FBS-Radar: Uncovering Fake Base Stations at Scale in the Wild
Zhenhua Li, Weiwei Wang, Christo Wilson, Jian Chen, Chen Qian, Taeho Jung, Lan Zhang, Kebin Liu, Xiangyang Li, Yunhao Liu
Abstract
Base stations constitute the basic infrastructure of today's cellular networks. Unfortunately, vulnerabilities in the GSM (2G) network protocol enable the creation of fake base stations (FBSes) that are not authorized by network operators. Criminal gangs are using FBSes to directly attack users by sending spam and fraud SMS messages, even if the users have access to 3G/4G networks. In this paper, we present the design, deployment, and evolution of an FBS detection system called FBS-Radar, based on crowdsourced data of nearly 100M users. In particular, we evaluate five different metrics for identifying FBSes in the wild, and find that FBSes can be precisely identified without sacrificing user privacy. Additionally, we present a novel method for accurately geolocating FBSes while incurring negligible impact on end-user devices. Our system protects users from millions of spam and fraud SMS messages per day, and has helped the authorities arrest hundreds of FBS operators. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a60911bf-1e15-4a86-9242-79acf247152fCited by top-tier papers20
- GUTI Reallocation Demystified: Cellular Location Tracking with Changing Temporary IdentifierByeongdo Hong, Sangwook Bae, Yongdae KimNDSS 2018 · 90 citations
- Privacy-Preserving and Standard-Compatible AKA Protocol for 5GYuchen Wang, Zhenfeng Zhang, Yongquan XieUSENIX Security 2021 · 58 citations
- AdaptOver: adaptive overshadowing attacks in cellular networksSimon Erni, Martin Kotuliak, Patrick Leu, Marc Roeschlin et al.MobiCom 2022 · 52 citations
- A nationwide study on cellular reliability: measurement, analysis, and enhancementsYang Li, Hao Lin, Zhenhua Li, Yunhao Liu et al.SIGCOMM 2021 · 44 citations
- Lies in the Air: Characterizing Fake-base-station Spam Ecosystem in ChinaYiming Zhang, Baojun Liu, Chaoyi Lu, Zhou Li et al.CCS 2020 · 43 citations
Related papers
- Gotta Detect 'Em All: Fake Base Station and Multi-Step Attack Detection in Cellular NetworksKazi Samin Mubasshir, Imtiaz Karim, Elisa BertinoUSENIX Security 2025
- SpiderMon: Towards Using Cell Towers as Illuminating Sources for Keystroke MonitoringKang Ling, Yuntang Liu, Ke Sun, Wei Wang et al.INFOCOM 2020 · 29 citations
- Small Cell, Big Risk: A Security Assessment of 4G LTE Femtocells in the WildYaru Yang, Yiming Zhang, Tao Wan, Haixin Duan et al.NDSS 2026 · 1 citation
- Crowd-GPS-Sec: Leveraging Crowdsourcing to Detect and Localize GPS Spoofing AttacksKai Jansen, Matthias Schäfer, Daniel Moser, Vincent Lenders et al.S&P 2018 · 135 citations
- Preventing Artificially Inflated SMS Attacks through Large-Scale Traffic InspectionJun Ho Huh, Hyejin Shin, Sunwoo Ahn, Hayoon Yi et al.USENIX Security 2025
