Uncovering IMS Insecurity via VoWiFi in 4G LTE Networks
碩士 === 國立交通大學 === 資訊科學與工程研究所 === 106 === Cellular networks introduce VoWiFi (Voice over WiFi) to complement conventional cellular calls for weak cellular signals. It allows cellular calls to be made through WiFi. Similar to VoLTE (Voice over LTE), it is enabled by an IMS (IP Multimedia Subsystem) sy...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | en_US |
Published: |
2018
|
Online Access: | http://ndltd.ncl.edu.tw/handle/4dyxmb |
id |
ndltd-TW-106NCTU5394160 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-106NCTU53941602019-05-16T01:24:32Z http://ndltd.ncl.edu.tw/handle/4dyxmb Uncovering IMS Insecurity via VoWiFi in 4G LTE Networks 經由VoWiFi服務發掘4G LTE網路中IMS系統的安全漏洞 Li, Yao-Yu 李曜宇 碩士 國立交通大學 資訊科學與工程研究所 106 Cellular networks introduce VoWiFi (Voice over WiFi) to complement conventional cellular calls for weak cellular signals. It allows cellular calls to be made through WiFi. Similar to VoLTE (Voice over LTE), it is enabled by an IMS (IP Multimedia Subsystem) system in the core network. However, at the end device, VoWiFi is supported fully by the software within the mobile OS but not by the cellular modem. It implies that once the root privilege of the mobile OS can be obtained (e.g., Android), the VoWiFi’s operation and network traffic may be wiretapped and hacked. Such design will expose the IMS system to security threats if the IMS is not well protected. In this work, we examine the IMS insecurity by leveraging two VoWiFi operations: call setup and call voice session. We discover five vulnerabilities totally: SIP forging, no defense against INVITE flooding, multiple outgoing calls, unprotected access to voice session, and no context-aware check of voice packets. We validate them in real cellular networks and identify their root causes. On top of them, we devise three novel attacks: hidden data transmission, cellular call DoS, and emergency hotline DoS. We finally evaluate the damages of the attacks and propose recommended solutions. Li, Chi-Yu 李奇育 2018 學位論文 ; thesis 28 en_US |
collection |
NDLTD |
language |
en_US |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立交通大學 === 資訊科學與工程研究所 === 106 === Cellular networks introduce VoWiFi (Voice over WiFi) to complement conventional cellular calls for weak cellular signals. It allows cellular calls to be made through WiFi. Similar to VoLTE (Voice over LTE), it is enabled by an IMS (IP Multimedia Subsystem) system in the core network. However, at the end device, VoWiFi is supported fully by the software within the mobile OS but not by the cellular modem. It implies that once the root privilege of the mobile OS can be obtained (e.g., Android), the VoWiFi’s operation and network traffic may be wiretapped and hacked. Such design will expose the IMS system to security threats if the IMS is not well protected. In this work, we examine the IMS insecurity by leveraging two VoWiFi operations: call setup and call voice session.
We discover five vulnerabilities totally: SIP forging, no defense against INVITE flooding, multiple outgoing calls, unprotected access to voice session, and no context-aware check of voice packets. We validate them in real cellular networks and identify their root causes. On top of them, we devise three novel attacks: hidden data transmission, cellular call DoS, and emergency hotline DoS. We finally evaluate the damages of the attacks and propose recommended solutions.
|
author2 |
Li, Chi-Yu |
author_facet |
Li, Chi-Yu Li, Yao-Yu 李曜宇 |
author |
Li, Yao-Yu 李曜宇 |
spellingShingle |
Li, Yao-Yu 李曜宇 Uncovering IMS Insecurity via VoWiFi in 4G LTE Networks |
author_sort |
Li, Yao-Yu |
title |
Uncovering IMS Insecurity via VoWiFi in 4G LTE Networks |
title_short |
Uncovering IMS Insecurity via VoWiFi in 4G LTE Networks |
title_full |
Uncovering IMS Insecurity via VoWiFi in 4G LTE Networks |
title_fullStr |
Uncovering IMS Insecurity via VoWiFi in 4G LTE Networks |
title_full_unstemmed |
Uncovering IMS Insecurity via VoWiFi in 4G LTE Networks |
title_sort |
uncovering ims insecurity via vowifi in 4g lte networks |
publishDate |
2018 |
url |
http://ndltd.ncl.edu.tw/handle/4dyxmb |
work_keys_str_mv |
AT liyaoyu uncoveringimsinsecurityviavowifiin4gltenetworks AT lǐyàoyǔ uncoveringimsinsecurityviavowifiin4gltenetworks AT liyaoyu jīngyóuvowififúwùfājué4gltewǎnglùzhōngimsxìtǒngdeānquánlòudòng AT lǐyàoyǔ jīngyóuvowififúwùfājué4gltewǎnglùzhōngimsxìtǒngdeānquánlòudòng |
_version_ |
1719175842411577344 |