Browse Definitions :
Definition

SS7 attack

Contributor(s): Matthew Haughn

An SS7 attack is an exploit that takes advantage of a weakness in the design of SS7 (Signalling System 7) to enable data theft, eavesdropping, text interception and location tracking.

While the SS7 network is fundamental to cellphones and its operators, the security of the design relied entirely on trust. The SS7 network operators counted on one another to play by the rules. Now, with operators opening the SS7 network to offer third-party access as a commercial offering, vulnerabilities are being exposed and attacked. Service provider cooperation with government agencies enabled state surveillance; the newly opened network and greater exposure enables access by agencies in other nations and individual hackers.

In 2014, security researchers in Germany demonstrated that attackers could exploit security holes in SS7 to track cell phone users' movements and communications and eavesdrop on conversations. The attack in question is essentially a man-in-the-middle attack on cell phone communications that, among other things, exploits the lack of authentication in the communication protocols that run on top of SS7.

Although the design element presents an exploitable vulnerability, it is integral to the system rather than a defect. The exposure of the SS7 vulnerabilities has demonstrated how easy it is for network operators, government and, due to the presence of exploit tools available on the Internet, even citizens to track and exploit smartphones. Used directly on a phone, SS7 attacks can surreptitiously enable location tracking, fraud, denial of service or call interception, even on GSM networks.

Interception SS7 attacks enable many potential exploits through the many services tied to smartphones as a supposed security-enhancing device. Examples include Facebook account hacking with just the phone number and tracking individuals within 50 meters with commercially available SS7: Locate. Track. Manipulate software. As well, with many bank accounts secured by multi-factor authentication that depends on smartphones, the security of everything smartphone-related might well need reassessment.

This was last updated in July 2016

Continue Reading About SS7 attack

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

File Extensions and File Formats

Powered by:

SearchCompliance

  • compliance audit

    A compliance audit is a comprehensive review of an organization's adherence to regulatory guidelines.

  • regulatory compliance

    Regulatory compliance is an organization's adherence to laws, regulations, guidelines and specifications relevant to its business...

  • Whistleblower Protection Act

    The Whistleblower Protection Act of 1989 is a law that protects federal government employees in the United States from ...

SearchSecurity

  • brute force attack

    Brute force (also known as brute force cracking) is a trial and error method used by application programs to decode encrypted ...

  • spyware

    Spyware is software that is installed on a computing device without the user's knowledge. Spyware can be difficult to detect; ...

  • ATM black box attack

    An ATM black box attack, also referred to as jackpotting, is a type of banking-system crime in which the perpetrators bore holes ...

SearchHealthIT

SearchDisasterRecovery

  • business continuity and disaster recovery (BCDR)

    Business continuity and disaster recovery (BCDR) are closely related practices that describe an organization's preparation for ...

  • warm site

    A warm site is a type of facility an organization uses to recover its technology infrastructure when its primary data center goes...

  • disaster recovery (DR) test

    A disaster recovery test (DR test) is the examination of each step in a disaster recovery plan as outlined in an organization's ...

SearchStorage

  • enterprise storage

    Enterprise storage is a centralized repository for business information that provides common data management, protection and data...

  • disk array

    A disk array, also called a storage array, is a data storage system used for block-based storage, file-based storage or object ...

  • optical storage

    Optical storage is any storage type in which data is written and read with a laser. Typically, data is written to optical media, ...

Close