VWAttacker: A Systematic Security Testing Framework for Voice over WiFi User Equipments
Imtiaz Karim, Hyunwoo Lee, Hassan Asghar, Kazi Samin Mubasshir, Seulgi Han, Mashroor Hasan Bhuiyan, Elisa Bertino
Abstract
We present VWAttacker, the first systematic testing framework for analyzing the security of Voice over WiFi (VoWiFi) User Equipment (UE) implementations. VWAttacker includes a complete VoWiFi network testbed that communicates with Commercial-Off-The-Shelf (COTS) UEs based on a simple interface to test the behavior of diverse VoWiFi UE implementations; uses property-guided adversarial testing to uncover security issues in different UEs systematically. To reduce manual effort in extracting and testing properties, we introduce an LLM-based, semi-automatic, and scalable approach for property extraction and testcase (TC) generation. These TCs are systematically mutated by two domain-specific transformations. Furthermore, we introduce two deterministic oracles to detect property violations automatically. Coupled with these techniques, VWAttacker extracts 63 properties from 11 specifications, evaluates 1,116 testcases, and detects 13 issues in 21 UEs. The issues range from enforcing a DH shared secret to 0 to supporting weak algorithms. These issues result in attacks that expose the victim UE's identity or establish weak channels, thus severely hampering the security of cellular networks. We responsibly disclose the findings to all the related vendors. At the time of writing, one of the vulnerabilities has been acknowledged by MediaTek with high severity.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cd69ac59-b235-4ab5-8f9a-bc1e4f1f9524Builds on12
- Retrieval-Augmented Generation for Knowledge-Intensive NLP TasksPatrick Lewis, Ethan Perez, Aleksandra Piktus, Fabio Petroni et al.NeurIPS 2020 · 19,162 citations
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic et al.CCS 2018 · 428 citations
- Touching the Untouchables: Dynamic Security Analysis of the LTE Control PlaneHongil Kim, Jiho Lee, Eunkyu Lee, Yongdae KimS&P 2019 · 174 citations
- Bookworm Game: Automatic Discovery of LTE Vulnerabilities Through Documentation AnalysisYi Chen, Yepeng Yao, XiaoFeng Wang, Dandan Xu et al.S&P 2021 · 57 citations
- From One Thousand Pages of Specification to Unveiling Hidden Bugs: Large Language Model Assisted Fuzzing of Matter IoT DevicesXiaoyue Ma, Lannan Luo, Qiang ZengUSENIX Security 2024 · 49 citations
Related papers
- Diffie-Hellman Picture Show: Key Exchange Stories from Commercial VoWiFi DeploymentsGabriel Karl Gegenhuber, Florian Holzbauer, Philipp É. Frenzel, Edgar R. Weippl et al.USENIX Security 2024 · 8 citations
- Ghost calls from operational 4G call systems: IMS vulnerability, call DoS attack, and countermeasureYu-Han Lu, Chi-Yu Li, Yao-Yu Li, Sandy Hsin-Yu Hsiao et al.MobiCom 2020 · 16 citations
- DoLTEst: In-depth Downlink Negative Testing Framework for LTE DevicesCheolJun Park, Sangwook Bae, Beomseok Oh, Jiho Lee et al.USENIX Security 2022
- State Machine Mutation-based Testing Framework for Wireless Communication ProtocolsSyed Md. Mukit Rashid, Tianwei Wu, Kai Tu, Abdullah Al Ishtiaq et al.CCS 2024 · 4 citations
- CITesting: Systematic Testing of Context Integrity Violations in LTE Core NetworksMincheol Son, Kwangmin Kim, Beomseok Oh, CheolJun Park et al.CCS 2025
