Preventing SIM Box Fraud Using Device Model Fingerprinting
Beomseok Oh, Junho Ahn, Sangwook Bae, Mincheol Son, Yonghwa Lee, Min Suk Kang, Yongdae Kim
摘要
—SIM boxes have been playing a critical role in the underground ecosystem of international-scale frauds that steal billions of dollars from individual victims and mobile network operators across the globe. Many mitigation schemes have been proposed for these frauds, mainly aiming to detect fraud call sessions; however, one direct approach to this problem—the prevention of the SIM box devices from network use—has not drawn much attention despite its highly anticipated benefit. This is exactly what we aim to achieve in this paper. We propose a simple access control logic that detects when unauthorized SIM boxes use cellular networks for communication. At the heart of our defense proposal is the precise fingerprinting of device models ( e.g. , distinguishing an iPhone 13 from any other smartphone models on the market) and device types ( i.e. , smartphones and IoT devices) without relying on international mobile equipment identity, which can be spoofed easily. We empirically show that fingerprints, which were constructed from network-layer auxiliary information with more than 31K features, are mostly distinct among 85 smartphones and thus can be used to prevent the vast majority of illegal SIM boxes from making unauthorized voice calls. Our proposal, as the very first practical, reliable unauthorized cellular device model detection scheme, greatly simplifies the mitigation against SIM box frauds.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper7
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 被引用 219 次
- Hiding in Plain Signal: Physical Signal Overshadowing Attack on LTEHojoon Yang, Sangwook Bae, Mincheol Son, Hongil Kim 等USENIX Security 2019 · 被引用 127 次
- Cryptanalysis of the GPRS Encryption Algorithms GEA-1 and GEA-2Christof Beierle, Patrick Derbez, Gregor Leander, Gaëtan Leurent 等EUROCRYPT 2021 · 被引用 22 次
- Over-The-Top Bypass: Study of a Recent Telephony FraudMerve Sahin, Aurélien FrancillonCCS 2016 · 被引用 21 次
- DoLTEst: In-depth Downlink Negative Testing Framework for LTE DevicesCheolJun Park, Sangwook Bae, Beomseok Oh, Jiho Lee 等USENIX Security 2022
相关 Paper
- SIMurai: Slicing Through the Complexity of SIM Card Security ResearchTomasz Piotr Lisowski, Merlin Chlosta, Jinjin Wang, Marius MuenchUSENIX Security 2024 · 被引用 10 次
- A Machine Learning Approach to Prevent Malicious Calls over Telephony NetworksHuichen Li, Xiaojun Xu, Chang Liu, Teng Ren 等S&P 2018 · 被引用 48 次
- Understanding and Detecting International Revenue Share FraudMerve Sahin, Aurélien FrancillonNDSS 2021
- SecureSIM: rethinking authentication and access control for SIM/eSIMJinghao Zhao, Boyan Ding, Yunqi Guo, Zhaowei Tan 等MobiCom 2021 · 被引用 18 次
- Ghost calls from operational 4G call systems: IMS vulnerability, call DoS attack, and countermeasureYu-Han Lu, Chi-Yu Li, Yao-Yu Li, Sandy Hsin-Yu Hsiao 等MobiCom 2020 · 被引用 16 次
