Detecting IMSI-Catchers by Characterizing Identity Exposing Messages in Cellular Traffic
Tyler Tucker, Nathaniel Bennett, Martin Kotuliak, Simon Erni, Srdjan Capkun, Kevin R. B. Butler, Patrick Traynor
Abstract
—IMSI-Catchers allow parties other than cellular network providers to covertly track mobile device users. While the research community has developed many tools to combat this problem, current solutions focus on correlated behavior and are therefore subject to substantial false classifications. In this paper, we present a standards-driven methodology that focuses on the messages an IMSI-Catcher must use to cause mobile devices to provide their permanent identifiers. That is, our approach focuses on causal attributes rather than correlated ones. We systematically analyze message flows that would lead to IMSI exposure (most of which have not been previously considered in the research community), and identify 53 messages an IMSI-Catcher can use for its attack. We then perform a measurement study on two continents to characterize the ratio in which connections use these messages in normal operations. We use these benchmarks to compare against open-source IMSI-Catcher implementations and then observe anomalous behavior at a large-scale event with significant media attention. Our analysis strongly implies the presence of an IMSI-Catcher at said public event ( p << 0 . 005 ), thus representing the first publication to provide evidence of the statistical significance of its findings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8469b1cf-f064-4b35-8d9f-0cf64e177d51Cited by top-tier papers1
Ask how each one uses itBuilds on12
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan et al.NDSS 2016 · 342 citations
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 219 citations
- Hiding in Plain Signal: Physical Signal Overshadowing Attack on LTEHojoon Yang, Sangwook Bae, Mincheol Son, Hongil Kim et al.USENIX Security 2019 · 127 citations
- FBS-Radar: Uncovering Fake Base Stations at Scale in the WildZhenhua Li, Weiwei Wang, Christo Wilson, Jian Chen et al.NDSS 2017 · 92 citations
- GUTI Reallocation Demystified: Cellular Location Tracking with Changing Temporary IdentifierByeongdo Hong, Sangwook Bae, Yongdae KimNDSS 2018 · 90 citations
Related papers
- LTrack: Stealthy Tracking of Mobile Phones in LTEMartin Kotuliak, Simon Erni, Patrick Leu, Marc Röschlin et al.USENIX Security 2022
- IMS is Not That Secure on Your 5G/4G PhonesJingwen Shi, Sihan Wang, Min-Yue Chen, Guan-Hua Tu et al.MobiCom 2024 · 5 citations
- Privacy Attacks to the 4G and 5G Cellular Paging Protocols Using Side Channel InformationSyed Rafiul Hussain, Mitziu Echeverria, Omar Chowdhury, Ninghui Li et al.NDSS 2019 · 160 citations
- On the (In)Security of Non-resettable Device Identifiers in Custom Android SystemsZikan Dong, Liu Wang, Guoai Xu, Haoyu WangASE 2025 · 1 citation
- AdaptOver: adaptive overshadowing attacks in cellular networksSimon Erni, Martin Kotuliak, Patrick Leu, Marc Roeschlin et al.MobiCom 2022 · 52 citations
