, the calling and called Global Titles, and whether the subscriber's current location makes the request plausible.
For SMS, this includes screening SendRoutingInfoForSM (SRI-for-SM) and MT-ForwardSM operations, detecting mismatches between SCCP addresses and MAP-layer addresses (a sign of SMS faking), and supporting SMS home routing so that subscriber identities and locations are not exposed to foreign SMSCs.
Diameter protection for 4G roaming
In 4G networks, Diameter replaces MAP between the HSS, MME and roaming partners. The firewall screens Diameter requests from interconnect partners, such as update-location, insert-subscriber-data and cancel-location, against the same rule: is this request plausible from this partner, for this subscriber, at this moment?
GTP protection for data roaming
GTP-C sets up and manages data sessions between a visited network and a subscriber's home network. The firewall checks GTP-C messages from roaming partners for spoofed sources, sessions for subscribers who are not roaming with that partner, and message sequences used for session hijacking or data fraud.
GT screening and home routing
Global Title screening limits which external addresses may send which operations to which internal elements. Combined with SMS home routing, it removes much of the information attackers depend on, such as real IMSIs and serving MSC addresses, from replies sent outside the network.
GSMA FS.11, FS.19 and FS.20
Rule sets follow the GSMA's guidance for interconnect signaling: FS.11 for SS7, FS.19 for Diameter and FS.20 for GTP. Each sorts messages by where they may legitimately come from, and the firewall enforces that sorting per interconnect partner. Our guide to GSMA security documents explains each one.
Monitoring and reporting
- Blocked and allowed operations by partner, Global Title and category.
- Alerts for new attack patterns and unusual volumes from a partner.
- Evidence for discussions with roaming partners and for regulators.
Deployment
The firewall connects at the operator's signaling edge: SIGTRAN links to the STP or signaling gateway for SS7, the Diameter edge agent for 4G, and the GTP interconnect for data roaming. A monitoring-only phase usually comes first, so rules are tuned on real traffic before anything is blocked.
Frequently asked questions
Why is SS7 still a risk if networks use 4G and 5G?
Most networks still run 2G and 3G for roaming, voice fallback and SMS, and interconnect with partners over SS7. A weakness in any generation of the network can be used against subscribers on all of them.
What are GSMA FS.11 categories 1, 2 and 3?
FS.11 groups SS7 messages by where they may legitimately come from. Category 1 messages should only come from inside the same network or bilateral partners. Category 2 messages should only come from a subscriber's home network. Category 3 messages should only come from the network the subscriber is actually visiting, which requires checking location plausibility.
Does the signaling firewall also stop SMS fraud?
It stops SMS fraud that relies on signaling abuse, such as faked origin addresses and illegitimate routing queries. Grey routes that use legitimate signaling are better handled by the SMS firewall, which looks at the message itself.
Do you protect 5G signaling?
Our firewall covers SS7/SIGTRAN, Diameter and GTP. Ask us about 5G (HTTP/2 and SEPP) interconnect requirements for your network.
Related
Assess your signaling exposure
Tell us which interconnects you run (SS7/SIGTRAN, Diameter, GTP) and what you want to protect against. We will propose an assessment or demo.
- Email: sales@wisenetwork.co
- Phone: +961 3 085 999