Flaws in 4G, 5G Networks Could Let Hackers Intercept Calls, Track Location
February 28, 2019 | Purdue UniversityEstimated reading time: 2 minutes
Newly discovered vulnerabilities in 4G and 5G networks could be used to intercept phone calls and track users’ locations, according to researchers at Purdue University and the University of Iowa.
Not only has 5G promised to be faster than previous generations, but it should also be more secure. That such serious vulnerabilities have been found in the new networks is hardly reassuring – the 5G standard was specifically developed to better protect against these kind of attacks, Wired reports.
“5G is trying to enforce stronger security and privacy policies than predecessors. However, it inherits many of its characteristics from previous generations, so it’s possible that vulnerabilities that exist in those generations will trickle down to 5G,” said Syed Rafiul Hussain, a postdoctoral researcher in computer science at Purdue.
Cellular networks attempt to conserve energy by only scanning for incoming calls, texts and other notifications periodically. The time periods at which the device looks for incoming communications, known as the paging occasion, are fixed; they’re designed into the 4G or 5G cellular protocol. If several calls are placed and cancelled in a short period of time, when the device isn’t scanning for incoming messages, a paging message can be triggered without notifying the device.
In an attack the researchers have dubbed “torpedo,” adversaries can use this paging message to track a victim’s location and then inject fake paging messages and stop calls and texts from coming in. The findings were presented Tuesday at the Network and Distributed Security Symposium in San Diego.
“It doesn’t require an experienced hacker to perform this attack,” Hussain said. “Anyone with a little knowledge of cellular paging protocols could carry it out.”
Torpedo also paves the way for two other attacks: one that allows attackers to obtain a device’s international mobile subscriber identity (IMSI) on 4G networks, and another that allows hackers to obtain a victim’s “soft identities,” such as phone number or Twitter handle, on 4G and 5G networks.
“The IMSI-Cracking attack is a huge blow for 5G because it bypasses the network’s new security policies to protect users' IMSIs from exposure,” Hussain said.
Torpedo can be carried out via the networks of all four major U.S. cellular companies (AT&T, Verizon, Sprint and T-Mobile), according to the paper.
Piercer, the attack that can associate a victim’s phone number with its IMSI and allow for targeted location tracking, will likely soon be fixed by the networks vulnerable to it, Hussain said. The industry group that oversees the development of mobile data standards, GSMA, is working to fix torpedo.
“Unfortunately, their proposed fixes are still vulnerable to the torpedo attack, which could have a lasting effect on the privacy of 5G users,” Hussain said.
Suggested Items
Scientists Propose a New Way to Search for Dark Matter
04/02/2024 | SLAC National Accelerator LaboratoryEver since its discovery, dark matter has remained invisible to scientists, despite the launch of multiple ultra-sensitive particle detector experiments around the world over several decades.
Walmart Acquires Vizio, Set to Overtake Samsung as the Largest TV Brand in the US
02/22/2024 | TrendForceUS retail giant Walmart announced on February 20, that it has acquired smart TV brand Vizio for US$2.3 billion, aiming to accelerate the growth of its advertising business: Walmart Connect. Since its launch in 2021, Walmart Connect has seen double-digit annual growth in both its online and offline retail media advertising ventures. Vizio has been expanding its device ecosystem and its SmartCast TV OS, boasting over 18 million active users, according to TrendForce.
Fiber Optic Cables Effective Way to Detect Tsunamis
02/16/2024 | University of MichiganFiber optic cables that line ocean floors could provide a less expensive, more comprehensive alternative to the current buoys that act as early warning systems for tsunamis, says a University of Michigan researcher.
EIPC Winter Conference 2024, Day 2: A Closer Look at Global Trends
02/14/2024 | Pete Starkey, I-Connect007The opening session of the second day’s conference proceedings focused on global PCB trends and was introduced and moderated by Dr. Michele Stampanoni, vice president of strategic sales and business development at Cicor Group in Switzerland. He opened the session with Dr. Hayao Nakahara’s knowledgeable and enlightening video presentation on the IC substrates industry.
IDTechEx Discusses Whether Fuel Cell Vehicles Will Succeed and What It Would Take
02/12/2024 | PRNewswireThe sales of hydrogen fuel cell cars have largely stalled from 2021 onwards, but does this mean there is no market for fuel cell electric vehicles (FCEVs) in the future, and what is required to make them a success? IDTechEx's report, "