(U)SimMonitor: A mobile application for security evaluation of cellular networks

被引:4
作者
Xenakis, Christos [1 ]
Ntantogian, Christoforos [1 ]
Panos, Orestis [1 ]
机构
[1] Univ Piraeus, Dept Digital Syst, Piraeus, Greece
基金
欧盟地平线“2020”;
关键词
Cellular networks; Mobile application; Android; AT commands; Security measurements;
D O I
10.1016/j.cose.2016.03.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The lack of precise directives in 3GPP specifications allows mobile operators to configure and deploy security mechanisms at their sole discretion. This may lead to the adoption of bad security practices and insecure configurations. Based on this observation, this paper presents the design and implementation of a novel mobile application named (U)SimMonitor that captures and analyzes the security policy that a cellular operator enforces, i.e., the invocation and employment of the specified security measures to protect its users. (U)SimMonitor achieves this by executing AT commands to extract network related parameters including encryption keys, identities, and location of users. Using (U)SimMonitor as our basic analysis tool, we have conducted a set of experiments for three mobile operators in Greece in a time period of 9 months. The obtained results allow us to quantify, compare and evaluate their applied security as well as pinpoint a set of generic critical observations. Numerical results and security measurements show that mobile networks have poor security configurations and practices, exposing subscribers to several attacks. (C) 2016 Elsevier Ltd. All rights reserved.
引用
收藏
页码:62 / 78
页数:17
相关论文
共 34 条
  • [1] [Anonymous], 2011, 143020 ETSI TS
  • [2] [Anonymous], 2010, 102221 ETSI TS
  • [3] [Anonymous], 2009, 35201 3GPP TS
  • [4] [Anonymous], 2000, 23912 3GPP TR
  • [5] [Anonymous], 2009, 33102 TS 3GPP
  • [6] [Anonymous], 2012, 27007 3GPP TS
  • [7] [Anonymous], 2014, 44006 3GPP TS
  • [8] [Anonymous], 2009, FUZZING PHONE YOUR P
  • [9] Arapinis M, 21 NETW DISTR SYST S
  • [10] Dunkelman O., 2010, 2010013 CRYPT EPRINT