Sonar: Detecting SS7 Redirection Attacks with Audio-Based Distance Bounding
Christian Peeters, Hadi Abdullah, Nolen Scaife, Jasmine D. Bowers, Patrick Traynor, Bradley Reaves, Kevin R. B. Butler
Abstract
The global telephone network is relied upon by billions every day. Central to its operation is the Signaling System 7 (SS7) protocol, which is used for setting up calls, managing mobility, and facilitating many other network services. This protocol was originally built on the assumption that only a small number of trusted parties would be able to directly communicate with its core infrastructure. As a result, SS7as a feature -allows all parties with core access to redirect and intercept calls for any subscriber anywhere in the world. Unfortunately, increased interconnectivity with the SS7 network has led to a growing number of illicit call redirection attacks. We address such attacks with Sonar, a system that detects the presence of SS7 redirection attacks by securely measuring call audio round-trip times between telephony devices. This approach works because redirection attacks force calls to travel longer physical distances than usual, thereby creating longer end-to-end delay. We design and implement a distance bounding-inspired protocol that allows us to securely characterize the round-trip time between the two endpoints. We then use custom hardware deployed in 10 locations across the United States and a redirection testbed to characterize how distance affects round trip time in phone networks. We develop a model using this testbed and show Sonar is able to detect 70.9% of redirected calls between call endpoints of varying attacker proximity (300-7100 miles) with low false positive rates (0.3%). Finally, we ethically perform actual SS7 redirection attacks on our own devices with the help of an industry partner to demonstrate that Sonar detects 100% of such redirections in a real network (with no false positives). As such, we demonstrate that telephone users can reliably detect SS7 redirection attacks and protect the integrity of their calls.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 601377a9-e5c7-4d55-930b-01036308d102Cited by top-tier papers6
- Pretty Good Phone PrivacyPaul Schmitt, Barath RaghavanUSENIX Security 2021 · 24 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Enforcing End-to-end Security for Remote Conference ApplicationsYuelin Liu, Huangxun Chen, Zhice YangS&P 2024 · 5 citations
- Freaky Leaky SMS: Extracting User Locations by Analyzing SMS TimingsEvangelos Bitsikas, Theodor Schnitzler, Christina Pöpper, Aanjhan RanganathanUSENIX Security 2023
- MobileAtlas: Geographically Decoupled Measurements in Cellular Networks for Security and Privacy ResearchGabriel K. Gegenhuber, Wilfried Mayer, Edgar R. Weippl, Adrian DabrowskiUSENIX Security 2023
Builds on6
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan et al.NDSS 2016 · 342 citations
- Dial One for Scam: A Large-Scale Analysis of Technical Support ScamsNajmeh Miramirkhani, Oleksii Starov, Nick NikiforakisNDSS 2017 · 116 citations
- SoK: Everyone Hates Robocalls: A Survey of Techniques Against Telephone SpamHuahong Tu, Adam Doupé, Ziming Zhao, Gail-Joon AhnS&P 2016 · 90 citations
- New Security Threats Caused by IMS-based SMS Service in 4G LTE NetworksGuan-Hua Tu, Chi-Yu Li, Chunyi Peng, Yuanjie Li et al.CCS 2016 · 60 citations
- AuthentiCall: Efficient Identity and Content Authentication for Phone CallsBradley Reaves, Logan Blue, Hadi Abdullah, Luis Vargas et al.USENIX Security 2017 · 39 citations
Related papers
- Using Sonar for Liveness Detection to Protect Smart Speakers against Remote AttackersYeonjoon Lee, Yue Zhao, Jiutian Zeng, Kwangwuk Lee et al.UbiComp 2020 · 36 citations
- Remote Attacks on Speech Recognition Systems Using Sound from Power SupplyLanqing Yang, Xinqi Chen, Xiangyong Jian, Leping Yang et al.USENIX Security 2023
- The Sounds of the Phones: Dangers of Zero-Effort Second Factor Login based on Ambient AudioBabins Shrestha, Maliheh Shirvanian, Prakash Shrestha, Nitesh SaxenaCCS 2016 · 56 citations
- Jäger: Automated Telephone Call TracebackDavid Adei, Varun Madathil, Sathvik Prasad, Bradley Reaves et al.CCS 2024 · 2 citations
- SurfingAttack: Interactive Hidden Attack on Voice Assistants Using Ultrasonic Guided WavesQiben Yan, Kehai Liu, Qin Zhou, Hanqing Guo et al.NDSS 2020
