Cellular network users can be attacked through Rogue Base Stations (RBSes). 3G introduced network authentication as a mitigation. However, roaming partnerships between network operators allow requesting authentication vectors. This feature opens doors for state-sponsored attackers with access to roaming infrastructure, allowing the operation of stealthy RBSes anywhere in the world. This by far exceeds what lawful interception interfaces were designed for but provides attackers with similar capabilities, such as network traffic interception, manipulation, and injecting management frames towards a user’s device. Updated 5G roaming procedures do not prevent this issue. We demonstrate that modern smartphones effectively cannot indicate such attacks to end-users.

Wherever I May Roam: Stealthy Interception and Injection Attacks Through Roaming Agreements

Gringoli F.;Classen J.
2024-01-01

Abstract

Cellular network users can be attacked through Rogue Base Stations (RBSes). 3G introduced network authentication as a mitigation. However, roaming partnerships between network operators allow requesting authentication vectors. This feature opens doors for state-sponsored attackers with access to roaming infrastructure, allowing the operation of stealthy RBSes anywhere in the world. This by far exceeds what lawful interception interfaces were designed for but provides attackers with similar capabilities, such as network traffic interception, manipulation, and injecting management frames towards a user’s device. Updated 5G roaming procedures do not prevent this issue. We demonstrate that modern smartphones effectively cannot indicate such attacks to end-users.
2024
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Ateneo di appartenenza
PE7_8 Networks (communication networks, sensor networks, networks of robots...)
Esperti anonimi
Inglese
no
29th European Symposium on Research in Computer Security, ESORICS 2024
2024
pol
Internazionale
ELETTRONICO
14985
208
228
21
9783031709029
9783031709036
Springer Science and Business Media Deutschland GmbH
5G; Baseband Exploitation; MitM Attacks; Roaming
no
Not applicable
none
Lange, S.; Gringoli, F.; Hollick, M.; Classen, J.
273
info:eu-repo/semantics/conferenceObject
4
4 Contributo in Atti di Convegno (Proceeding)::4.1 Contributo in Atti di convegno
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11379/614916
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 4
  • ???jsp.display-item.citation.isi??? 4
social impact