GSMA SMS and Signaling Security Guidelines Explained
Operators and vendors cite GSMA documents constantly, but rarely explain them. This guide summarises the ones that matter for SMS and signaling security, and what each asks operators to do.
Short answer
The GSMA publishes guidance that mobile operators use to secure interconnects and messaging. For SMS and signaling, the key documents are FF.09 (SMS fraud), FS.07 (SS7 and SIGTRAN security), FS.11 (SS7 interconnect monitoring and firewall rules), FS.12 (A2P SMS bypass and fraud), SG.22 (SMS firewall best practices), FS.19 (Diameter), FS.20 (GTP) and FS.52 (Global Title leasing). Several are available only to GSMA members.
The documents at a glance
| Document | Topic | Why it matters |
|---|---|---|
| FF.09 | SMS fraud | Describes SMS types, normal traffic flows and how fraud scenarios arise |
| FS.07 | SS7 and SIGTRAN network security | Analyses security at each layer of the SS7 and SIGTRAN stack |
| FS.11 | SS7 interconnect security monitoring and firewall guidelines | The basis for SS7 firewall rules, including message categories 1, 2 and 3 |
| FS.12 | A2P SMS bypass and fraud: methods, detection and mitigation | Covers A2P bypass, artificially inflated traffic and unauthorised HLR lookups |
| SG.22 | SMS firewall best practices and policies | High-level guidance for designing and managing SMS firewall policies |
| FS.19 | Diameter interconnect security | The 4G counterpart to FS.11 |
| FS.20 | GTP security | Protection of data-roaming signaling |
| FS.21 | Interconnect signaling security recommendations | A risk-based approach across interconnect protocols |
| FS.52 | Global Title leasing code of conduct | Rules for leasing Global Titles, a common route for signaling abuse |
The GSMA lists these documents on its interworking security page. Access to several requires GSMA membership.
FS.11 categories explained
FS.11 sorts SS7 messages by where they may legitimately come from, which turns into firewall rules:
- Category 1
- Messages that should only be received from within the same network, or from partners with an explicit bilateral agreement. Arriving from any other interconnect, they are blocked.
- Category 2
- Messages that should only be received from a visiting subscriber's home network. The firewall checks that the sender is the subscriber's home operator.
- Category 3
- Messages that should only be received from the network the subscriber is actually visiting. Enforcing this needs location checks, such as whether the subscriber could plausibly be in that network now.
FS.12 and A2P bypass
FS.12 addresses the commercial side of SMS fraud: A2P traffic delivered through bypass routes, artificially inflated traffic, and HLR lookups used to harvest subscriber data. It is the reference document behind grey route policies on operator SMS firewalls. See SMS grey routes.
SG.22 and SMS firewall policy
SG.22 is about how operators run an SMS firewall: which traffic to classify, how to set and review policies, and how to avoid blocking legitimate traffic. It is a management guide rather than a technical specification.
How the guidelines translate into products
- A signaling firewall implements FS.11, FS.19 and FS.20 rules on SS7, Diameter and GTP interconnects.
- An SMS firewall applies FS.12 and SG.22 to the messages themselves.
- Global Title screening reflects FS.52 concerns about leased and misused GTs.
A caution
Compliance with a GSMA document is not a certification, and the documents are guidance rather than law. Ask a vendor which specific rules and categories its product enforces, and how it shows that in reports.
Related
Talk to our carrier team
Tell us which destinations, volumes or networks you are working with. A member of our team will reply by email.
- Email: sales@wisenetwork.co
- Phone: +961 3 085 999