360UnicornTeam
LTE Redirection 1
LTE Redirection
Forcing Targeted LTE Cellphone into Unsafe Network
Qing Yang@360 UnicornTeam Wanqiao Zhang @360 UnicornTeam
LTE Redirection Forcing Targeted LTE Cellphone into Unsafe Network - - PowerPoint PPT Presentation
360UnicornTeam LTE Redirection Forcing Targeted LTE Cellphone into Unsafe Network Qing Yang@360 UnicornTeam Wanqiao Zhang @360 UnicornTeam 1 LTE Redirection LTE and IMSI catcher myths In Nov. 2015, BlackHat EU, Ravishankar Borgaonkar,
360UnicornTeam
LTE Redirection 1
Qing Yang@360 UnicornTeam Wanqiao Zhang @360 UnicornTeam
LTE Redirection
Shaik etc. introduced the LTE IMSI catcher and DoS attack.
2
LTE Redirection 3
Once a cellphone goes through the fake network coverage area, its IMSI will be reported to the fake network.
LTE Redirection 4
DoS message examples: You are an illegal cellphone! Here is NO network available. You could shut down your 4G/3G/2G modem.
LTE Redirection 5
Malicious LTE: “Hello cellphone, come into my GSM network…”
LTE Redirection 6
Fake LTE Network Fake GSM Network USRPs
LTE Redirection
8
LTE Redirection 9
ESM: PDN connectivity request
LTE Redirection 10
Firstly send a TAU reject, then cellphone will send Attach Request, with its IMSI!
LTE Redirection 11
If you send Identity request at the same state, you can also get the cellphone’s IMSI!
Identity Request
LTE Redirection 12
Attach Reject message can bring reject cause. Some special causes result in NO service on cellphone.
LTE Redirection 13
RRC Release message can bring the cell info which it can let cellphone re-direct to.
LTE Redirection
14
LTE Redirection
15
LTE Redirection
16
LTE Redirection 17
Firstly send a TAU reject, then cellphone will send Attach Request, with its IMSI!
LTE Redirection 18
If you send Identity request at the same state, you can also get the cellphone’s IMSI!
Identity Request
LTE Redirection
19
LTE Redirection 20
*Refer to Attach reject module
LTE Redirection 21
Network Optimization Master
LTE Redirection 22
Identity Request Identity response
LTE Redirection 23
DoS attack can directly utilize the cause setting in Attach Reject message.
LTE Redirection 24
Attach Reject message can bring reject cause. Some special causes result in NO service on cellphone.
LTE Redirection 25
redirectCarrierInfo can be inserted into RRC Connection Release message.
LTE Redirection 26
LTE Redirection 27
LTE Redirection 28
LTE Redirection
TSG-RAN WG2/RAN WG3/SA WG3 joint meeting, R3- 060032, 9-13 January 2006
29
LTE Redirection
TSG SA WG3 meeting #45, S3-060833, 31st Oct - 3rd Nov 2006
30
LTE Redirection
base station overloaded.
coming cellphone to redirect to another base station.
base station is light-loaded, the cellphones will blindly and inefficiently search one by one, and then increase the whole network load.
31
Overloaded Base station Overloaded Base station Overloaded Base station Light-loaded Base station
LTE Redirection 32
e.g. Wifi MAC addr tracking
LTE Redirection
33
LTE Redirection
Security Issues and Mitigation Proposals, Liaison Statement from GSMA.
34
LTE Redirection
35
LTE Redirection
36
LTE Redirection
37