Mobile Networks Security Landscape 65
These malicious apps can be used to gain stealth access to user personal data and
passwords (stored on the phone) for financial and other criminal gains.
Malwares and worms can be installed to launch an attack on the local user network or
widely target the mobile service provider network, as the smartphone is considered a
trusted network device by mobile service providers.
3.2.4.2 LTE (Remote Access Network) Domain Security
LTE E‐UTRAN can be exploited to gain access to UE locations using its Cell Radio
Network Temporary Identifier (C‐RNTI), while UE resides in a single cell or roams
across multiple cells. This attack can be protected by encrypting the traffic carrying
control signal, and command and confirm messages for C‐RNTI [7].
3.2.4.3 LTE Core Network Domain Security
LTE is designed with an IP‐based end‐to‐end open network architecture that helps simplify the overall network operations, but on the other hand, it opens the mobile network
to IP‐based security threats.
The LTE core network can be a potential target for a distributed denial of service
(DDoS) attack with an impact as large as the loss of network services to millions of
subscribers. DDoS can target critical EPC (Evolved Packet Core) components to cause
a loss of service, such as sending overwhelming authentication and authorization
requests to the HSS database, causing system overflow conditions. A DDoS can be run
against an entire IP network backbone by injecting false routing information or manipulating the network database to cause service downtown. The simplest form of DDoS
attack is the TCP SYN attack, where a network device is sent with millions of false TCP
SYN packets to cause a denial of service condition. Complex DDoS attacks may involve
installation of malware on the affected systems and will require extensive efforts to
mitigate its after effects from the system.
Protection for DDoS can be done through a specialized Anti‐DDoS security system,
or newer network technologies such as Software Defined Network (SDN) can be used
to push security policies through a centralize controller.
3.2.4.4 Security Threat Analysis for 4G
Table 3.1 below covers the detailed threat analysis of common 4G threats, their impact
severity and the probability of threat occurrence:
Protection mechanisms against 4G security threats involve the following measures
and mechanisms:
● Always install authorized apps on your mobile devices.
● Download apps from the vendor app store only.
● Protect app access with a passcode.
● Define a service access policy for each app, i.e. limit location and contact access to
certain app types.
● Enable encryption on mobile devices.
● Business and critical apps should use secure containers to encrypt and control
sensitive data.
● Install antivirus.
● Always keep the operating system patched and updated.
These malicious apps can be used to gain stealth access to user personal data and
passwords (stored on the phone) for financial and other criminal gains.
Malwares and worms can be installed to launch an attack on the local user network or
widely target the mobile service provider network, as the smartphone is considered a
trusted network device by mobile service providers.
3.2.4.2 LTE (Remote Access Network) Domain Security
LTE E‐UTRAN can be exploited to gain access to UE locations using its Cell Radio
Network Temporary Identifier (C‐RNTI), while UE resides in a single cell or roams
across multiple cells. This attack can be protected by encrypting the traffic carrying
control signal, and command and confirm messages for C‐RNTI [7].
3.2.4.3 LTE Core Network Domain Security
LTE is designed with an IP‐based end‐to‐end open network architecture that helps simplify the overall network operations, but on the other hand, it opens the mobile network
to IP‐based security threats.
The LTE core network can be a potential target for a distributed denial of service
(DDoS) attack with an impact as large as the loss of network services to millions of
subscribers. DDoS can target critical EPC (Evolved Packet Core) components to cause
a loss of service, such as sending overwhelming authentication and authorization
requests to the HSS database, causing system overflow conditions. A DDoS can be run
against an entire IP network backbone by injecting false routing information or manipulating the network database to cause service downtown. The simplest form of DDoS
attack is the TCP SYN attack, where a network device is sent with millions of false TCP
SYN packets to cause a denial of service condition. Complex DDoS attacks may involve
installation of malware on the affected systems and will require extensive efforts to
mitigate its after effects from the system.
Protection for DDoS can be done through a specialized Anti‐DDoS security system,
or newer network technologies such as Software Defined Network (SDN) can be used
to push security policies through a centralize controller.
3.2.4.4 Security Threat Analysis for 4G
Table 3.1 below covers the detailed threat analysis of common 4G threats, their impact
severity and the probability of threat occurrence:
Protection mechanisms against 4G security threats involve the following measures
and mechanisms:
● Always install authorized apps on your mobile devices.
● Download apps from the vendor app store only.
● Protect app access with a passcode.
● Define a service access policy for each app, i.e. limit location and contact access to
certain app types.
● Enable encryption on mobile devices.
● Business and critical apps should use secure containers to encrypt and control
sensitive data.
● Install antivirus.
● Always keep the operating system patched and updated.
