The Dark Side of Operational Wi-Fi Calling Services

The Dark Side of Operational Wi-Fi Calling Services
复制标题

运营 Wi-Fi 通话服务的黑暗面

DOI:
--
复制
发表时间:
2018
期刊:
IEEE Conference on Communications and Network Security
影响因子:
--
通讯作者:
Mi Zhang
Mi Zhang
中科院分区:
--
文献类型:
--
作者:
Tian Xie;Guan;Chi;Chunyi Peng;Jiawei Li;Mi Zhang

文献摘要

被引文献

相似文献

美国四个主要运营商都在全国范围内推出了Wi-Fi呼叫服务。与常规的蜂窝语音解决方案相比,基于3GPP IMS(IP多媒体子系统)的Wi-Fi网络,主要差异在于它们的流量遍历不信任的Wi-Fi网络和Internet可能会导致这种不安全的网络。 Wi-Fi呼吁用户遭受安全性威胁。但是,不幸的是,他们足以确保Wi-Fi呼叫服务吗?使用商品设备。攻击:用户隐私泄漏和电话骚扰或拒绝语音服务(THDOS);他们可以绕过移动设备和网络基础结构上的安全防御潜在的损害和建议的解决方案。
All of four major U.S. operators have rolled out nationwide Wi-Fi calling services. They are projected to surpass VoLTE (Voice over LTE) and other VoIP services in terms of mobile IP voice usage minutes in 2018. They enable mobile users to place cellular calls over Wi-Fi networks based on the 3GPP IMS (IP Multimedia Subsystem) technology. Compared with conventional cellular voice solutions, the major difference lies in that their traffic traverses untrustful Wi-Fi networks and the Internet. This exposure to insecure networks may cause the Wi-Fi calling users to suffer from security threats. Its security mechanisms are similar to the VoLTE, because both of them are supported by the IMS. They include SIM-based security, 3GPP AKA (Authentication and Key Agreement), IPSec (Internet Protocol Security), etc. However, are they sufficient to secure Wi–Fi calling services? Unfortunately, our study yields a negative answer. In this work, we explore security issues of the operational Wi-Fi calling services in three major U.S. operators’ networks using commodity devices. We disclose that current Wi-Fi calling security is not bullet-proof. We uncover four vulnerabilities which stem from improper standard designs, device implementation issues and network operation slips. By exploiting them, we devise two proof-of-concept attacks: user privacy leakage and telephony harassment or denial of voice service (THDoS); they can bypass the security defenses deployed on both mobile devices and network infrastructure. We have confirmed their feasibility and simplicity using real-world experiments, as well as assessed their potential damages and proposed recommended solutions.