Contextual SS7 Firewall MSU Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SS7 network firewalls are ineffective in blocking malicious actors from bypassing security criteria, allowing unlawful access and compromising message traffic integrity.

Innovation Solution

A contextual SS7 firewall system and method that validates Message Signaling Units (MSUs) within GSM messages, blocking or allowing transmission based on predefined criteria, including HLR interrogation, switch address comparisons, and MTP field validation, without requiring changes to existing SS7 network operators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional SS7 firewalls are used to filter signaling traffic, then basic routing control is provided, but malicious actors can bypass the pre-determined criteria and compromise network integrity

Engineering Contradiction:
Improvenetwork securityVSAvoidfirewall validation mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary validation of MSU contents and correctness before allowing traffic through the firewall. By validating message structure, syntax, and semantic correctness in advance, the system prevents malicious traffic from bypassing security controls, thereby improving network reliability without requiring complex real-time detection mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary validation layer that sits between the traditional firewall and the SS7 network. This intermediary component performs detailed MSU validation (checking message structure, syntax, and semantics) before traffic is allowed through, providing enhanced security without requiring changes to existing firewall infrastructure or network operators' equipment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive MSU validation is performed to block fraudulent traffic, then message traffic integrity is ensured, but processing time and system complexity increase

Engineering Contradiction:
Improvemessage traffic integrityVSAvoidmessage processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the validation process into distinct components: MSU structure validation, syntax validation, and semantic correctness validation. By dividing the validation into separate modular steps, the system can efficiently process each aspect independently, ensuring message integrity while minimizing overall processing time through parallel processing capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes validation parameters dynamically based on message type and source. By adjusting the depth and type of validation performed based on predefined criteria and message characteristics, the system ensures thorough validation of potentially fraudulent messages while allowing quickly validated legitimate messages to pass with minimal processing delay.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11039316B2Contextual signaling system 7 (SS7) firewall and associated method of use
Publication Date: 2021.06.15 SYNIVERSE TECHNOLOGIES LLC
  • US11039316B2 patent drawing
  • US11039316B2 patent drawing
  • US11039316B2 patent drawing

AI summary

A contextual SS7 firewall filter is inserted between a network operator and its roaming partners intra network and inter network SS7 traffic. SS7 firewall filter validates GSM MAP and GSM CAP messages based on specific criteria as provisioned for those message types and either allows them or blocks them from reaching their intended destination based on the validation results. The validation step involves verification of MSU correctness, verification of correctness of SS7 MTP fields for each MSU, and verification of correctness of SS7 SCCP fields for each MSU. SS7 firewall filter blocks GSM messages that fail at least one of the verification steps.