Breaking LTE on Layer Two
David Rupprecht, Katharina Kohls, Thorsten Holz, Christina Pöpper
Abstract
Long Term Evolution (LTE) is the latest mobile communication standard and has a pivotal role in our information society: LTE combines performance goals with modern security mechanisms and serves casual use cases as well as critical infrastructure and public safety communications. Both scenarios are demanding towards a resilient and secure specification and implementation of LTE, as outages and open attack vectors potentially lead to severe risks. Previous work on LTE protocol security identified crucial attack vectors for both the physical (layer one) and network (layer three) layers. Data link layer (layer two) protocols, however, remain a blind spot in existing LTE security research. In this paper, we present a comprehensive layer two security analysis and identify three attack vectors. These attacks impair the confidentiality and/or privacy of LTE communication. More specifically, we first present a passive identity mapping attack that matches volatile radio identities to longer lasting network identities, enabling us to identify users within a cell and serving as a stepping stone for follow-up attacks. Second, we demonstrate how a passive attacker can abuse the resource allocation as a side channel to perform website fingerprinting that enables the attacker to learn the websites a user accessed. Finally, we present the ALTER attack that exploits the fact that LTE user data is encrypted in counter mode (AES-CTR) but not integrity protected, which allows us to modify the message payload. As a proof-of-concept demonstration, we show how an active attacker can redirect DNS requests and then perform a DNS spoofing attack. As a result, the user is redirected to a malicious website. Our experimental analysis demonstrates the real-world applicability of all three attacks and emphasizes the threat of open attack vectors on LTE layer two protocols. TABLE I OVERVIEW OF LAYER TWO ATTACKS
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fe3e6dbb-9855-4337-8dd5-77ca2c652cc6Cited by top-tier papers45
- 5GReasoner: A Property-Directed Security and Privacy Analysis Framework for 5G Cellular Network ProtocolSyed Rafiul Hussain, Mitziu Echeverria, Imtiaz Karim, Omar Chowdhury et al.CCS 2019 · 188 citations
- Touching the Untouchables: Dynamic Security Analysis of the LTE Control PlaneHongil Kim, Jiho Lee, Eunkyu Lee, Yongdae KimS&P 2019 · 174 citations
- Privacy Attacks to the 4G and 5G Cellular Paging Protocols Using Side Channel InformationSyed Rafiul Hussain, Mitziu Echeverria, Omar Chowdhury, Ninghui Li et al.NDSS 2019 · 160 citations
- AdaptOver: adaptive overshadowing attacks in cellular networksSimon Erni, Martin Kotuliak, Patrick Leu, Marc Roeschlin et al.MobiCom 2022 · 52 citations
- Noncompliance as Deviant Behavior: An Automated Black-box Noncompliance Checker for 4G LTE Cellular DevicesSyed Rafiul Hussain, Imtiaz Karim, Abdullah Al Ishtiaq, Omar Chowdhury et al.CCS 2021 · 41 citations
Builds on3
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan et al.NDSS 2016 · 342 citations
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 225 citations
- GUTI Reallocation Demystified: Cellular Location Tracking with Changing Temporary IdentifierByeongdo Hong, Sangwook Bae, Yongdae KimNDSS 2018 · 90 citations
Related papers
- IMP4GT: IMPersonation Attacks in 4G NeTworksDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperNDSS 2020
- Watching the Watchers: Practical Video Identification Attack in LTE NetworksSangwook Bae, Mincheol Son, Dongkwan Kim, CheolJun Park et al.USENIX Security 2022
- Call Me Maybe: Eavesdropping Encrypted LTE Calls With ReVoLTEDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperUSENIX Security 2020
- CITesting: Systematic Testing of Context Integrity Violations in LTE Core NetworksMincheol Son, Kwangmin Kim, Beomseok Oh, CheolJun Park et al.CCS 2025
- LTrack: Stealthy Tracking of Mobile Phones in LTEMartin Kotuliak, Simon Erni, Patrick Leu, Marc Röschlin et al.USENIX Security 2022
