In short
SS7 SMS firewall protection analyses the signaling associated with SMS delivery to detect unauthorised, suspicious, malformed, spoofed or policy-violating signaling activity. It inspects MAP operations such as MO-ForwardSM, MT-ForwardSM and SRI-SM before the message reaches the operator's SMSC, and validates that the signaling source is entitled to send what it is sending.
Which operations carry SMS
SMS delivery over SS7 uses a small set of MAP operations, and each one is a potential abuse vector. MO-ForwardSM carries a message from a subscriber's serving switch to the SMSC. MT-ForwardSM delivers toward a subscriber. SendRoutingInfoForSM (SRI-SM) asks the HLR where a subscriber currently is. ReportSM-DeliveryStatus and AlertServiceCentre handle the retry lifecycle.
Screening these operations means checking not just their syntax but their plausibility: whether this source should be issuing this operation, for this subscriber, at this rate, from this Global Title.
What signaling inspection catches
Signaling-layer checks catch categories that application-layer inspection simply cannot see:
- Messages arriving from Global Titles that belong to no agreed interconnect partner
- Spoofed calling-party addresses impersonating a trusted operator or SMSC
- Malformed or non-conformant PDUs used to probe or evade downstream systems
- SRI-SM requests at volumes inconsistent with genuine delivery attempts
- Attempts to bypass SMS home routing so inbound traffic avoids screening
- Mismatches between the route a message claims and the route it actually took
Signaling and application layers together
Neither layer is sufficient alone. A message can be perfectly well-formed at the signaling layer and carry a phishing URL; another can have innocuous content but arrive from a Global Title with no business sending it.
In Guardivia's architecture the Hawk engine performs the signaling processing and screening, then passes message content over an internal SMPP path to the Dolphin and Shark inspection engines. The result is that SS7-derived traffic and direct ESME traffic are judged against the same content rules, registries and classifiers.
Scope boundary
This protection is scoped to SMS signaling. General SS7 security — subscriber location tracking, non-SMS MAP category screening and similar — is a different problem addressed through the STP platform in the Guardivia Core Network Suite or a separately scoped engagement. Conflating the two leads to deployments that are assumed to cover threats they were never configured for.