Browse Definitions :
Definition

SS7 attack

Contributor(s): Matthew Haughn

An SS7 attack is an exploit that takes advantage of a weakness in the design of SS7 (Signalling System 7) to enable data theft, eavesdropping, text interception and location tracking.

While the SS7 network is fundamental to cellphones and its operators, the security of the design relied entirely on trust. The SS7 network operators counted on one another to play by the rules. Now, with operators opening the SS7 network to offer third-party access as a commercial offering, vulnerabilities are being exposed and attacked. Service provider cooperation with government agencies enabled state surveillance; the newly opened network and greater exposure enables access by agencies in other nations and individual hackers.

In 2014, security researchers in Germany demonstrated that attackers could exploit security holes in SS7 to track cell phone users' movements and communications and eavesdrop on conversations. The attack in question is essentially a man-in-the-middle attack on cell phone communications that, among other things, exploits the lack of authentication in the communication protocols that run on top of SS7.

Although the design element presents an exploitable vulnerability, it is integral to the system rather than a defect. The exposure of the SS7 vulnerabilities has demonstrated how easy it is for network operators, government and, due to the presence of exploit tools available on the Internet, even citizens to track and exploit smartphones. Used directly on a phone, SS7 attacks can surreptitiously enable location tracking, fraud, denial of service or call interception, even on GSM networks.

Interception SS7 attacks enable many potential exploits through the many services tied to smartphones as a supposed security-enhancing device. Examples include Facebook account hacking with just the phone number and tracking individuals within 50 meters with commercially available SS7: Locate. Track. Manipulate software. As well, with many bank accounts secured by multi-factor authentication that depends on smartphones, the security of everything smartphone-related might well need reassessment.

This was last updated in July 2016

Continue Reading About SS7 attack

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

SearchCompliance

  • risk assessment

    Risk assessment is the identification of hazards that could negatively impact an organization's ability to conduct business.

  • PCI DSS (Payment Card Industry Data Security Standard)

    The Payment Card Industry Data Security Standard (PCI DSS) is a widely accepted set of policies and procedures intended to ...

  • risk management

    Risk management is the process of identifying, assessing and controlling threats to an organization's capital and earnings.

SearchSecurity

SearchHealthIT

SearchDisasterRecovery

  • call tree

    A call tree is a layered hierarchical communication model that is used to notify specific individuals of an event and coordinate ...

  • Disaster Recovery as a Service (DRaaS)

    Disaster recovery as a service (DRaaS) is the replication and hosting of physical or virtual servers by a third party to provide ...

  • cloud disaster recovery (cloud DR)

    Cloud disaster recovery (cloud DR) is a combination of strategies and services intended to back up data, applications and other ...

SearchStorage

  • RAM (Random Access Memory)

    RAM (Random Access Memory) is the hardware in a computing device where the operating system (OS), application programs and data ...

  • business impact analysis (BIA)

    Business impact analysis (BIA) is a systematic process to determine and evaluate the potential effects of an interruption to ...

  • M.2 SSD

    An M.2 SSD is a solid-state drive that is used in internally mounted storage expansion cards of a small form factor.

Close