{"id":4224,"date":"2024-06-27T12:05:00","date_gmt":"2024-06-27T17:05:00","guid":{"rendered":"https:\/\/www.darkreading.com\/mobile-security\/your-phone-s-5g-connection-is-exposed-to-bypass-dos-attacks"},"modified":"2024-06-27T12:05:00","modified_gmt":"2024-06-27T17:05:00","slug":"your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/27\/your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks\/","title":{"rendered":"Your Phone&#8217;s 5G Connection is Vulnerable to Bypass, DoS Attacks"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltbc72880aedd3fc4a\/667d9c4b89e9245d494d875c\/5Gtower_peter_galleghan_alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Mobile devices are at risk of wanton data theft and denial of service, thanks to vulnerabilities in 5G technologies.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At the upcoming Black Hat 2024 in Las Vegas, a team of seven Penn State University researchers will describe how hackers can go beyond sniffing your Internet traffic by literally <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.blackhat.com\/us-24\/briefings\/schedule\/#cracking-the-g-fortress-peering-into-gs-vulnerability-abyss-40620\" rel=\"noopener\">providing your Internet connection to you<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. From there, spying, phishing, and plenty more are all on the table.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s a remarkably accessible form of attack, they say, involving commonly overlooked vulnerabilities and equipment you can buy online for a couple of hundred dollars.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Step 1: Set Up a Fake Base Station\">Step 1: Set Up a Fake Base Station<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When a device first attempts to connect with a mobile network base station, the two undergo an authentication and key agreement (AKA). The device sends a registration request, and the station replies with requests for authentication and security checks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Though the station vets the phone, the phone does not vet the station. Its legitimacy is essentially accepted as a given.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Base stations advertise their presence in a particular area by broadcasting &#8216;hello&#8217; messages every 20 minutes, or 40 minutes, and none of those broadcast messages have authentication, or any kind of security mechanisms,&#8221; explains Penn State research assistant Syed Md Mukit Rashid. &#8220;They&#8217;re just plaintext messages. So there&#8217;s no way that a phone or a device can check whether it&#8217;s coming from a fake tower.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Setting up a fake tower isn&#8217;t as tall a task as it might seem. You just need to mimic a real one using a Raspberry Pi or, even better, a software-defined radio (SDR). As&nbsp;Kai Tu, another Penn State research assistant points out, &#8220;People can purchase them online \u2014 they&#8217;re easy to get. Then you can get some open source software (OSS) to run on it, and this kind of setup can be used as a fake base station.&#8221; Expensive SDRs might cost tens of thousands of dollars, but cheap ones that get the job done are available for only a few hundred.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It might seem counterintuitive that a small contraption could seduce your phone away from an established commercial tower. But a targeted attack with a nearby SDR could provide even greater 5G signal strength than a tower servicing thousands of other people at the same time. &#8220;By their nature, devices try to connect to the best possible cell towers \u2014 that is, the ones providing the highest signal strength,&#8221; Rashid says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Step 2: Exploit a Vulnerability\">Step 2: Exploit a Vulnerability<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Like any security process, AKA can be exploited. In the 5G modem integrated in one popular brand of mobile processor, for example, the researchers found a mishandled security header that an attacker could use to bypass the AKA process entirely.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This processor in question is used in the majority of devices manufactured by two of the world&#8217;s biggest smartphone companies. Dark Reading has agreed to keep its name confidential.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">After having attracted a targeted device, an attacker could use this AKA bypass to return a maliciously crafted &#8220;registration accepted&#8221; message and initiate a connection. At this point the attacker becomes the victim&#8217;s Internet service provider, capable of seeing everything they do on the Web in unencrypted form. They can also engage the victim by, for example, sending a spear phishing SMS message, or redirecting them to malicious sites.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Though AKA bypass was the most severe, the researchers discovered other vulnerabilities that would allow them to determine a device&#8217;s location, and perform denial of service (DoS).<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"How to Secure 5G\">How to Secure 5G<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Penn State researchers have reported all the vulnerabilities they discovered to their respective mobile vendors, which have all since deployed patches.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A more permanent solution, however, would have to begin with <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/middle-easts-5g-acceleration-may-pose-serious-security-issues\" rel=\"noopener\">securing 5G authentication<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. As Rashid says, &#8220;If you want to ensure the authenticity of these broadcast messages, you need to use public key [infrastructure] cryptography (PKI). And deploying PKI is expensive \u2014 you need to update all of the cell towers. And there are some non-technical challenges. For example, who will be the root certificate authority of the public keys?&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s unlikely that such an overhaul will happen any time soon, as 5G systems were knowingly built to transmit messages in plaintext for specific reasons.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It&#8217;s a matter of incentives. Messages are sent in milliseconds, so if you incorporate some kind of cryptographic mechanism, it will increase the computational overhead for the cell tower and for the user device. Computational overhead is also associated with time, so performance-wise it will be a bit slower,&#8221; Rashid explains.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Perhaps the performance incentives outweigh security ones. But whether it be via a fake cell tower, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/researchers-show-how-attackers-can-crack-lte-data-link-layer\" rel=\"noopener\">Stingray device<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, or any other means, &#8220;They all exploit this feature \u2014 the lack of authentication of the initial broadcast messages from the cell towers.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This is the root of all evil,&#8221; Rashid adds.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/mobile-security\/your-phone-s-5g-connection-is-exposed-to-bypass-dos-attacks\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mobile devices are at risk of wanton data theft and<\/p>\n","protected":false},"author":12,"featured_media":4225,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4224","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks.jpg?fit=1825%2C1013&ssl=1",1825,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks.jpg?fit=300%2C167&ssl=1",300,167,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks.jpg?fit=640%2C355&ssl=1",640,355,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks.jpg?fit=640%2C355&ssl=1",640,355,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks.jpg?fit=1536%2C853&ssl=1",1536,853,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks.jpg?fit=1825%2C1013&ssl=1",1825,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks.jpg?fit=1024%2C568&ssl=1",1024,568,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/your-phones-5g-connection-is-vulnerable-to-bypass-dos-attacks.jpg?fit=1825%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4224","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4224"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4224\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4225"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4224"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}