@affitz

Let Me Answer That for You: Exploiting Broadcast Information in Cellular Networks

, , and . Proceedings of the 22nd USENIX Security Symposium, Washington, D.C., USA, (August 2013)

Abstract

Mobile telecommunication has become an important part of our daily lives. Yet, industry standards such as GSM often exclude scenarios with active attackers. Devices participating in communication are seen as trusted and non-malicious. By implementing our own baseband firmware based on OsmocomBB, we violate this trust and are able to evaluate the impact of a rogue device with regard to the usage of broadcast information. Through our analysis we show two new attacks based on the paging procedure used in cellular networks. We demonstrate that for at least GSM, it is feasible to hijack the transmission of mobile terminated services such as calls, perform targeted denial of service attacks against single subscribers and as well against large geographical regions within a metropolitan area.

Links and resources

Tags

community

  • @dblp
  • @affitz
@affitz's tags highlighted