MobileAtlas: Geographically Decoupled Measurements in Cellular Networks for Security and Privacy Research
Gabriel K. Gegenhuber, Wilfried Mayer, Edgar R. Weippl, Adrian Dabrowski
摘要
Cellular networks are not merely data access networks to the Internet. Their distinct services and ability to form large complex compounds for roaming purposes make them an attractive research target in their own right. Their promise of providing a consistent service with comparable privacy and security across roaming partners falls apart at close inspection. Thus, there is a need for controlled testbeds and measurement tools for cellular access networks doing justice to the technology's unique structure and global scope. Particularly, such measurements suffer from a combinatorial explosion of operators, mobile plans, and services. To cope with these challenges, we built a framework that geographically decouples the SIM from the cellular modem by selectively connecting both remotely. This allows testing any subscriber with any operator at any modem location within minutes without moving parts. The resulting GSM/UMTS/LTE measurement and testbed platform offers a controlled experimentation environment, which is scalable and cost-effective. The platform is extensible and fully open-sourced, allowing other researchers to contribute locations, SIM cards, and measurement scripts. Using the above framework, our international experiments in commercial networks revealed exploitable inconsistencies in traffic metering, leading to multiple phreaking opportunities, i.e., fare-dodging. We also expose problematic IPv6 firewall configurations, hidden SIM card communication to the home network, and fingerprint dial progress tones to track victims across different roaming networks and countries with voice calls.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Diffie-Hellman Picture Show: Key Exchange Stories from Commercial VoWiFi DeploymentsGabriel Karl Gegenhuber, Florian Holzbauer, Philipp É. Frenzel, Edgar R. Weippl 等USENIX Security 2024 · 被引用 8 次
- Hey there! You are using WhatsApp: Enumerating Three Billion Accounts for Security and PrivacyGabriel K. Gegenhuber, Philipp É. Frenzel, Maximilian Günther, Johanna Ullrich 等NDSS 2026 · 被引用 5 次
- Gotta Detect 'Em All: Fake Base Station and Multi-Step Attack Detection in Cellular NetworksKazi Samin Mubasshir, Imtiaz Karim, Elisa BertinoUSENIX Security 2025
它引用的顶会 Paper6
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- Don't Forget to Lock the Back Door! A Characterization of IPv6 Network Security PolicyJakub Czyz, Matthew J. Luckie, Mark Allman, Michael D. BaileyNDSS 2016 · 被引用 87 次
- Over-The-Top Bypass: Study of a Recent Telephony FraudMerve Sahin, Aurélien FrancillonCCS 2016 · 被引用 21 次
- Sonar: Detecting SS7 Redirection Attacks with Audio-Based Distance BoundingChristian Peeters, Hadi Abdullah, Nolen Scaife, Jasmine D. Bowers 等S&P 2018 · 被引用 20 次
- Insights from operating an IP exchange providerAndra Lutu, Diego Perino, Marcelo Bagnulo, Fabián E. BustamanteSIGCOMM 2021 · 被引用 12 次
相关 Paper
- CITesting: Systematic Testing of Context Integrity Violations in LTE Core NetworksMincheol Son, Kwangmin Kim, Beomseok Oh, CheolJun Park 等CCS 2025
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 被引用 225 次
- Invade the Walled Garden: Evaluating GTP Security in Cellular NetworksYiming Zhang, Tao Wan, Yaru Yang, Haixin Duan 等S&P 2025
- IMS is Not That Secure on Your 5G/4G PhonesJingwen Shi, Sihan Wang, Min-Yue Chen, Guan-Hua Tu 等MobiCom 2024 · 被引用 5 次
- SIMurai: Slicing Through the Complexity of SIM Card Security ResearchTomasz Piotr Lisowski, Merlin Chlosta, Jinjin Wang, Marius MuenchUSENIX Security 2024 · 被引用 10 次
