Cellusys

TCAP Handshaking & SS7 Security

Security is always a major topic in communications. It is important for customers, regulatory bodies, vendors and operators. 3GPP is standardizing more and more measures to increase security of theGSM in every new GSM release. Some examples:


Introduction to SS7 and Security

Absence of security in SS7 is identified as a weakness, but not seen as a problem due to the following:

Today networks are changing and protection for SS7 is becoming a necessity due to:

SS7 Based Security Threats

Spoofing

Definition:

Precaution:

Faking (MT Spoofing)

Definition:

Precaution:

Spamming

Definition:

Precaution:

Flooding

Definition:

Precaution:

Mobile Viruses

Definition:

Example:

Precaution:


TCAP Handshaking

Overview

TCAP Handshaking MT SMS

TCAP Handshaking MO SMS

TCAPsec

Overview

Network Architecture

SS7 Security Gateway

An SS7 Security Gateway (SS7-SEG) is a network node defined in 3GPP TS 29.204 Signalling System No. 7 (SS7) security gateway; Architecture, functional description and protocol details document. it is responsible for:

An SEG contains two databases:

An outbound message is protected according to the destination address , the policy information and the existing SA corresponding to that address. An inbound message is unprotected or blocked according to the originating address, the policy information and the existing SA corresponding to that address.

Security Association

Before protection can be applied, at least one Security Association (SA) needs to be established between the respective SS7-SEG. A Security Association consists of:#

A Security Parameters Index (SPI) identifies:

Structure of a Protected TCAP Message

A protected TCAP messages is sent as a Unidirectional TCAP message without a dialogue portion, with one invoke component. Operation Code=90 (SecureTransport). ParameterPart (SecureTransportArg) filled with original SCCP Info, original TCAP Info and protected Payload.

Protected payload has 2 sections:

Protection Mode 1: Integrity, Authenticity

Protection Mode 2: Confidentiality, Integrity, and Authenticity


Enabling Security On Real Life Applications

SS7-based security attacks were happening before TCAP security measures were decided. Those attacks were tried to be prevented by special (vendor specific) security additions to network elements and applications, SCCP/MAP policy changes specific to the threat and log analysis. Let’s explore some real-life security scenarios.

Sending SM to invalid network nodes

Basic spam filtering in the SMSC

Hatihati prevention

MO Spoofing Solutions

SMS Firewall / SMS Router

Our SMS firewall and router solutions contain the following features to help secure your network:


Conclusion

TCAP Handshaking is a short/medium term solution, effective only for some SMS related security threats but easy to apply. TCAPsec is a medium/long term solution, more difficult to apply but useful for different TCAP based attacks. These two TCAP security mechanisms are defined in 3GPP specifications and will show their value as more operators will begin to use them. Therefore operators and vendors should take action to implement these measures as soon as they can. These two are not the only precautions. For specific scenarios, other specific and effective solutions can be found.

For further information on our SMS Firewall and SMS Router solutions, check our “Splutions: Network Protection” or contact us directly.