HomeSecurityFlaws in 4G and 5G allow call monitoring, identifying...

Flaws in 4G and 5G allow call tracking, pinpointing device location

Newly discovered security flaws in 4G and emerging 5G cell networks can be used to monitor phone calls and track the location of mobile devices, researchers say.

5G

The trio of attacks were discovered by a team of academics and are believed to be the first time vulnerabilities affecting both the most widely used wireless cellular technology and what has been hailed as its cutting-edge and more secure successor, according to TechCrunch, which detailed the flaws before their disclosure on Tuesday.

5G is supposed to bring super-fast speeds to mobile devices and low latency, opening the door to technological innovations such as self-driving cars and virtual reality. The new technology is also expected to offer a new level of security, as government agencies use International Mobile Subscriber Identity, or IMSI, collectors to mimic cell towers and spy on phones with older connections.

The researchers' three-layer attack is described in a paper to be presented at the Network and Distributed System Security Symposium in San Diego.

The first attack, called Torpedo, exploits a weakness in the standard paging protocol used to notify phone users of an incoming call or text message before it arrives, the researchers say. Multiple calls made in a short period of time could allow someone nearby to track the device and send fake text messages and launch a denial-of-service attack.

The paper, written by researchers at Purdue University and the University of Iowa, argues that Torpedo lays the groundwork for two additional exploits. It is “reasonable,” they say, for an attacker to gain access to the victim device’s ISMI — GSM Subscriber Identity — with a brute-force attack called IMSI-Cracking. A third attack, called Piercer, allows tracking of the user’s location, they said.

The farms are legal, researchers say.

"All of our attacks have been validated and evaluated using commodity hardware and software," the researchers said in their paper.

This means that even the latest cellular protocol is vulnerable to Stingrays – surveillance tools used by the FBI and police across America to secretly track the locations of cell phones and other mobile devices.

The Torpedo attack can be carried out with radio equipment that costs as little as $200 and affects all four major US wireless carriers, according to researchers at TechCrunch.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS