TechFacts007.in

Be Smart, Be Technical

Dedicated Server

What is SS7 (Signaling System 7) – What Can SS7 Do ?

What Is SS7 : Signaling System 7 (SS7) is an international telecommunications standard that defines how network elements in a public switched telephone network (PSTN) exchange information over a digital signaling network. Nodes in an SS7 network are called signaling points.

SS7 attack image

SS7 consists of a set of reserved or dedicated channels known as signaling links. There are three kinds of network points signaling points: Service Switching Points (SSPs), Signal Transfer Points (STPs), and Service Control Points (SCPs). SSPs originate or terminate a call and communicate on the SS7 network with SCPs to determine how to route a call or set up and manage some special feature. Traffic on the SS7 network is routed by packet switches called STPs. SCPs and STPs are usually mated so that service can continue if one network point fails.

 

What is ss7 used for?


Signalling System No. 7. Signaling System No. 7 (SS7) is a set of telephony signaling protocols developed in 1975, which is used to set up and tear down most of the world’s public switched telephone network (PSTN) telephone calls.

 

What does SS7 normally do?


SS7 is a set of protocols allowing phone networks to exchange the information needed for passing calls and text messages between each other and to ensure correct billing. It also allows users on one network to roam on another, such as when travelling in a foreign country.

 

What can I do to protect myself from snooping via SS7 ?


For text messages, avoiding SMS and instead using encrypted messaging services such as Apple’s iMessage, Facebook’s WhatsApp or the many others available will allow you to send and receive instant messages without having to go through the SMS network, protecting them from surveillance.

For calls, using a service that carries voice over data rather than through the voice call network will help prevent your calls from being snooped on. Messaging services including WhatsApp permit calls. Silent Circle’s end-to-end encrypted Phone service or the open-source Signal app also allow secure voice communications.

Your location could be being tracked at any stage when you have your mobile phone on. The only way to avoid it is to turn off your phone or turn off its connection to the mobile phone network and rely on Wi-Fi instead.

 



 

SS7 uses out-of-band signaling, which means that signaling (control) information travels on a separate, dedicated 56 or 64 Kbps channel rather than within the same channel as the telephone call. Historically, the signaling for a telephone call has used the same voice circuit that the telephone call traveled on (this is known as in-band signaling). Using SS7, telephone calls can be set up more efficiently and special services such as call forwarding and wireless roaming service are easier to add and manage.

VPS Hosting

SS7 is used for these and other services:

  • Setting up and managing the connection for a call
  • Tearing down the connection when the call is complete
  • Billing
  • Managing call forwarding, calling party name and number display, three-way calling, and other Intelligent Network (IN) services
  • Toll-free (800 and 888) and toll (900) calls
  • Wireless as well as wireline call service including mobile telephone subscriber authentication, personal communication service (PCS), and roaming

SS7 messages contain such information as:

How should I route a call to 914 331-4985?

The route to network point 587 is crowded. Use this route only for calls of priority 2 or higher.

Subscriber so-and-so is a valid wireless subscriber. Continue with setting up the call.

 



 

In 2014, security researchers in Germany demonstrated that attackers could exploit security holes in SS7 to track cell phone users’ movements and communications and eavesdrop on conversations. The attack in question is essentially a man-in-the-middle attack on cell phone communications that, among other things, exploits the lack of authentication in the communication protocols that run on top of SS7.