Project

General

Profile

Actions

Feature #4249

open
SD SD

Task #7118: tracking: add support for new protocols

Task #3299: tracking: Add support for industrial protocol

ics protocol: SS7 Protocol Support

Feature #4249: ics protocol: SS7 Protocol Support

Added by Simon Dugas about 5 years ago. Updated 4 months ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Effort:
medium
Difficulty:
medium
Label:
Protocol

Description

Add support for TCAP/MAP Signalling System 7 (SS7) protocols transported on the SIGTRAN stack:

IP / SCTP / MTP2 / MTP3 / SCCP / TCAP / MAP

This includes EVE logging and detection keywords.

Addressing schemes in this stack:
- IP address & SCTP port may not be useful for signatures
- Add support for Point Code (MTP3) & Subsystem Number (SCCP)
- Add support for Global Title (SCCP)

Fields useful as detection keywords:
- Message Type (TCAP)
- Operation Code (MAP)
- Other arguments specific to op codes (MAP)

Keep in mind the various protocol standards, ANSI MAP is different from GSM MAP (ITU).

Resources
  • All: ITU-T Q.700–Q.849 Series for SS7
  • TCAP: ITU-T Q.771-Q.775 or ANSI T1.114
  • MAP: 3GPP TS 29.002 or 3GPP2 X.S0004

Related issues 2 (2 open0 closed)

Related to Suricata - Task #4251: protocol: SCTP supportNewGiuseppe LongoActions
Related to Suricata - Task #8123: Suricon 2025 BrainstormAssignedVictor JulienActions

VJ Updated by Victor Julien about 5 years ago Actions #1

  • Status changed from New to Assigned
  • Label Protocol added

Suricata's SCTP support is currently rather minimal. Is that enough for your use case or are you also planning improvements to SCTP?

SD Updated by Simon Dugas about 5 years ago Actions #2

We are planning to extend support and at the least at session tracking.

VJ Updated by Victor Julien about 5 years ago Actions #3

  • Related to Task #4251: protocol: SCTP support added

JI Updated by Jason Ish over 2 years ago Actions #4

  • Related to Task #3299: tracking: Add support for industrial protocol added

JI Updated by Jason Ish 4 months ago Actions #5

  • Related to Task #8123: Suricon 2025 Brainstorm added

VJ Updated by Victor Julien 4 months ago Actions #6

  • Subject changed from SS7 Protocol Support to ics protocol: SS7 Protocol Support

VJ Updated by Victor Julien 4 months ago Actions #7

  • Parent task set to #3299
Actions

Also available in: PDF Atom