On the Impact of Rogue Base Stations in 4G/LTE Self Organizing Networks

被引:22
作者
Shaik, Altaf [1 ]
Borgaonkar, Ravishankar [2 ,3 ]
Park, Shinjo [1 ]
Seifert, Jean-Pierre [1 ]
机构
[1] Tech Univ Berlin, Berlin, Germany
[2] Univ Oxford, Oxford, England
[3] SINTEF Digital, Oslo, Norway
来源
WISEC'18: PROCEEDINGS OF THE 11TH ACM CONFERENCE ON SECURITY & PRIVACY IN WIRELESS AND MOBILE NETWORKS | 2018年
基金
欧盟地平线“2020”;
关键词
D O I
10.1145/3212480.3212497
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Mobile network operators choose Self Organizing Network (SON) concept as a cost-effective method to deploy LTE/4G networks and meet user expectations for high quality of service and bandwidth. The main objective of SON is to introduce automation into network management activities and reduce human intervention. SON enabled LTE networks heavily rely on the information acquired from mobile phones to provide self-configuration, self-optimization, and self-healing features. However, mobile phones can be attacked over-the-air using rogue base stations. In this paper, we carefully study SON related LTE/4G security specifications and reveal several vulnerabilities. Our key idea is to introduce a rogue eNodeB that uses legitimate mobile devices as a covert channel to launch attacks against SON enabled LTE networks. We demonstrate low-cost, practical, silent and persistent Denial of Service attacks against the network and end-users by injecting fake measurement and configuration information into the SON system. An active attacker can shut down network services in 2 km(2) area of a city for a certain period of time and also block network services to a selective set of mobile phones in a targeted area of 200 m to 2 km in radius. With the help of low cost tools, we design an experimental setup and evaluate these attacks on commercial networks. We present strategies to mitigate our attacks and outline possible reasons that may explain why these vulnerabilities exist in the system.
引用
收藏
页码:75 / 86
页数:12
相关论文
共 39 条
  • [1] 3GPP, 2019, 3GPP TS 36.300
  • [2] *3GPP, 2011, 36902 3GPP TR
  • [3] 3GPP, 2009, 32500 3GPP
  • [4] 4G Americas, 2013, SELF OPT NETW 3GPP R
  • [5] Airhop communications, POW 4G NETW
  • [6] A Survey of Self Organisation in Future Cellular Networks
    Aliu, Osianoh Glenn
    Imran, Ali
    Imran, Muhammad Ali
    Evans, Barry
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2013, 15 (01): : 336 - 361
  • [7] On Self-Optimization of the Random Access Procedure in 3G Long Term Evolution
    Amirijoo, Mehdi
    Frenger, Pal
    Gunnarsson, Fredrik
    Moe, Johan
    Zetterberg, Kristina
    [J]. 2009 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT - WORKSHOPS, 2009, : 177 - 184
  • [8] [Anonymous], 2017, TS 33899
  • [9] [Anonymous], 2020, 3GPP Standard TS 36.331
  • [10] [Anonymous], 2011, 36401 3GPP TS