A Stealthy Location Identification Attack Exploiting Carrier Aggregation in Cellular Networks
Nitya Lakshmanan, Nishant Budhdev, Min Suk Kang, Mun Choon Chan, Jun Han
摘要
We present the SLIC that achieves fine-grained location tracking (e.g., finding indoor walking paths) of targeted cellular user devices in a passive manner. The attack exploits a new side channel in modern cellular systems through a universally available feature called carrier aggregation (CA). CA enables higher cellular data rates by allowing multiple base stations on different carrier frequencies to concurrently transmit to a single user. We discover that a passive adversary can learn the side channel -namely, the number of actively transmitting base stations for any user of interest in the same macrocell. We then show that a time series of this side channel can constitute a highly unique fingerprint of a walking path, which can be used to identify the path taken by a target cellular user. We first demonstrate the collection of the new side channel and a small-scale path identification attack in an existing LTE-A network with up to three CA capability (i.e., three base stations can be coordinated for concurrent transmission), showing the feasibility of SLIC in the current cellular networks. We then emulate a near-future 5G network environment with up to nine CA capability in various multi-story buildings in our institution. SLIC shows up to 98.4% of path-identification accuracy among 100 different walking paths in a large office building. Through testing in various building structures, we confirm that the attack is effective in typical office building environments; e.g., corridors, open spaces. We present complete and partial countermeasures and discuss some practical cell deployment suggestions for 5G networks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Enabling Physical Localization of Uncooperative Cellular DevicesTaekkyung Oh, Sangwook Bae, Junho Ahn, Yonghwa Lee 等MobiCom 2024 · 被引用 4 次
- Passive Multi-Target GUTI Identification via Visual-RF Correlation in LTE NetworksByeongdo Hong, Gunwoo YoonNDSS 2026 · 被引用 1 次
- Small Cell, Big Risk: A Security Assessment of 4G LTE Femtocells in the WildYaru Yang, Yiming Zhang, Tao Wan, Haixin Duan 等NDSS 2026 · 被引用 1 次
- Freaky Leaky SMS: Extracting User Locations by Analyzing SMS TimingsEvangelos Bitsikas, Theodor Schnitzler, Christina Pöpper, Aanjhan RanganathanUSENIX Security 2023
- Invade the Walled Garden: Evaluating GTP Security in Cellular NetworksYiming Zhang, Tao Wan, Yaru Yang, Haixin Duan 等S&P 2025
它引用的顶会 Paper4
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan 等NDSS 2016 · 被引用 342 次
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 被引用 219 次
- Privacy Attacks to the 4G and 5G Cellular Paging Protocols Using Side Channel InformationSyed Rafiul Hussain, Mitziu Echeverria, Omar Chowdhury, Ninghui Li 等NDSS 2019 · 被引用 160 次
- Inferring User Routes and Locations Using Zero-Permission Mobile SensorsSashank Narain, Triet D. Vo-Huu, Kenneth Block, Guevara NoubirS&P 2016 · 被引用 149 次
相关 Paper
- CA++: Enhancing Carrier Aggregation Beyond 5GQianru Li, Zhehui Zhang, Yanbing Liu, Zhaowei Tan 等MobiCom 2023 · 被引用 11 次
- Channel Access Deterrence Attack: An Attack Against Spectrum Coexistence Between NR-U and Wi-Fi in the 5 GHz BandMd. Rashedur Rahman, Moinul HossainINFOCOM 2025 · 被引用 2 次
- U-CIMAN: Uncover Spectrum and User Information in LTE Mobile Access NetworksRui Zou, Wenye WangINFOCOM 2020 · 被引用 4 次
- From 5G Sniffing to Harvesting Leakages of Privacy-Preserving MessengersNorbert Ludant, Pieter Robyns, Guevara NoubirS&P 2023
- Watching the Watchers: Practical Video Identification Attack in LTE NetworksSangwook Bae, Mincheol Son, Dongkwan Kim, CheolJun Park 等USENIX Security 2022
