Abro
64
4G threats were scattered throughout multiple domains of the 4G network, as shown
in Figure 3.4. There were new types or viruses and malware targeting smartphones, in
order to steal user data and passwords. Millions of malicious apps have been developed
to impersonate user games, utility or fake major banking apps. As the install base of the
smartphone operating system went into millions, attackers started identifying vulnerabilities and developed threats accordingly.
With IP core networks, 4G networks were targeted with well‐designed DDoS
(Distributed Denial of Services) attacks to cause a larger impact on the mobile services.
4G LTE security can be divided into multiple domains such as UE, RAN, Core Network
and Internet Services. Individual domain security threats for 4G are covered in the
following sections.
3.2.4.1 LTE UE (User Equipment) Domain Security
Today’s UE are a powerful internet connecting small handheld computers with high
speed CPU (Central Processing Unit) and memory capacity. It serves us in our daily life,
social and financial activities, not only to interact with each other, but to make online
payments and bank transactions. Smartphones are always connected via wireless LAN
or cellular connection and can run an interdependent operating system and software
applications that allow users to access their data anywhere, at any time, and in any place.
A simple vulnerability in the mobile operating system can have a significant impact; as
a reference, a recent “XCODEGHOST” vulnerability found in an iOS tool affected 500
million users [5].
Today, about 87% of the time spent on mobile devices is using apps and at least 24.7%
of mobile apps carry one high risk security flaw [6]. Malicious applications can be downloaded and installed intentionally or accidentally by the users or attackers respectively.
Evolved Packet System
Evolved Packet Core
E-UTRAN
S1-MME
UE
eNodeB-2
Malware
Spyware
Malicious App
Rogue eNodeB
IMSI Catcher
Man-in-the-Middle to
Renegotiate, track UE,
Call Hijack, sniffing
DDoS
Worms
Botnets
S11
S8
S8
Gx
Rx
Internet
SGi
S6a
x2
S-GW
P-GW
PCRF
IPX
4G LTE Security Threat Landscape
IP Svc
(IMS,
PSS)
HSS
MME
S1-U
Figure 3.4 4G end to end security threat landscape.
64
4G threats were scattered throughout multiple domains of the 4G network, as shown
in Figure 3.4. There were new types or viruses and malware targeting smartphones, in
order to steal user data and passwords. Millions of malicious apps have been developed
to impersonate user games, utility or fake major banking apps. As the install base of the
smartphone operating system went into millions, attackers started identifying vulnerabilities and developed threats accordingly.
With IP core networks, 4G networks were targeted with well‐designed DDoS
(Distributed Denial of Services) attacks to cause a larger impact on the mobile services.
4G LTE security can be divided into multiple domains such as UE, RAN, Core Network
and Internet Services. Individual domain security threats for 4G are covered in the
following sections.
3.2.4.1 LTE UE (User Equipment) Domain Security
Today’s UE are a powerful internet connecting small handheld computers with high
speed CPU (Central Processing Unit) and memory capacity. It serves us in our daily life,
social and financial activities, not only to interact with each other, but to make online
payments and bank transactions. Smartphones are always connected via wireless LAN
or cellular connection and can run an interdependent operating system and software
applications that allow users to access their data anywhere, at any time, and in any place.
A simple vulnerability in the mobile operating system can have a significant impact; as
a reference, a recent “XCODEGHOST” vulnerability found in an iOS tool affected 500
million users [5].
Today, about 87% of the time spent on mobile devices is using apps and at least 24.7%
of mobile apps carry one high risk security flaw [6]. Malicious applications can be downloaded and installed intentionally or accidentally by the users or attackers respectively.
Evolved Packet System
Evolved Packet Core
E-UTRAN
S1-MME
UE
eNodeB-2
Malware
Spyware
Malicious App
Rogue eNodeB
IMSI Catcher
Man-in-the-Middle to
Renegotiate, track UE,
Call Hijack, sniffing
DDoS
Worms
Botnets
S11
S8
S8
Gx
Rx
Internet
SGi
S6a
x2
S-GW
P-GW
PCRF
IPX
4G LTE Security Threat Landscape
IP Svc
(IMS,
PSS)
HSS
MME
S1-U
Figure 3.4 4G end to end security threat landscape.
