Publication | Closed Access
Real Threats to Your Data Bills
28
Citations
26
References
2014
Year
Unknown Venue
Mobile SecurityEngineeringInformation SecurityInformation ForensicsSide-channel AttackHardware SecurityCellular Network OperationsData ScienceWireless SecurityData ManagementPersonal DataAuthentication ProtocolReal ThreatsNetwork SecurityData PrivacyMdc SystemMobile ComputingComputer SciencePrivacyData SecurityCryptographyData RiskSecure Mobile DataData Protection
Secure mobile data charging (MDC) is critical to cellular network operations. It must charge the right user for the right volume that (s)he authorizes to consume (i.e., requirements of authentication, authorization, and accounting (AAA)). In this work, we conduct security analysis of the MDC system in cellular networks. We find that all three can be breached in both design and practice, and identify three concrete vulnerabilities: authentication bypass, authorization fraud and accounting volume inaccuracy. The root causes lie in technology fundamentals of cellular networks and the Internet IP design, as well as imprudent implementations. We devise three showcase attacks to demonstrate that, even simple attacks can easily penetrate the operational 3G/4G cellular networks. We further propose and evaluate defense solutions.
| Year | Citations | |
|---|---|---|
Page 1
Page 1