SS7 still supports essential mobile services such as voice, SMS, roaming and core-network signaling. The problem is that SS7 was designed when telecom networks operated within a much more trusted environment.
That trust model no longer matches today’s threat landscape.
The GSMA notes that SS7 lacks modern authentication and encryption protections, which can allow attackers with signaling-network access to attempt location tracking, SMS interception and traffic rerouting.
For operators, SS7 security therefore requires more than simply keeping signaling links available. It requires controlling who can send signaling requests, understanding what those requests are doing and stopping suspicious activity before it reaches subscriber data or services.
Why SS7 Is Still a Security Target
SS7 connects network elements that exchange information required for services such as roaming, SMS delivery and subscriber mobility.
Because these systems need to communicate across networks, a malicious or compromised signaling participant can potentially abuse legitimate SS7 procedures.
ENISA has identified several security risks associated with signaling weaknesses, including:
- Location tracking
- SMS interception
- Call interception
- Subscriber denial of service
- Account fraud
- Subscriber-information extraction
These attacks do not necessarily require malware on the subscriber’s phone. The attack can happen within the signaling infrastructure itself.
That makes network-level protection essential.
How Location Tracking Happens
Mobile networks need to know roughly where subscribers are registered so calls, messages and services can reach them.
Certain SS7 procedures therefore allow network elements to request subscriber and serving-network information.
If an unauthorized party gains signaling access and those requests are not properly controlled, the same functionality can potentially be abused to identify the network currently serving a subscriber and infer their location.
The risk is serious enough that the GSMA maintains dedicated guidance covering SS7 and SIGTRAN security, signaling monitoring and firewall controls.
The objective is not to block normal signaling. Operators need to distinguish legitimate roaming and service traffic from suspicious requests.
How Attackers Can Intercept SMS
SMS interception is particularly significant because SMS is still used for authentication messages, transaction alerts and one-time passwords.
An attacker with sufficient signaling access may attempt to manipulate subscriber-routing information so that an SMS is redirected through infrastructure under the attacker’s control.
ENISA has documented real-world and demonstrated cases involving SMS and one-time-password interception through signaling weaknesses.
The GSMA consequently maintains specific guidance for identifying and containing SMS-related SS7 attacks.
Protecting SMS therefore requires looking beyond the SMSC. Operators also need visibility into the signaling requests determining where the SMS is routed.
What Operators Should Do
A practical SS7 security strategy should combine several controls.
1. Control signaling traffic
Operators should define which signaling messages are permitted from external networks, roaming partners and other interconnected systems.
Requests that do not match legitimate network behavior should be rejected or investigated.
GSMA’s SS7 implementation guidance specifically addresses security measures for MAP and CAP signaling and identifies possible enforcement points within operator, carrier, roaming and SMS environments.
2. Monitor signaling continuously
Filtering alone is not enough.
Operators should watch for patterns such as unusual subscriber-information queries, unexpected location requests, abnormal routing changes or repeated requests involving the same subscriber.
Monitoring also gives security teams evidence for adjusting firewall policies as attack techniques evolve.
3. Protect sensitive subscriber procedures
Processes involving location, authentication information and subscriber routing deserve particularly strict controls.
A signaling request may technically be valid while still being suspicious because of its source, frequency or context.
Security decisions therefore need to consider both the signaling message and who is sending it.
4. Secure the SIGTRAN layer
Many operators now transport SS7 signaling across IP networks using SIGTRAN.
This means operators need a signaling architecture that can integrate reliably with existing network elements while providing clear control over the applications accessing signaling functions.
hSenid Mobile’s SIGTRAN Gateway is an in-house software-based SIGTRAN stack designed to integrate with existing operator environments and manage signaling integration for value-added services.
Its stack includes SCTP, MTP, SCCP, TCAP and MAP, while exposing signaling functionality to internal applications through HTTP APIs.
Importantly, the supplied product documentation does not explicitly state that the gateway itself provides SS7 firewall or signaling-filtering functionality. That capability should therefore be confirmed before describing the product as an SS7 firewall.
Proven in Real Operator Integrations
This is where the discussion becomes more practical than a generic SS7 security checklist.
According to hSenid Mobile’s product documentation, its SIGTRAN Gateway has already been used in carrier-grade environments across:
- SMSC integrations
- USSD Gateway integrations
- Location-Based Services
- HLR integration for authentication-vector extraction
- MNP call-control integration for fixed-line traffic
The platform also exposes direct signaling functions such as subscriber-information retrieval, authentication-vector requests, IMSI lookup and routing information for location services.
That experience matters because signaling security has to coexist with real operational traffic. Operators cannot simply block SS7 requests aggressively and risk breaking roaming, messaging or value-added services.
SS7 Security Is Now About Controlled Trust
SS7 cannot simply disappear while operators still depend on it for existing mobile services.
The practical answer is to reduce the amount of implicit trust inside the signaling environment.
Know which systems are communicating. Control which signaling operations they can perform. Monitor unusual behavior. Protect sensitive subscriber requests. And maintain clear visibility across SS7 and SIGTRAN interconnections.
As the GSMA continues to emphasize, effective signaling security depends on monitoring, firewall controls and cooperation between interconnected operators.





