Exposing LTE Security Weaknesses at Protocol Inter-layer, and Inter-radio Interactions

Exposing LTE Security Weaknesses at Protocol Inter-layer, and Inter-radio Interactions
复制标题

暴露协议层间和无线电间交互的 LTE 安全弱点

DOI:
10.1007/978-3-319-78813-5_16
复制
发表时间:
2017
期刊:
2012 IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
Songwu Lu
Songwu Lu
中科院分区:
--
文献类型:
--
作者:
M. T. Raza;F. Anwar;Songwu Lu

文献摘要

被引文献

相似文献

尽管使用安全盾牌来保护用户与无线接入网络和核心基础设施的通信,但4G LTE仍然容易受到一些安全威胁。这些漏洞主要是由于其协议的层间通信和接入技术(2G/3G)的无线电间交互造成的。我们从认证、安全关联和服务可用性三个维度对未被覆盖的漏洞进行分类,并在运行中的LTE网络中验证这些漏洞。为了评估这些安全威胁的实际影响,我们将这些威胁转换为主动攻击,在这种攻击中,对手可以(A)将受害者的设备踢出网络,(B)劫持受害者的位置,以及(C)静默耗尽受害者的电池电量。此外,我们已经证明,攻击者不需要与受害者设备通信或驻留在设备上就可以发起这些攻击(即,不需要特洛伊木马或恶意软件)。我们进一步建议对已确定的攻击采取补救措施。
Despite security shields to protect user communication with both the radio access network and the core infrastructure, 4G LTE is still susceptible to a number of security threats. The vulnerabilities mainly exist due to its protocol’s inter-layer communication, and the access technologies (2G/3G) inter-radio interaction. We categorize the uncovered vulnerabilities in three dimensions, i.e., authentication, security association and service availability, and verify these vulnerabilities in operational LTE networks. In order to assess practical impact from these security threats, we convert these threats into active attacks, where an adversary can (a) kick the victim device out of the network, (b) hijack the victim’s location, and (c) silently drain the victim’s battery power. Moreover, we have shown that the attacker does not need to communicate with the victim device or reside at the device to launch these attacks (i.e., no Trojan or malware is required). We further propose remedies for the identified attacks.