17
FOS LTE IMSI CATCHER DOMI

fos lte imsi catchers - H.A.C.K.Catching the IMSI • No more key/security context in UE • UE will initiate attach • It is allowed to ask for its IMSI in an IDENTITY REQUEST •

  • Upload
    others

  • View
    22

  • Download
    0

Embed Size (px)

Citation preview

FOSLTEIMSICATCHERDOMI

WARNING!ThistalkwillbeaboutclassicIMSIcatchers– do

notexpectMITMcalls,dataetc.

GSMIMSIcatcher- recap• CreateafakeBTSwith• highreselectionvalue(C1,C2)• randomlocationareacode

• PhoneswillconnectandinitiateLocationUpdate• ReplywithIdentityRequest(requestIMSI)• AftergettingtheIMSIsendLUReject– cause13oranyotherdependingonyourintention

Whycouldwedothis?Nomutualauthentication,thenetworkisalwaystrusted

Rejectmessagesneedtobeunencrypted

(Sh*tty ornullcryptoalsoleadtoMITMetc.)

LTEArchitecture

EUTRANArchitecturebyCrati underCCBY-SA3.0

INTERNETPSTNPLMN

ChangesinLTE•Mutualauthentication

• Integrityprotection

• Bettercrypto

Procedureimprovements•MostproceduresrequireASsecurityenabled(integrityprotection)• UEsdropnon-protectedmessagesoncetheyhaveestablishedsecuritycontext

•Shouldbefine,right?

Tinylittleprotocolproblem…

TrackingAreaUpdateReject• UEsendsaTrackingAreaUpdateRequest• RogueeNodeB rejectsitwithcause9

3GPPTS24.301-5.5.3.2.5

CatchingtheIMSI• Nomorekey/securitycontextinUE

• UEwillinitiateattach

• ItisallowedtoaskforitsIMSIinanIDENTITYREQUEST

• AftergettingitwesendanATTACHREJECTwithcause#12(TrackingAreanotallowed)

HWandSW• USRPandlaptop•ManyopensourceLTEprojects(thisisAWESOMEbtw):•openLTE•OpenAirInterface• srsLTE andsrsUE• OwnimplementationofMME/corenetwork(pendingrequesttoopensourceit)

RogueeNodeB• Needtosomehow‘lure’UEs• InGSMyoujustneededaneighborcell’sfrequency+highreselectionvalue• InLTEalistoffrequenciesarebroadcastedwiththeirpriorities–>youneedtodecodethelist,andselectthefrequencywiththehighestpriority

ThesePeoplearegreat!*APPLAUSE*• Ravishankar Borgaonkar andAltaf ShaikfordiscoveringtheTAURejectvuln (andmanyotherproblems)inLTE• BenoitMichau forthelibrarymycorenetworkisbasedon• PhilippeLanglois andElvisPfützenreuter forpysctp

•MymentorsduringmyinternshipatQualcomm:KevinRedonandNicoGolde

Q&A

Thankyou!Key-ID:E2712651

Fingerprint:811C3FC3CFCB16E4BAEBF5FB7440DF59E2712651