Wherever I May Roam: Stealthy Interception and Injection Attacks Through Roaming Agreements
Contributo in Atti di convegno
Data di Pubblicazione:
2024
Abstract:
Cellular network users can be attacked through Rogue Base Stations (RBSes). 3G introduced network authentication as a mitigation. However, roaming partnerships between network operators allow requesting authentication vectors. This feature opens doors for state-sponsored attackers with access to roaming infrastructure, allowing the operation of stealthy RBSes anywhere in the world. This by far exceeds what lawful interception interfaces were designed for but provides attackers with similar capabilities, such as network traffic interception, manipulation, and injecting management frames towards a user’s device. Updated 5G roaming procedures do not prevent this issue. We demonstrate that modern smartphones effectively cannot indicate such attacks to end-users.
Tipologia CRIS:
4.1 Contributo in Atti di convegno
Keywords:
5G; Baseband Exploitation; MitM Attacks; Roaming
Elenco autori:
Lange, S.; Gringoli, F.; Hollick, M.; Classen, J.
Link alla scheda completa:
Titolo del libro:
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Pubblicato in: