SMS and one-time-password interception in LTE networks

SMS and one-time-password interception in LTE networks
复制标题

LTE 网络中的 SMS 和一次性密码拦截

DOI:
--
复制
发表时间:
2017
期刊:
2017 IEEE International Conference on Communications (ICC)
影响因子:
--
通讯作者:
Ian Oliver
Ian Oliver
中科院分区:
--
文献类型:
--
作者:
S. Holtmanns;Ian Oliver

文献摘要

被引文献

相似文献

互连网络将通信网络本身彼此连接起来,从而能够在所述网络之间实现诸如漫游和数据服务之类的特征。自2014年以来,已经知道可以使用传统的SS7(7号信令系统)协议截取基于SMS的业务。网络提供商现在正转向基于Diameter的LTE网络,希望该协议中提供的额外安全性也提高了整体互连安全性。在本文中,我们将展示如何使用独立于设备或操作系统类型的基于Diameter的网络来拦截短信。我们将展示对谷歌、微软、推特等服务的实际影响。我们将总结推特对负责任的披露的反应、潜在的对策和未来的研究展望。
The Interconnection network connects the communication networks themselves to each other enabling features such as roaming and data services between those said networks. It has been known since 2014 that using the legacy SS7 (Signaling System No. 7) protocol SMS based traffic can be intercepted. Network providers are now moving towards diameter based LTE networks with the hope that the additional security provided in that protocol also improves overall interconnection security. In this article we will show how SMS can be intercepted using diameter based networks independently of device or OS type. We will show the practical impact upon services such as those provided by Google, Microsoft, Twitter, etc. We will summarize the reaction of twitter to the responsible disclosure, potential countermeasures and future research outlook.