Demonstration of vulnerabilities in GSM security with USRP B200 and open-source penetration tools

Arusha Dubey, Deepak Vohra, Khyati Vachhani, A.Venkateswara Rao · 2016

This paper showcases the vulnerabilities in the GSM security architecture through implementation of an active attack at the Um interface. The attack was carried out by taking advantage of lack of two-way authentication. A rogue GSM base transceiver system was established using Universal Software Radio Peripheral (USRP) B200 board and OpenBTS. B200 allows relaxation of an external 10 MHz reference signal as opposed to widely used USRP1 and N-series. After establishing rogue BTS, IMSI catch-attack and impersonation of a mobile subscriber to send malicious SMS are executed. Along with OpenBTS, standalone standard applications - Asterisk and smqueue are used for correct routing of messages. The attacks are observed on the TEST network and not the spoofed network so that no infringement is established on security and privacy of the existing GSM subscribers.

Read the paper · More papers on PaperTik