Contextual SS7 Firewall MSU Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current SS7 network firewalls are ineffective in blocking malicious actors from bypassing security criteria, allowing unlawful access and compromising message traffic integrity.
Innovation Solution
A contextual SS7 firewall system and method that validates Message Signaling Units (MSUs) within GSM messages, blocking or allowing transmission based on predefined criteria, including HLR interrogation, switch address comparisons, and MTP field validation, without requiring changes to existing SS7 network operators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional SS7 firewalls are used to filter signaling traffic, then basic routing control is provided, but malicious actors can bypass the pre-determined criteria and compromise network integrity
Solution Approach 1:
The patent performs preliminary validation of MSU contents and correctness before allowing traffic through the firewall. By validating message structure, syntax, and semantic correctness in advance, the system prevents malicious traffic from bypassing security controls, thereby improving network reliability without requiring complex real-time detection mechanisms.
Solution Approach 2:
The patent introduces an intermediary validation layer that sits between the traditional firewall and the SS7 network. This intermediary component performs detailed MSU validation (checking message structure, syntax, and semantics) before traffic is allowed through, providing enhanced security without requiring changes to existing firewall infrastructure or network operators' equipment.
2Reliability
If comprehensive MSU validation is performed to block fraudulent traffic, then message traffic integrity is ensured, but processing time and system complexity increase
Solution Approach 1:
The patent segments the validation process into distinct components: MSU structure validation, syntax validation, and semantic correctness validation. By dividing the validation into separate modular steps, the system can efficiently process each aspect independently, ensuring message integrity while minimizing overall processing time through parallel processing capabilities.
Solution Approach 2:
The patent changes validation parameters dynamically based on message type and source. By adjusting the depth and type of validation performed based on predefined criteria and message characteristics, the system ensures thorough validation of potentially fraudulent messages while allowing quickly validated legitimate messages to pass with minimal processing delay.
Data Source
AI summary
A contextual SS7 firewall filter is inserted between a network operator and its roaming partners intra network and inter network SS7 traffic. SS7 firewall filter validates GSM MAP and GSM CAP messages based on specific criteria as provisioned for those message types and either allows them or blocks them from reaching their intended destination based on the validation results. The validation step involves verification of MSU correctness, verification of correctness of SS7 MTP fields for each MSU, and verification of correctness of SS7 SCCP fields for each MSU. SS7 firewall filter blocks GSM messages that fail at least one of the verification steps.


