Ghost calls from operational 4G call systems: IMS vulnerability, call DoS attack, and countermeasure
Yu-Han Lu, Chi-Yu Li, Yao-Yu Li, Sandy Hsin-Yu Hsiao, Tian Xie, Guan-Hua Tu, Wei-Xun Chen
Abstract
IMS (IP Multimedia Subsystem) is an essential framework for providing 4G/5G multimedia services. It has been deployed worldwide to support two call services: VoLTE (Voice over LTE) and VoWi-Fi (Voice over Wi-Fi). VoWi-Fi enables telephony calls over the Wi-Fi network to complement VoLTE. In this work, we uncover that the VoWi-Fi signaling session can be hijacked to maliciously manipulate the IMS call operation. An adversary can easily make ghost calls to launch a stealthy call DoS (Denial of Service) attack against specific cellular users. Only phone numbers, but not any malware or network information, are required from the victims. This sophisticated attack harnesses a design defect of the IMS call state machine, but not simply flooding or a crash trigger. To stealthily detect attackable phones at run time, we exploit a vulnerability of the 4G network infrastructure, call information leakage, which we explore using machine learning. We validate these vulnerabilities in operational 4G networks of 4 top-tier carriers across Asia and North America countries with 7 phone brands. Our result shows that the call DoS attack can prevent the victims from receiving incoming calls up to 99.0% time without user awareness. We finally propose and evaluate recommended solutions.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers4
- CellDAM: User-Space, Rootless Detection and Mitigation for 5G Data PlaneZhaowei Tan, Jinghao Zhao, Boyan Ding, Songwu LuNSDI 2023 · 13 citations
- Insecurity of operational cellular IoT service: new vulnerabilities, attacks, and countermeasuresSihan Wang, Guan-Hua Tu, Xinyu Lei, Tian Xie et al.MobiCom 2021 · 12 citations
- IMS is Not That Secure on Your 5G/4G PhonesJingwen Shi, Sihan Wang, Min-Yue Chen, Guan-Hua Tu et al.MobiCom 2024 · 5 citations
- VWAttacker: A Systematic Security Testing Framework for Voice over WiFi User EquipmentsImtiaz Karim, Hyunwoo Lee, Hassan Asghar, Kazi Samin Mubasshir et al.INFOCOM 2026
Related papers
- Call Me Maybe: Eavesdropping Encrypted LTE Calls With ReVoLTEDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperUSENIX Security 2020
- New Security Threats Caused by IMS-based SMS Service in 4G LTE NetworksGuan-Hua Tu, Chi-Yu Li, Chunyi Peng, Yuanjie Li et al.CCS 2016 · 60 citations
- Diffie-Hellman Picture Show: Key Exchange Stories from Commercial VoWiFi DeploymentsGabriel Karl Gegenhuber, Florian Holzbauer, Philipp É. Frenzel, Edgar R. Weippl et al.USENIX Security 2024 · 8 citations
- StealthyIMU: Stealing Permission-protected Private Information From Smartphone Voice Assistant Using Zero-Permission SensorsKe Sun, Chunyu Xia, Songlin Xu, Xinyu ZhangNDSS 2023
- Uncovering insecure designs of cellular emergency services (911)Yiwen Hu, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li et al.MobiCom 2022 · 10 citations
