{"id":551,"date":"2018-08-07T13:31:57","date_gmt":"2018-08-07T12:31:57","guid":{"rendered":"https:\/\/www.erroussafi.com\/?p=551"},"modified":"2019-05-01T17:45:44","modified_gmt":"2019-05-01T16:45:44","slug":"brief-introduction-to-ss7-and-its-flaws","status":"publish","type":"post","link":"https:\/\/www.erroussafi.com\/index.php\/2018\/08\/07\/brief-introduction-to-ss7-and-its-flaws\/","title":{"rendered":"Brief Introduction to SS7 and its Flaws"},"content":{"rendered":"<p>Dans le cadre d&#8217;une plateforme d&#8217;\u00e9change, j&#8217;ai publi\u00e9 un article tr\u00e8s simple d&#8217;introduction des vuln\u00e9rabilit\u00e9s SS7 des r\u00e9seaux d&#8217;interconnections mobiles. Voici l&#8217;article et le lien vers l&#8217;\u00e9change complet.<\/p>\n<p><!--more--><\/p>\n<p>SS7\u00a0or Signaling System No. 7 is a networking\/interconnect set of\u00a0protocols\u00a0and interconnection definitions developed in the 1970s, which is still widely used to set up and connect most of\u00a0Telephone\u00a0Networks.<\/p>\n<p>It was supposed to be used internally, in a form of \u201cwalled garden\u201d network. and that was sufficient at the time to consider it as &#8220;secure&#8221; among telco players.<\/p>\n<p>At design, the high cost of SS7\u00a0hardware\u00a0(and software), was the only barrier preventing third\u00a0parties\u00a0from penetrating such\u00a0networks\u00a0and using it in a\u00a0malicious\u00a0and harmful way.<\/p>\n<p>During the past decades, the telco landscape changed drastically, mainly driven by: The All-IP transition, the\u00a0evolution\u00a0of data and the very, very, very competitive market of\u00a0telecom\u00a0suppliers.<\/p>\n<p>The hardware barrier was removed thanks to the wide adoption of SIGTRAN (SS7 over IP) in order to interconnect networks over IP. Then\u00a0documentation, and the work of many\u00a0security researcher\u00a0lead to the exposition of the many built-in flaws of this protocol.<\/p>\n<p>A very large set of\u00a0Attacks\u00a0can be launched and are mainly targeting :<\/p>\n<ul>\n<li>The\u00a0network operators\u00a0themselves<\/li>\n<li>The end\u00a0customer<\/li>\n<\/ul>\n<p>Those, very critical attacks can go from calls\u00a0interception,\u00a0SMS\u00a0interception \u2026 to a complete\u00a0DDOS\u00a0of\u00a0network\u00a0infrastructures and a complete loss of service.<\/p>\n<p>The\u00a0GSMA\u00a0addressed those\u00a0threats\u00a0in a series of reference\u00a0documents\u00a0dealing with the how-to detect, mitigate, and assess those\u00a0risks\u00a0:<\/p>\n<ul>\n<li>IR.82\u00a0SS7 Security\u00a0Network\u00a0Implementation\u00a0Guidelines<\/li>\n<li>FS.07 SS7 and SIGTRAN\u00a0Network Security<\/li>\n<li>FS.11 SS7 Interconnect\u00a0Security Monitoring\u00a0and\u00a0Firewall\u00a0Guidelines<\/li>\n<li>FS.19 Diameter Interconnect Security<\/li>\n<li>FS.20 GPRS Tunnelling\u00a0Protocol\u00a0(GTP) Security<\/li>\n<li>FS.21 Interconnect Signalling Security Recommendations<\/li>\n<\/ul>\n<p>Mainly, measures should cover different layers of the SS7\/SIGTRAN stack. But taken in consideration that policing in MTP, SCCP, MAP layers are mandatory, many architectural considerations are to be taken in order to have effective measures.<\/p>\n<p>Those will be maybe detailed in a next post.<\/p>\n<p>Thank you.<\/p>\n<p>Full thread :\u00a0<a href=\"https:\/\/www.peerlyst.com\/posts\/brief-introduction-to-ss7-and-its-flaws-elmehdi-erroussafi\">https:\/\/www.peerlyst.com\/posts\/brief-introduction-to-ss7-and-its-flaws-elmehdi-erroussafi<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Dans le cadre d&#8217;une plateforme d&#8217;\u00e9change, j&#8217;ai publi\u00e9 un article tr\u00e8s simple d&#8217;introduction des vuln\u00e9rabilit\u00e9s SS7 des r\u00e9seaux d&#8217;interconnections mobiles. Voici l&#8217;article et le lien vers l&#8217;\u00e9change complet.<\/p>\n","protected":false},"author":1,"featured_media":6651,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[3,9],"tags":[],"class_list":["post-551","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-securite","category-technique"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/www.erroussafi.com\/wp-content\/uploads\/2018\/08\/mititgae-ss7-vulnerabilities1.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.erroussafi.com\/index.php\/wp-json\/wp\/v2\/posts\/551","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.erroussafi.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.erroussafi.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.erroussafi.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.erroussafi.com\/index.php\/wp-json\/wp\/v2\/comments?post=551"}],"version-history":[{"count":0,"href":"https:\/\/www.erroussafi.com\/index.php\/wp-json\/wp\/v2\/posts\/551\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.erroussafi.com\/index.php\/wp-json\/wp\/v2\/media\/6651"}],"wp:attachment":[{"href":"https:\/\/www.erroussafi.com\/index.php\/wp-json\/wp\/v2\/media?parent=551"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.erroussafi.com\/index.php\/wp-json\/wp\/v2\/categories?post=551"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.erroussafi.com\/index.php\/wp-json\/wp\/v2\/tags?post=551"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}