HomeRapidalertHow hackers could disrupt the operation of a Mobile Telephony Network...

How hackers could disrupt a mobile phone network

c817694a8b48bd3140c1739d62ed794a

Another study by the Digital Systems Security Laboratory of the University of Piraeus has been published. Following recent studies, researchers at the University of Piraeus claim that mobile networks can be disabled by malicious users. By using a technique similar to a distributed denial of service (DDoS) attack on websites, it would be possible to compromise a mobile network and put it out of service.

After detecting vulnerabilities in mobile networks, Mr. Christos Xenakis, assistant professor at the University of Piraeus, and Mr. Christopher Dantoyan, research assistant at the University of Piraeus, adopted this specific method, which has not been tested on a large scale so far. The results of the research were published in a recent issue of the journal Computers & Security.

The DDoS attack on mobile phones involves cloning the identification information from SIM cards and creating duplicate SIM cards on hundreds of thousands of phones. Multiple roaming calls are then made from a great distance relative to the location of the devices.

The attack increases the effort required to verify the identity of a roaming call and deliberately confuses the network with a number that appears to be in hundreds of places at once.

Mr. Xenakis and Mr. Dantoyan report that the total cost of such an attack could be only a few thousand dollars.

Sending the clones

SIM cards have been cloned before. It's an old trick that's been used since the 1990s to make calls while charging someone else. Mobile phone carriers, wanting to protect their customers, have made it harder for malicious users to do so, but it still exists as a possibility.

The attack carried out by researchers Mr. Xenakis and Mr. Dantoyan is a little different from the SIM cloning method, because it does not require all the information of the SIM card to copy it, but only certain information to convince the mobile network software, which will request verification of the SIM card.

To prepare for the attack, a hacker would need to have a device that can collect the International Mobile Subscriber Identity, known as IMSI, numbers from SIM cards of multiple devices.

Mr. Xenakis said it would be possible to create, using commercially available materials, a kind of fake antenna that could collect the IMSI numbers from any device within a short radius. Each IMSI could then be replicated on dozens or hundreds of blank SIM cards.

The mobile network breach point

Authenticating a roaming mobile phone takes time because the host network will need to check with the home network it is on to make sure that the particular phone is legitimate.

When a mobile phone is outside the home network, any call it makes is supported by the nearest network. The provider requires a home location register (HLR), a central database containing the details of each mobile subscriber, in order to allow them to use the local network.

If a mobile phone's identity does not include a database, the local HLRs contact the device's network HLR to determine if the phone is legitimate and authorized. If the user has paid or activated roaming service, the answer is positive and the call is then connected.

However, this verification process usually takes a few seconds. Even if the verification request fails and the call is not connected, the HLR-to-HLR communication and data transfer consumes computing resources.

Normally, this system overload wouldn't be a problem. But the many requests could disrupt a local mobile network.

This is what happened in the New York area during the terrorist attacks of September 11, 2001. Cellular networks, which normally handle hundreds of thousands of calls daily, were unable to cope with this massive volume of simultaneous calls to and from the area, and many people trying to call their loved ones found they could not connect.

Network outage

Mr. Xenakis and Mr. Dantoyan's attack will essentially replicate the system load, but the calls will not even need to be connected, all that will need to be done is to keep an HLR's time with fake roaming call verification requests.

Mr. Xenakis says: “The home network trusts roaming networks. The roaming network cannot check whether you are a legitimate subscriber or not.”

Multiple SIM card copies with identical IMSIs attempt to authenticate simultaneously, so even the home or roaming HLRs can't figure out which phone is legitimate. This drains system resources, because it's not something the mobile network software would expect to deal with.

The hundreds of thousands of fake devices trying to make calls at the same time, as well as the control effort, overwhelms home network servers and causes call denial, or simply denial of service, to legitimate users.

Too difficult or too expensive to make happen?

This type of attack is not something a hacker could pull off in a weekend, and some security researchers believe it may not even be a real threat.

Douglas DePerry, a researcher at Leaf Security Research in Red Bank, NJ, says no one can make money from such an attack. While it could cause a loss of revenue for a telecommunications provider, that might not be enough to attract malicious Internet users.

Karsten Nohl, a mobile network security expert at Security Research Labs in Berlin, said another obstacle would be the expense and effort required to clone a huge number of SIM cards.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS