首页> 外文会议>IEEE Conference on Communications and Network Security >The Dark Side of Operational Wi-Fi Calling Services
【24h】

The Dark Side of Operational Wi-Fi Calling Services

机译:运营Wi-Fi呼叫服务的阴暗面

获取原文

摘要

All of four major U.S. operators have rolled out nationwide Wi-Fi calling services. They are projected to surpass VoLTE (Voice over LTE) and other VoIP services in terms of mobile IP voice usage minutes in 2018. They enable mobile users to place cellular calls over Wi-Fi networks based on the 3GPP IMS (IP Multimedia Subsystem) technology. Compared with conventional cellular voice solutions, the major difference lies in that their traffic traverses untrustful Wi-Fi networks and the Internet. This exposure to insecure networks may cause the Wi-Fi calling users to suffer from security threats. Its security mechanisms are similar to the VoLTE, because both of them are supported by the IMS. They include SIM-based security, 3GPP AKA (Authentication and Key Agreement), IPSec (Internet Protocol Security), etc. However, are they sufficient to secure Wi–Fi calling services? Unfortunately, our study yields a negative answer. In this work, we explore security issues of the operational Wi-Fi calling services in three major U.S. operators’ networks using commodity devices. We disclose that current Wi-Fi calling security is not bullet-proof. We uncover four vulnerabilities which stem from improper standard designs, device implementation issues and network operation slips. By exploiting them, we devise two proof-of-concept attacks: user privacy leakage and telephony harassment or denial of voice service (THDoS); they can bypass the security defenses deployed on both mobile devices and network infrastructure. We have confirmed their feasibility and simplicity using real-world experiments, as well as assessed their potential damages and proposed recommended solutions.
机译:美国四大运营商都已在全国范围内推出Wi-Fi通话服务。预计在2018年移动IP语音使用分钟数方面,它们将超过VoLTE(LTE上的语音)和其他VoIP服务。它们使移动用户能够基于3GPP IMS(IP多媒体子系统)技术通过Wi-Fi网络拨打蜂窝电话。与传统的蜂窝语音解决方案相比,主要区别在于它们的流量经过不可靠的Wi-Fi网络和Internet。这种不安全网络的暴露可能导致Wi-Fi呼叫用户遭受安全威胁。它的安全机制与VoLTE相似,因为IMS都支持这两种机制。它们包括基于SIM的安全性,3GPP AKA(身份验证和密钥协议),IPSec(Internet协议安全性)等。但是,它们是否足以保护Wi-Fi呼叫服务?不幸的是,我们的研究给出了否定的答案。在这项工作中,我们探索了使用商品设备在美国三大运营商网络中运营Wi-Fi呼叫服务的安全性问题。我们透露目前的Wi-Fi通话安全性不是防弹的。我们发现了四个漏洞,这些漏洞是由不正确的标准设计,设备实施问题和网络操作清单引起的。通过利用它们,我们设计了两种概念验证攻击:用户隐私泄漏和电话骚扰或拒绝语音服务(THDoS);他们可以绕过部署在移动设备和网络基础架构上的安全防御措施。我们已经通过实际实验确认了它们的可行性和简便性,并评估了它们的潜在损害并提出了建议的解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号