Security Testing 4G (LTE) Networks
44con 6th September 2012 Martyn Ruks & Nils
1
11/09/2012
Security Testing 4G (LTE) Networks 44con 6th September 2012 Martyn - - PowerPoint PPT Presentation
Security Testing 4G (LTE) Networks 44con 6th September 2012 Martyn Ruks & Nils 1 11/09/2012 Todays Talk Intro to 4G (LTE) Networks Technical Details Attacks and Testing Defences Conclusions 2 11/09/2012 Intro to 4G
44con 6th September 2012 Martyn Ruks & Nils
1
11/09/2012
11/09/2012
2
11/09/2012
3
11/09/2012
4
11/09/2012
5
11/09/2012
6
11/09/2012
7
11/09/2012
8
11/09/2012
9
NodeB Core Network
Internet Base Station
User
Back-End
RNC
11/09/2012
10
UE NB NB SGSN GGSN Internet HSS AuC
RNC
11/09/2012
11
eNodeB EPC
Internet Base Station
User
Back-End
11/09/2012
12
UE eNB eNB MME SGw PGw PCRF Internet HSS
11/09/2012
13
11/09/2012
14
11/09/2012
15
11/09/2012
16
11/09/2012
17
11/09/2012
18
11/09/2012
19
11/09/2012
20
11/09/2012
21
11/09/2012
22
RRC PDCP RLC
11/09/2012
23
IP
11/09/2012
24
IP SCTP
11/09/2012
25
IP GTP-U UDP
11/09/2012
26
IP GTP-C UDP
11/09/2012
27
IP S1AP SCTP
11/09/2012
28
IP X2AP SCTP
11/09/2012
29
11/09/2012
30
11/09/2012
31
11/09/2012
32
11/09/2012
33
11/09/2012
34
11/09/2012
35
11/09/2012
36
11/09/2012
37
11/09/2012
38
11/09/2012
39
11/09/2012
40
11/09/2012
41
eNB UE MME S1AP NAS NAS
11/09/2012
42
eNB UE MME
Spoofed UE Spoofed eNB
11/09/2012
43
eNB MME
S1 Setup S1 Setup Response Attach Request Authentication Request Authentication Response Security Mode
11/09/2012
44
11/09/2012
45
eNB UE SGw GTP IP IP Internet IP
11/09/2012
46
UE IP UDP GTP IP IP UDP GTP eNodeB
11/09/2012
47
eNB UE SGw Internet
IP
GTP
GTP
IP
GTP
IP
GTP
11/09/2012
48
eNB UE SGw Source IP Address (IP) Invalid IP Protocols (IP) GTP Tunnel ID (GTP) Source IP Address (GTP) Destination IP Address (IP) PGw
11/09/2012
49
11/09/2012
50
11/09/2012
51
11/09/2012
52
11/09/2012
53
11/09/2012
54
11/09/2012
55
EPC Internet eNodeB
MME HSS Serving Gateway PDN Gateway
Internet Gateway EPC Switch
11/09/2012
56
11/09/2012
57
11/09/2012
58
11/09/2012
59
11/09/2012
60
11/09/2012
61
@mwrinfosecurity @mwrlabs