Privacy Attacks to the 4G and 5G Cellular Paging Protocols Using Side Channel Information
Syed Rafiul Hussain, Mitziu Echeverria, Omar Chowdhury, Ninghui Li, Elisa Bertino
Abstract
—The cellular paging (broadcast) protocol strives to balance between a cellular device’s energy consumption and quality-of-service by allowing the device to only periodically poll for pending services in its idle, low-power state. For a given cellular device and serving network, the exact time periods when the device polls for services (called the paging occasion ) are fixed by design in the 4G/5G cellular protocol. In this paper, we show that the fixed nature of paging occasions can be exploited by an adversary in the vicinity of a victim to associate the victim’s soft- identity (e.g., phone number, Twitter handle) with its paging occasion, with only a modest cost, through an attack dubbed ToRPEDO . Consequently, ToRPEDO can enable an adversary to verify a victim’s coarse-grained location information, inject fabricated paging messages, and mount denial-of-service attacks. We also demonstrate that, in 4G and 5G, it is plausible for an adversary to retrieve a victim device’s persistent identity (i.e., IMSI) with a brute-force IMSI-Cracking attack while using ToRPEDO as an attack sub-step. Our further investigation on 4G paging protocol deployments also identified an implementation oversight of several network providers which enables the adversary to launch an attack, named PIERCER , for associating a victim’s phone number with its IMSI; subsequently allowing targeted user location tracking. All of our attacks have been validated and evaluated in the wild using commodity hardware and software. We finally discuss potential countermeasures against the presented attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4c167edc-4901-4881-a13e-30f657fab208Cited by top-tier papers27
- 5GReasoner: A Property-Directed Security and Privacy Analysis Framework for 5G Cellular Network ProtocolSyed Rafiul Hussain, Mitziu Echeverria, Imtiaz Karim, Omar Chowdhury et al.CCS 2019 · 188 citations
- AdaptOver: adaptive overshadowing attacks in cellular networksSimon Erni, Martin Kotuliak, Patrick Leu, Marc Roeschlin et al.MobiCom 2022 · 52 citations
- Noncompliance as Deviant Behavior: An Automated Black-box Noncompliance Checker for 4G LTE Cellular DevicesSyed Rafiul Hussain, Imtiaz Karim, Abdullah Al Ishtiaq, Omar Chowdhury et al.CCS 2021 · 41 citations
- Hermes: Unlocking Security Analysis of Cellular Network Protocols by Synthesizing Finite State Machines from Natural Language SpecificationsAbdullah Al Ishtiaq, Sarkar Snigdha Sarathi Das, Syed Md. Mukit Rashid, Ali Ranjbar et al.USENIX Security 2024 · 28 citations
- Pretty Good Phone PrivacyPaul Schmitt, Barath RaghavanUSENIX Security 2021 · 24 citations
Builds on6
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan et al.NDSS 2016 · 342 citations
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 225 citations
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 219 citations
- GUTI Reallocation Demystified: Cellular Location Tracking with Changing Temporary IdentifierByeongdo Hong, Sangwook Bae, Yongdae KimNDSS 2018 · 90 citations
- A Machine Learning Approach to Prevent Malicious Calls over Telephony NetworksHuichen Li, Xiaojun Xu, Chang Liu, Teng Ren et al.S&P 2018 · 48 citations
Related papers
- Invade the Walled Garden: Evaluating GTP Security in Cellular NetworksYiming Zhang, Tao Wan, Yaru Yang, Haixin Duan et al.S&P 2025
- IMP4GT: IMPersonation Attacks in 4G NeTworksDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperNDSS 2020
- IMS is Not That Secure on Your 5G/4G PhonesJingwen Shi, Sihan Wang, Min-Yue Chen, Guan-Hua Tu et al.MobiCom 2024 · 5 citations
- Ghost calls from operational 4G call systems: IMS vulnerability, call DoS attack, and countermeasureYu-Han Lu, Chi-Yu Li, Yao-Yu Li, Sandy Hsin-Yu Hsiao et al.MobiCom 2020 · 16 citations
- Data-plane signaling in cellular IoT: attacks and defenseZhaowei Tan, Boyan Ding, Jinghao Zhao, Yunqi Guo et al.MobiCom 2021 · 13 citations
