Researchers uncover 4G LTE exploits that can be used to spy, spoof and cause panic
Full article597 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Exploits include the ability to spoof or track a victim device’s location, intercept phone calls and messages and even inject fake emergency alerts.
Vulnerabilities in a common wireless telecommunications standard could allow hackers to send a fake emergency alert message to almost anyone’s smartphone.
Researchers from Purdue University and the University of Iowa say they’ve discovered 10 new vulnerabilities in the 4G LTE protocol that can disrupt victims’ devices in several ways. They present the new findings in a paper published last month that showcases a tool they developed in order to detect such vulnerabilities.
Among the new attacks, the researchers highlight an authentication relay attack, which they say allows an attacker to connect to an LTE network while spoofing another existing device’s identity and location. This is done without having legitimate credentials.
“Through this attack the adversary can poison the location of the victim device in the core networks, thus allowing setting up a false alibi or planting fake evidence during a criminal investigation,” the paper says.
The researchers explain that the 4G LTE protocol is an “amalgamation of multiple critical procedures”, each of which requires an “in-depth security and privacy analysis of its own.” Thus, their research tackles the question of whether they can exploit three of these procedures—known as attach, detach and paging—and whether their findings could be implemented by malicious actors.
Other exploits include the ability to track a victim device’s location, intercept phone calls and messages and even inject fake emergency alerts. The researchers say this could create an “artificial emergency”, much like the panic caused by a faulty missile alert that caused a mass scare in Hawaii in January.
The paper presents a tool that the researchers developed to discover these exploits dubbed “LTEInspector.” The paper describes LTEInspector as a model that “lazily” scans a 4G LTE network for certain vulnerabilities.
Given that the main purpose of the paper is to show how LTEInspector works, the researchers say that they don’t dive into how to defend against the attacks they uncovered. They suggested that creating adequate defensive measures would be difficult without a significant overhaul of the 4G LTE infrastructure.
“We deliberately do not discuss defenses for the observed attacks as retrospectively adding security into an existing protocol without breaking backward compatibility often yields band-aid-like-solutions which do not hold up under extreme scrutiny,” the researchers say.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/4g-exploits-spy-spoof-panic/