In this paper, we design a stealthy GSM phone identity catcher. As the GSM protocols do not mandate the authentication of BSes (Base Stations) to MSes (Mobile Stations), fake BSes can be implemented to lure victims to register with and thereby intercept crucial information of the user, including their identities. However, the straightforward implementation of GSM phone identity catcher can be easily perceived by users employing detection software due to such phenomena as phone interface changes and service interruptions. In this paper, we propose several effective mechanisms, such as smart configuration of the fake BSes, quick attachment/detachment and service relay, to make the catching process invisible to users and software. Real world experiments have been conducted and the results prove the efficiency and stealth of our proposed GSM phone identity catcher. We hope our work could help to enhance the effectiveness of IMSI catching attack and thereby alert the industry to design stronger authentication protocol in communication systems.
Changqing XU
Shanghai JiaoTong University
Fan YANG
The Ohio State University
Jin TENG
The Ohio State University
Sumxin JIANG
Shanghai JiaoTong University
The copyright of the original papers published on this site belongs to IEICE. Unauthorized use of the original or translated papers is prohibited. See IEICE Provisions on Copyright for details.
Copy
Changqing XU, Fan YANG, Jin TENG, Sumxin JIANG, "Stealthy Mobile Phone Identity Catcher" in IEICE TRANSACTIONS on Communications,
vol. E98-B, no. 3, pp. 494-501, March 2015, doi: 10.1587/transcom.E98.B.494.
Abstract: In this paper, we design a stealthy GSM phone identity catcher. As the GSM protocols do not mandate the authentication of BSes (Base Stations) to MSes (Mobile Stations), fake BSes can be implemented to lure victims to register with and thereby intercept crucial information of the user, including their identities. However, the straightforward implementation of GSM phone identity catcher can be easily perceived by users employing detection software due to such phenomena as phone interface changes and service interruptions. In this paper, we propose several effective mechanisms, such as smart configuration of the fake BSes, quick attachment/detachment and service relay, to make the catching process invisible to users and software. Real world experiments have been conducted and the results prove the efficiency and stealth of our proposed GSM phone identity catcher. We hope our work could help to enhance the effectiveness of IMSI catching attack and thereby alert the industry to design stronger authentication protocol in communication systems.
URL: https://globals.ieice.org/en_transactions/communications/10.1587/transcom.E98.B.494/_p
Copy
@ARTICLE{e98-b_3_494,
author={Changqing XU, Fan YANG, Jin TENG, Sumxin JIANG, },
journal={IEICE TRANSACTIONS on Communications},
title={Stealthy Mobile Phone Identity Catcher},
year={2015},
volume={E98-B},
number={3},
pages={494-501},
abstract={In this paper, we design a stealthy GSM phone identity catcher. As the GSM protocols do not mandate the authentication of BSes (Base Stations) to MSes (Mobile Stations), fake BSes can be implemented to lure victims to register with and thereby intercept crucial information of the user, including their identities. However, the straightforward implementation of GSM phone identity catcher can be easily perceived by users employing detection software due to such phenomena as phone interface changes and service interruptions. In this paper, we propose several effective mechanisms, such as smart configuration of the fake BSes, quick attachment/detachment and service relay, to make the catching process invisible to users and software. Real world experiments have been conducted and the results prove the efficiency and stealth of our proposed GSM phone identity catcher. We hope our work could help to enhance the effectiveness of IMSI catching attack and thereby alert the industry to design stronger authentication protocol in communication systems.},
keywords={},
doi={10.1587/transcom.E98.B.494},
ISSN={1745-1345},
month={March},}
Copy
TY - JOUR
TI - Stealthy Mobile Phone Identity Catcher
T2 - IEICE TRANSACTIONS on Communications
SP - 494
EP - 501
AU - Changqing XU
AU - Fan YANG
AU - Jin TENG
AU - Sumxin JIANG
PY - 2015
DO - 10.1587/transcom.E98.B.494
JO - IEICE TRANSACTIONS on Communications
SN - 1745-1345
VL - E98-B
IS - 3
JA - IEICE TRANSACTIONS on Communications
Y1 - March 2015
AB - In this paper, we design a stealthy GSM phone identity catcher. As the GSM protocols do not mandate the authentication of BSes (Base Stations) to MSes (Mobile Stations), fake BSes can be implemented to lure victims to register with and thereby intercept crucial information of the user, including their identities. However, the straightforward implementation of GSM phone identity catcher can be easily perceived by users employing detection software due to such phenomena as phone interface changes and service interruptions. In this paper, we propose several effective mechanisms, such as smart configuration of the fake BSes, quick attachment/detachment and service relay, to make the catching process invisible to users and software. Real world experiments have been conducted and the results prove the efficiency and stealth of our proposed GSM phone identity catcher. We hope our work could help to enhance the effectiveness of IMSI catching attack and thereby alert the industry to design stronger authentication protocol in communication systems.
ER -