New Security Threats Caused by IMS-based SMS Service in 4G LTE Networks

New Security Threats Caused by IMS-based SMS Service in 4G LTE Networks
复制标题

4G LTE网络中基于IMS的短信业务带来新的安全威胁

DOI:
--
复制
发表时间:
2016
期刊:
Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Songwu Lu
Songwu Lu
中科院分区:
--
文献类型:
--
作者:
Guan;Chi;Chunyi Peng;Yuanjie Li;Songwu Lu

文献摘要

被引文献

相似文献

SMS (Short Messaging Service)是一种为移动用户提供短信交换的短信服务。它也被广泛用于提供短信驱动的服务(例如,移动银行)。随着全IP 4G移动网络的快速部署,短信的底层技术从传统的电路交换网络发展到分组交换网络上的IMS (IP多媒体子系统)系统。本文主要研究了基于ims的短信系统的不安全性。我们发现了它的安全漏洞,并利用它们设计了四种短信攻击:无声短信滥用、短信欺骗、短信客户端拒绝和短信垃圾邮件。我们进一步发现,这些短信威胁可以传播到短信驱动的服务,从而导致三种恶意攻击:社交网络帐户劫持,未经授权的捐赠和未经授权的订阅。我们的分析表明,这些问题源于移动电话、运营商网络和短信服务之间松散的安全规定。最后,我们针对已发现的安全问题提出补救措施。
SMS (Short Messaging Service) is a text messaging service for mobile users to exchange short text messages. It is also widely used to provide SMS-powered services (e.g., mobile banking). With the rapid deployment of all-IP 4G mobile networks, the underlying technology of SMS evolves from the legacy circuit-switched network to the IMS (IP Multimedia Subsystem) system over packet-switched network. In this work, we study the insecurity of the IMS-based SMS. We uncover its security vulnerabilities and exploit them to devise four SMS attacks: silent SMS abuse, SMS spoofing, SMS client DoS, and SMS spamming. We further discover that those SMS threats can propagate towards SMS-powered services, thereby leading to three malicious attacks: social network account hijacking, unauthorized donation, and unauthorized subscription. Our analysis reveals that the problems stem from the loose security regulations among mobile phones, carrier networks, and SMS-powered services. We finally propose remedies to the identified security issues.