IMS is Not That Secure on Your 5G/4G Phones
Jingwen Shi, Sihan Wang, Min-Yue Chen, Guan-Hua Tu, Tian Xie, Man-Hsin Chen, Yiwen Hu, Chi-Yu Li, Chunyi Peng
Abstract
IMS (IP Multimedia Subsystem) is vital for delivering IP-based multimedia services in mobile networks. Despite constant upgrades by 3GPP over the past two decades to support heterogeneous radio access networks (e.g., 4G LTE, 5G NR, and Wi-Fi) and enhance IMS security, the focus has primarily been on cellular infrastructure. Consequently, IMS security measures on mobile equipment (ME), such as smartphones, lag behind rapid technological advancements. Our study reveals that mandated IMS security measures on ME fail to keep pace, resulting in new vulnerabilities and attack vectors, including denial of service (DoS) across all networks, named SMS source spoofing, and covert communications over Video-over-IMS attacks. All vulnerabilities and proof-of-concept attacks have been experimentally validated in operational 5G/4G networks across various phone models and network operators. Finally, we propose and prototype standard-compliant remedies for these vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 381b0aeb-2d2c-45c5-aeca-cc95d88714fbCited by top-tier papers1
Ask how each one uses itBuilds on5
- New Security Threats Caused by IMS-based SMS Service in 4G LTE NetworksGuan-Hua Tu, Chi-Yu Li, Chunyi Peng, Yuanjie Li et al.CCS 2016 · 60 citations
- Ghost calls from operational 4G call systems: IMS vulnerability, call DoS attack, and countermeasureYu-Han Lu, Chi-Yu Li, Yao-Yu Li, Sandy Hsin-Yu Hsiao et al.MobiCom 2020 · 16 citations
- Insecurity of operational cellular IoT service: new vulnerabilities, attacks, and countermeasuresSihan Wang, Guan-Hua Tu, Xinyu Lei, Tian Xie et al.MobiCom 2021 · 12 citations
- Uncovering insecure designs of cellular emergency services (911)Yiwen Hu, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li et al.MobiCom 2022 · 10 citations
- Call Me Maybe: Eavesdropping Encrypted LTE Calls With ReVoLTEDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperUSENIX Security 2020
Related papers
- Small Cell, Big Risk: A Security Assessment of 4G LTE Femtocells in the WildYaru Yang, Yiming Zhang, Tao Wan, Haixin Duan et al.NDSS 2026 · 1 citation
- Invade the Walled Garden: Evaluating GTP Security in Cellular NetworksYiming Zhang, Tao Wan, Yaru Yang, Haixin Duan et al.S&P 2025
- Instructions Unclear: Undefined Behaviour in Cellular Network SpecificationsDaniel Klischies, Moritz Schloegel, Tobias Scharnowski, Mikhail Bogodukhov et al.USENIX Security 2023
- Vehicle-to-Nothing? Securing C-V2X Against Protocol-Aware DoS AttacksGeoff Twardokus, Hanif RahbariINFOCOM 2022 · 28 citations
- AdaptOver: adaptive overshadowing attacks in cellular networksSimon Erni, Martin Kotuliak, Patrick Leu, Marc Roeschlin et al.MobiCom 2022 · 52 citations
