Abro
60
evolution of security threats in terms of the technology architecture, technical
capabilities, services offered, and associated threat vectors.
Mobile networks started witnessing serious threats and challenges immediately after
the introduction of the first generation (also called 1G) of mobile technology and has
kept on growing as a complex and challenging threat landscape. 1G was primarily introduced to offer mobility for voice users. Consumers started witnessing the freedom to
attend and make calls while mobile. Criminals discovered an opportunity and methods to
commit mobile frauds and impersonate the legal subscribers to hack their phone to make
free calls. Cell phone cloning became an industry by making and selling illegal cloned
phones. Some hackers identified new ways to hijack and eavesdrop on the  calls  while
being made, and listen in to the private conversations for various nefarious reasons.
With 2G, the era of message spamming arose in the mobile world. Spamming was
used as a pervasive attack to inject false information or send unwanted marketing
jargon to the mobile users. Message inboxes were occupied with spam messages targeting a certain group or the wider community. Fraudsters used mobile spamming for their
own vicious purposes. Rogue base stations (also called IMSI Catchers) were invented to
intercept mobile traffic by offering fake network authentication.
As the user devices become smart and resourceful, data applications and internet
became the key services offered by mobile service providers in new 3G networks. An
average 3G data connection speed was somewhere between 500 and 700 kbps, which
was sufficient to provide connectivity for internet facing applications. Threat vector in
3G targeted the user phones, computer system and its operating system. Mobile OS
vulnerabilities were exploited, as mobile applications were injected with malicious code
to gain unauthorized access to sensitive personal information, such as contacts, user
passwords and location data. As the data speed increased so did the type of infections
in the shape of malwares and spywares.
LTE was the first time the mobile network was switched to an all IP‐based end‐to‐end
architecture. It helped mobile service providers with speed of innovation, offered new
services and scale, and also increased the threat vector for 4G networks. DDoS
Eavesdrop
Fraud
Voice
1G
2G
3G
5G
4G (LTE, LTE adv)
1970–1980
1990–2004
2004–2010
2011–2015
2020
Voice + Text
V oice + Internet
Voice + Video + Internet
C onnected World
Physical
Spam
Virus
DDoS (Distributed
Denial of Service)
APT(Advance
Persistent Threats)
Mobileware
Cyberwarfare
Espionage
Critical Infrastructure
Threats
Malicious
Apps
Spywares
Rogue Base
Station
Mobile Networks
Security Landscape
Mobile
Generations
Applications
Figure 3.1 Mobile network security landscape.
Précédent

- 102/483

Suivant