LTE Is Vulnerable: Implementing Identity Spoofing and Denial-of-Service Attacks in LTE Networks
Teng Fei, Wenye Wang · 2019
Recent years have witnessed the rapid growth of mobile users, which further accelerates the deployment of mobile communication networks, especially LTE networks, due to its high data rate, as well as comprehensive functionality. Compared to its predecessors, LTE networks have incorporated a number of security measures specified by 3GPP, including amalgamation of temporary identities, mutual authentication, and enhanced signaling procedures, which are meant to protect the system and individual subscribers against various forms of attacks. However, as we show in this paper, flaws in real-world implementation render commercial LTE systems vulnerable to several attacks, including identity spoofing and denial-of-service (DoS), which have severe impacts on subscriber's data integrity, QoS, and even privacy. Specifically, we identify the vulnerabilities by carefully analyzing LTE specifications, list possible attacks targeting these vulnerabilities, and successfully implement two attacks on a commercial LTE network with a USRP-based testbed. Our work reveals severe security risks in real-world LTE systems, which call for immediate enhancement from both standardization organizations and cellular service providers.