Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Outline
LTE/4G Security
AAacking methods/demos
Mo+va+on
Baseband story
Fake base-sta+ons..1
Fake base-sta+ons..2
LTE/4G networks
LTE
Architecture
E-UTRAN
Cell
S1
eNodeB
UE
AS
Tracking Area
MME
I
n
t
e
r
n
e
t
NAS
AS
:
Access
Stratum
UE:
User
Equipment
NAS
:
Non-Access
Stratum
S1
:
Interface
E-UTRAN:
Evolved
Universal
Terrestrial
Access
Network
MME
:
Mobility
Management
EnMty
Security algorithms
Paging in LTE
10
Paging
in
LTE
IMSI = 404220522xxxxxx"
TMSI = A000FFFF"
eNodeB"
11
Cell
5
Cell
4
Cell
1
Cell
3
Tracking Area
Cell 2
12
But
in
pracMce:
implementaMons
aws,
specicaMon/protocol
deciencies?
* hAps://insidersurveillance.com/rayzone-piranha-lte-imsi-catcher/
13
Specica+on Vulnerabili+es
14
Broadcast
informaMon
UE
idenMMes
Network
informaMon
(SIB)
messages
Neither
authenMcated
nor
encrypted
UE measurement reports
*3GPP
TS
36.331
:
E-UTRA;
RRC
protocol
Fig.
source:
hAp://lteuniversity.com/
15
Broadcast
informaMon
UE
IdenMMes
IMSI,
TMSI
Network
informaMon
messages
(SIB)
Neither
authenMcated
nor
encrypted
eNodeB
16
Tracking
Area
Update(TAU)
procedure
17
18
19
20
For
handover
Privacy
sensiMve
informaMon
in
the
report
Request
not
authenMcated
reports
are
not
encrypted
21
22
Congura+on
issues
Deployments
all
over
the
world!
Smart
Paging
Directed
onto
a
small
cell
rather
than
a
tracking
area
Allows
aAacker
to
locate
LTE
subscriber
in
a
cell
GUTI
persistence
GUTI
change
handover/aAach/reallocaMon
procedure
MNOs
tend
not
to
change
GUTI
suciently
frequently
MME issues
23
24
Experiment
Set-up
Set-up
cost
-
liZle
over
1000
Euro!
25
Demo
26
Demo
27
Measurement/RLF
report
Two
rogue
eNodeBs
for
RLF
eNodeB1
triggers
RL
failure:
disconnects
mobile
eNodeB2
then
requests
RLF
report
from
mobile
Demo
28
DoS
AZacks
Exploi+ng
specica+on
vulnerability
in
EMM
protocol!
Downgrade
to
non-LTE
network
services
(GSM/3G)
Persistent DoS
Demo
29
Summary
30
Solu+on!
Use
any
old
Nokia
phone
without
baZery
and
SIM
card!
31
Impact
Specica+on
vulnerabili+es
aect
every
LTE-enabled
device!
ImplementaMon
issues
are
(almost)
xed
by
baseband
chip
manufacturers
J
32
Thanks
Ques+ons?