Mobile Networks Security Landscape 63
was not only used to steal the IMSI information, but was also used to sniff the voice
traffic over GSM, and to tap the sensitive user data transmitted over GPRS and EDGE.
An attacker could easily copy the user internet traffic and extract the information such
as the password through analyzers. Interestingly, the tools required to launch a GSM
MitM attack are readily available on the market, that is, a regular BTS (Base Transceiver
Station) and open source software OSMOCOMBB.
2G also introduced encryption on a limited scale to protect the traffic between
user equipment and base station. Although it was unable to fully protect against cryptanalytics attacks, it was able to provide some basic encryption protection for signaling
and user data.
Other common security threats were in the form of mobile short messaging spam
traffic for false advertising and marketing.
3.2.3 Security Threats and Protection for 3G
Mobile network third generation (3G) decided to baseline its security following
the CIA (Confidentiality, Integrity and Availability) framework. As a result, the AKA
(Authentication and Key Agreement) protocol was adopted for two‐way authentication
between user equipment and the network, and also to protect against attacks, such as
rogue base stations. AKA used strong 128 bit auth keys and hash functions to maintain the
authenticity and integrity of signaling messages sent over the radio.
Even though two‐way authentication reduced the chances of such attacks, attacks
such as MitM would were still possible in the UMTS environment using such advanced
tools like mobile jammers and OSMOCOMBB.
As 3G was designed to offer the next generation of data services and Internet
connectivity for mobile users, new challenges and vulnerabilities were introduced to the
system.
Mobile networks transitioned to a packet switching model, IP‐based RAN (Radio
Access Network) and IP Core network, and these changes unleashed the IP‐based
threat vector that had not been present in previous generations of mobile networks.
Mobile devices were replaced with small‐sized computers called smartphones, which
became host to typical OS vulnerabilities and weaknesses. Smartphones now required
regular patching and updates against system vulnerabilities, as any failure will expose
the phone to threats by attackers who can exploit the vulnerabilities to leaked data or
install viruses and spywares.
Installation of unauthorized or malicious application caused phones to be hacked and
were sometimes used to degrade the mobile service providers’ service performance and
attack the network. Some phone manufacturers were able to implement a strict application security policy for a centralized app store, but others found it hard to cope with the
ever‐growing number of malicious codes hosted on their app store platform.
3.2.4 Security Threats and Protection for 4G
4G LTE and LTE Adv. has overall introduced a great leap and evolution to the mobile
network performance and throughput. It offers voice, data, video and internet services
through a common mobile architecture.
was not only used to steal the IMSI information, but was also used to sniff the voice
traffic over GSM, and to tap the sensitive user data transmitted over GPRS and EDGE.
An attacker could easily copy the user internet traffic and extract the information such
as the password through analyzers. Interestingly, the tools required to launch a GSM
MitM attack are readily available on the market, that is, a regular BTS (Base Transceiver
Station) and open source software OSMOCOMBB.
2G also introduced encryption on a limited scale to protect the traffic between
user equipment and base station. Although it was unable to fully protect against cryptanalytics attacks, it was able to provide some basic encryption protection for signaling
and user data.
Other common security threats were in the form of mobile short messaging spam
traffic for false advertising and marketing.
3.2.3 Security Threats and Protection for 3G
Mobile network third generation (3G) decided to baseline its security following
the CIA (Confidentiality, Integrity and Availability) framework. As a result, the AKA
(Authentication and Key Agreement) protocol was adopted for two‐way authentication
between user equipment and the network, and also to protect against attacks, such as
rogue base stations. AKA used strong 128 bit auth keys and hash functions to maintain the
authenticity and integrity of signaling messages sent over the radio.
Even though two‐way authentication reduced the chances of such attacks, attacks
such as MitM would were still possible in the UMTS environment using such advanced
tools like mobile jammers and OSMOCOMBB.
As 3G was designed to offer the next generation of data services and Internet
connectivity for mobile users, new challenges and vulnerabilities were introduced to the
system.
Mobile networks transitioned to a packet switching model, IP‐based RAN (Radio
Access Network) and IP Core network, and these changes unleashed the IP‐based
threat vector that had not been present in previous generations of mobile networks.
Mobile devices were replaced with small‐sized computers called smartphones, which
became host to typical OS vulnerabilities and weaknesses. Smartphones now required
regular patching and updates against system vulnerabilities, as any failure will expose
the phone to threats by attackers who can exploit the vulnerabilities to leaked data or
install viruses and spywares.
Installation of unauthorized or malicious application caused phones to be hacked and
were sometimes used to degrade the mobile service providers’ service performance and
attack the network. Some phone manufacturers were able to implement a strict application security policy for a centralized app store, but others found it hard to cope with the
ever‐growing number of malicious codes hosted on their app store platform.
3.2.4 Security Threats and Protection for 4G
4G LTE and LTE Adv. has overall introduced a great leap and evolution to the mobile
network performance and throughput. It offers voice, data, video and internet services
through a common mobile architecture.
