SlideShare a Scribd company logo
1 of 44
Download to read offline
4G LTE Man in the Middle
Attack with a Hacked
Femtocell
Xiaodong Zou (aka Seeker)
@xdzou
8/30/2019
Agenda
•Who am I
•4G LTE RAN Security in the Real World
•How to Root a 4G Femtocell
•Man in the Middle Attack with a 4G Femtocell
•Design of HBoS (Hacking Box of S1)
•Q&A
Who Am I
• Hacker and HAM, My Lifelong Hobbies
• Entrepreneur, Educator
• Angel Investor
• Founder and President at HiTeam Institute of Software Engineering
• Seeking for Visiting Research Scholar Opportunity
• Twitter: @xdzou
• Email: zouxd@hiteam.com
• WeChat: 70772177
• Callsign: BD4ET
My Collection of Small Cells
•More than 100 Femtocells,
Pico Cells, Nano Cells,
Micro Cells
•TD-LTE, LTE FDD
•WCDMA, TDS-CDMA
•GSM, CDMA
My Huawei BTS3900 4G LampSite
•BBU 3910
•RHUB 3908
•pRRU 3902
•ETP 48100
•GPS Antenna
Why Purchase So Many Small Cells
•Cheap and Easy to Get
•for Statistics
•Collect Old Versions of Firmwares
•Build Up Telecom Labs for Training and Researching
What I Discovered, in the Real World
•4G Small Cells are easy to get from Taobao.com, but they
rarely work properly
•4G Internet Backhual is hard to get, that's why a proxy
server is needed
Base
Stations
Internet
Backhaul
Private Network
Backhaul
IPSec
Enabled
Default LMT
Password
4G Small Cells 5% 95% 20% 99%
2G/3G Femtocells 90% 10% 95% 95%
Macro Cells 0% 100% <1% 100%
X2
UE eNodeB S-GW P-GW
PCRFMME
IMS
HSS
S1-MME
LTE
Uu
S1-U
S10
S11
S5 SGi
S7 RX+
S6a Ch,
Sx
PCRF: Policy Control and Charging
Rule Function
IMS: IP Multimedia Subsystem
EPC: Evolved Packet Core
SAE: System Architecture Evolution
LTE: Long-Term Evolution
EPS: Evolved Packet System
EPCE-UTRAN
UE: User Equipment
S-GW: Serving Gateway
P-GW: PDN Gateway
MME: Mobility Management Entity
eNB: evolved Node B
HSS: Home Subscriber Server
4G LTE Network Logical Architecture
Small Cell and Backhual Network
Small Cell
Access Network
Backhaul
Network
Residential / SMB
Femtocells
Operator’s Core Network
P-CSCF
MME HSS
S6a
SGiS5
VoLTE, Internet
and other IP
Services
S-GW S11 PDN-GW
S1-MME
S1-U
ACS
SeGW HeNB-GW
• SeGW (Security Gateway): provides authentication of HeNB, secure
tunnelling of communication between HeNB and MME, using IPSec.
• ACS (Auto Configuration Server): managing large number of HeNBs
automatically, using TR-069.
• HeNB-GW (Home eNodeB Gateway): aggregation of S1-MME and/or S1-U.
Why Focus on Small Cells Security
•50%-70% of the cellular traffic is consumed indoors
•Most data applications are expected to be used indoors
•Huge amount of small cells in 5G era
•Very cheap devices, not so secure
•Could be physically touched by attackers
Backhaul of Small Cells
•xPON (GPON, EPON)
• Copper UTP to ONU(Optical Network Unit)
•PTN, IP RAN
• Fiber
• Copper UTP to FOT(Fiber Optical Transceiver)
•Internet
• Copper UTP
Flaws in Small Cells Backhaul
•IPSec is Optional.
• 3GPP TS 33.401: In case the S1 management plane interfaces are
trusted (e.g. physically protected), the use of protection
based on IPsec/IKEv2 or equivalent mechanisms is not needed
•The Pratical Problem:
• xPON is secure, the operators consider it as trusted network.
• Network Cable (Fiber or Copper) from a small cell to the ONU
could be 100 meters, but was ignored by the operators.
• Network traffics in most of the cables are not protected by
IPSec, which means plain text and opened to man-in-the-middle
attack.
Pico Cell: Ericsson ENC-nRBS01
Ericsson ENC-nRBS01: root shell
Ericsson ENC-nRBS01: listening port
Pico Cell: Comba ENB-35
Comba ENB-35: UART root access
Comba ENB-35: gain remote root access
rooted Comba ENB-35: root shell
rooted Comba ENB-35: firmware dir
Pico Cell: ZTE BS8102
rooted ZTE BS8102: root shell
Pico Cell: Huawei BTS3203
Pico Cell: Datang fbs3211/3221
Compromised Femtocell-- SMS
•SMS over NAS
Compromised Femtocell-- SMS
•SMS over IMS
Compromised Femtocell-- VoLTE
•SIP AMR or AMR-WB
Compromised Femtocell-- Internet
•GTP-U
Compromised Femtocell-- IMSI Catcher
•IP
•IMSI
•IMEI
•Location
•VoLTE
• MSISDN
• IMEI
• Cell-ID
• IP
Root a FemtoCell
•Purchase a Working 3G/4G FemtoCell
•Get Root Shell
•Get IPSec Keys
•Eveasdropping Network Traffics
•Man in the Middle Attacks
•Attack Core Network
Tools to Root a FemtoCell (1)
•Digital Meter
•CP2102
•SEGGER J-Link
Tools to Root a FemtoCell (2)
•BUS Pirate
•JTAGulator
•NAND/NOR Flash Programmer + TSOP48/56 Slot
•Soldering Station
Tools to Root a FemtoCell (3)
• TR-069 Server: GenieACS
• Update Firmware
• Upload, Modify Configuration
• IDA Pro, Ghidra
• QEmu
• OpenOCD
• Binwalk
• firmware-mod-kit
• HEX Editor
Compromised Femtocell in a Backpack
•12V Battery Pack
•Internet Access
• Portable 4G WiFi Router:
• with RJ-45 Slot
• Huawei WiFi2 Pro
•Backhaul via Internet
Make a Rooted Femtocell Portable
•The Femtocell Comes with a Internet Backhaul
• Just need a battery pack and a portable 4G router
•Private Backhaul, but Still Working
• Add an Internet Access Point to the Private Backhaul
• Connect more Femtocells to the Core Network?
• Perform some Man-in-the-Middle Attacks?
•Backhaul not Working Anymore
• Build up a test environment with your own core ntwork and USIM
cards, for telecom/IoT security research
Wide Range of Attacking Scenarios
•Not only Femtocell with Private Backhaul
•Any 4G LTE Backhaul without IPSec Protection
• Be able to change the configuration of the eNodeB
• or not
•Rooted 4G Femtocell with IPSec Protection
Hacking the S1 Interface
Protocols in the Backhaul
•User Plane: GTP-U
•Control Plane: SCTP
• S1-AP,form eNodeB to MME
•Network Management: TR-069 (HTTP/HTTPS)
•IPSec Tunnel(from eNodeB to SeGW)
Implant at Backhaul(Hacking Box of S1)
•Dual RJ45 Ports
•USIM Slot
•mini PCI-e 4G Module
•12V Battery Pack or
PoE
Hacking Box of S1: Gateway Mode
•Need to Modify the Configuration of the eNodeB, Change
the IP Address of MME to the Address of HBoS.
•Modify the Source Code of srsLTE.
•Working as a Home eNodeB Gateway Offers Control-Plane
(S1-AP) Aggregation.
•Enables the MME to View the Cluster of Femtocells as a
Single Entity.
•Offers User-Plane (GTP-U) Aggregation Functions.
•Allows the S-GW to view the Cluster of Femtocells as a
Single Entity.
•Perform MitM Attacks on S1-AP and GTP-U.
HeNB Gateway Aggregation
Hacking Box of S1: Transparent Mode
•No Need to Modify the Configuration of the eNodeB.
•MitM Attacks Mainly Focus on User-Plane (GTP-U).
•Can not Provide more eNodeBs to Access the EPC.
•Kernel Module, BPF filters.
The Limitations of HBoS
•Transparent Mode:
• Only User Plane Data Attacks
• No Control Plane Attack
• More eNodeB Access is not Allowed
•Gateway Mode:
• User Plane Attacks
• Limited Control Plane Attacks
Q&A

More Related Content

What's hot

Advanced: 5G Service Based Architecture (SBA)
Advanced: 5G Service Based Architecture (SBA)Advanced: 5G Service Based Architecture (SBA)
Advanced: 5G Service Based Architecture (SBA)3G4G
 
Advanced: 5G NR RRC Inactive State
Advanced: 5G NR RRC Inactive StateAdvanced: 5G NR RRC Inactive State
Advanced: 5G NR RRC Inactive State3G4G
 
Beginners: 5G Terminology (Updated - Feb 2019)
Beginners: 5G Terminology (Updated - Feb 2019)Beginners: 5G Terminology (Updated - Feb 2019)
Beginners: 5G Terminology (Updated - Feb 2019)3G4G
 
5 g ran architcture
5 g ran architcture5 g ran architcture
5 g ran architctureHemraj Kumar
 
VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)
VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)
VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)Vikas Shokeen
 
VoLTE Flows and CS network
VoLTE Flows and CS networkVoLTE Flows and CS network
VoLTE Flows and CS networkKarel Berkovec
 
Advanced: True Fixed-Mobile Convergence (FMC) with 5G
Advanced: True Fixed-Mobile Convergence (FMC) with 5GAdvanced: True Fixed-Mobile Convergence (FMC) with 5G
Advanced: True Fixed-Mobile Convergence (FMC) with 5G3G4G
 
SGSN- serving gprs support node - Platform - HW, SW and CLI
SGSN- serving gprs support node  - Platform - HW, SW and CLI SGSN- serving gprs support node  - Platform - HW, SW and CLI
SGSN- serving gprs support node - Platform - HW, SW and CLI Mustafa Golam
 
5G Network Architecture Options
5G Network Architecture Options5G Network Architecture Options
5G Network Architecture Options3G4G
 
ims registration call flow procedure volte sip
ims registration call flow procedure volte sipims registration call flow procedure volte sip
ims registration call flow procedure volte sipVikas Shokeen
 
EPG PGW SAPC SACC PISC Configuration
EPG PGW SAPC SACC PISC ConfigurationEPG PGW SAPC SACC PISC Configuration
EPG PGW SAPC SACC PISC ConfigurationMustafa Golam
 
High-level architecture of Mobile Cellular Networks from 2G to 5G
High-level architecture of Mobile Cellular Networks from 2G to 5GHigh-level architecture of Mobile Cellular Networks from 2G to 5G
High-level architecture of Mobile Cellular Networks from 2G to 5G3G4G
 
Beginners: 5G Terminology
Beginners: 5G TerminologyBeginners: 5G Terminology
Beginners: 5G Terminology3G4G
 
2G / 3G / 4G / IMS / 5G Overview with Focus on Core Network
2G / 3G / 4G / IMS / 5G Overview with Focus on Core Network2G / 3G / 4G / IMS / 5G Overview with Focus on Core Network
2G / 3G / 4G / IMS / 5G Overview with Focus on Core NetworkHamidreza Bolhasani
 

What's hot (20)

Advanced: 5G Service Based Architecture (SBA)
Advanced: 5G Service Based Architecture (SBA)Advanced: 5G Service Based Architecture (SBA)
Advanced: 5G Service Based Architecture (SBA)
 
Advanced: 5G NR RRC Inactive State
Advanced: 5G NR RRC Inactive StateAdvanced: 5G NR RRC Inactive State
Advanced: 5G NR RRC Inactive State
 
Nokia LTE IP Planning Guide
Nokia LTE IP Planning GuideNokia LTE IP Planning Guide
Nokia LTE IP Planning Guide
 
Beginners: 5G Terminology (Updated - Feb 2019)
Beginners: 5G Terminology (Updated - Feb 2019)Beginners: 5G Terminology (Updated - Feb 2019)
Beginners: 5G Terminology (Updated - Feb 2019)
 
5 g ran architcture
5 g ran architcture5 g ran architcture
5 g ran architcture
 
VoLTE flows - basics
VoLTE flows - basicsVoLTE flows - basics
VoLTE flows - basics
 
VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)
VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)
VoWifi 03 - vowifi epdg aaa and architecture (pdf ppt)
 
VoLTE Flows and CS network
VoLTE Flows and CS networkVoLTE Flows and CS network
VoLTE Flows and CS network
 
LTE Procedures
LTE ProceduresLTE Procedures
LTE Procedures
 
Introduction to LTE
Introduction to LTEIntroduction to LTE
Introduction to LTE
 
Advanced: True Fixed-Mobile Convergence (FMC) with 5G
Advanced: True Fixed-Mobile Convergence (FMC) with 5GAdvanced: True Fixed-Mobile Convergence (FMC) with 5G
Advanced: True Fixed-Mobile Convergence (FMC) with 5G
 
SGSN- serving gprs support node - Platform - HW, SW and CLI
SGSN- serving gprs support node  - Platform - HW, SW and CLI SGSN- serving gprs support node  - Platform - HW, SW and CLI
SGSN- serving gprs support node - Platform - HW, SW and CLI
 
5G Network Architecture Options
5G Network Architecture Options5G Network Architecture Options
5G Network Architecture Options
 
ims registration call flow procedure volte sip
ims registration call flow procedure volte sipims registration call flow procedure volte sip
ims registration call flow procedure volte sip
 
EPG PGW SAPC SACC PISC Configuration
EPG PGW SAPC SACC PISC ConfigurationEPG PGW SAPC SACC PISC Configuration
EPG PGW SAPC SACC PISC Configuration
 
SS7 & SIGTRAN
SS7 & SIGTRANSS7 & SIGTRAN
SS7 & SIGTRAN
 
High-level architecture of Mobile Cellular Networks from 2G to 5G
High-level architecture of Mobile Cellular Networks from 2G to 5GHigh-level architecture of Mobile Cellular Networks from 2G to 5G
High-level architecture of Mobile Cellular Networks from 2G to 5G
 
Cisco ASA Firewalls
Cisco ASA FirewallsCisco ASA Firewalls
Cisco ASA Firewalls
 
Beginners: 5G Terminology
Beginners: 5G TerminologyBeginners: 5G Terminology
Beginners: 5G Terminology
 
2G / 3G / 4G / IMS / 5G Overview with Focus on Core Network
2G / 3G / 4G / IMS / 5G Overview with Focus on Core Network2G / 3G / 4G / IMS / 5G Overview with Focus on Core Network
2G / 3G / 4G / IMS / 5G Overview with Focus on Core Network
 

Similar to 4G LTE Man in the Middle Attack with a Hacked Femtocell

BaiCells Introduction & Product Introduction-EN-vf-updated
BaiCells Introduction & Product Introduction-EN-vf-updatedBaiCells Introduction & Product Introduction-EN-vf-updated
BaiCells Introduction & Product Introduction-EN-vf-updatedJi Hun (Jay) Ko
 
Presentation on Femtocell technology
Presentation on Femtocell technologyPresentation on Femtocell technology
Presentation on Femtocell technologyvijay rastogi
 
6-IoT protocol.pptx
6-IoT protocol.pptx6-IoT protocol.pptx
6-IoT protocol.pptxPratik Gohel
 
Presentatie Alcom - Meetup
Presentatie Alcom - Meetup Presentatie Alcom - Meetup
Presentatie Alcom - Meetup Jesse van Doren
 
zigbee technology
zigbee technology zigbee technology
zigbee technology N.CH Karthik
 
ZyXEL MWC 2015: Mobile Access Solution – Residential/Enterprise/Small Cell So...
ZyXEL MWC 2015: Mobile Access Solution – Residential/Enterprise/Small Cell So...ZyXEL MWC 2015: Mobile Access Solution – Residential/Enterprise/Small Cell So...
ZyXEL MWC 2015: Mobile Access Solution – Residential/Enterprise/Small Cell So...Zyxel Communications Corp.
 
New Catalog of Inter-clouds
New Catalog of Inter-cloudsNew Catalog of Inter-clouds
New Catalog of Inter-cloudsAngle cheung
 
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptxConnecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptxssuser52b751
 
LTE and Satellite: Solutions for Rural and Public Safety Networking
LTE and Satellite: Solutions for Rural and Public Safety NetworkingLTE and Satellite: Solutions for Rural and Public Safety Networking
LTE and Satellite: Solutions for Rural and Public Safety NetworkingSmall Cell Forum
 
Virtualization of motes, gateways and networks new.pptx
Virtualization of motes, gateways and networks new.pptxVirtualization of motes, gateways and networks new.pptx
Virtualization of motes, gateways and networks new.pptxssuserd54a18
 
5. Firetide Next Generation Wireless Infrastructure for City Surveillance.pdf
5. Firetide Next Generation Wireless Infrastructure for City Surveillance.pdf5. Firetide Next Generation Wireless Infrastructure for City Surveillance.pdf
5. Firetide Next Generation Wireless Infrastructure for City Surveillance.pdfPawachMetharattanara
 
IOT Protocols
IOT  Protocols IOT  Protocols
IOT Protocols Nagesh Rao
 
Lemko X4T Outdoor
Lemko X4T OutdoorLemko X4T Outdoor
Lemko X4T OutdoorShaowei Pan
 
ch5-Fog Networks and Cloud Computing
ch5-Fog Networks and Cloud Computingch5-Fog Networks and Cloud Computing
ch5-Fog Networks and Cloud Computingssuser06ea42
 
M2M One & M2M Connectivity - Developing a Cellular IoT or M2M Solution in Aus...
M2M One & M2M Connectivity - Developing a Cellular IoT or M2M Solution in Aus...M2M One & M2M Connectivity - Developing a Cellular IoT or M2M Solution in Aus...
M2M One & M2M Connectivity - Developing a Cellular IoT or M2M Solution in Aus...James Mack
 

Similar to 4G LTE Man in the Middle Attack with a Hacked Femtocell (20)

BaiCells Introduction & Product Introduction-EN-vf-updated
BaiCells Introduction & Product Introduction-EN-vf-updatedBaiCells Introduction & Product Introduction-EN-vf-updated
BaiCells Introduction & Product Introduction-EN-vf-updated
 
Presentation on Femtocell technology
Presentation on Femtocell technologyPresentation on Femtocell technology
Presentation on Femtocell technology
 
6-IoT protocol.pptx
6-IoT protocol.pptx6-IoT protocol.pptx
6-IoT protocol.pptx
 
It's LTE Time!
It's LTE Time!It's LTE Time!
It's LTE Time!
 
Presentatie Alcom - Meetup
Presentatie Alcom - Meetup Presentatie Alcom - Meetup
Presentatie Alcom - Meetup
 
Cyberspace LTE
Cyberspace LTECyberspace LTE
Cyberspace LTE
 
zigbee technology
zigbee technology zigbee technology
zigbee technology
 
Bell4GLTE
Bell4GLTEBell4GLTE
Bell4GLTE
 
ZyXEL MWC 2015: Mobile Access Solution – Residential/Enterprise/Small Cell So...
ZyXEL MWC 2015: Mobile Access Solution – Residential/Enterprise/Small Cell So...ZyXEL MWC 2015: Mobile Access Solution – Residential/Enterprise/Small Cell So...
ZyXEL MWC 2015: Mobile Access Solution – Residential/Enterprise/Small Cell So...
 
New Catalog of Inter-clouds
New Catalog of Inter-cloudsNew Catalog of Inter-clouds
New Catalog of Inter-clouds
 
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptxConnecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
 
LTE and Satellite: Solutions for Rural and Public Safety Networking
LTE and Satellite: Solutions for Rural and Public Safety NetworkingLTE and Satellite: Solutions for Rural and Public Safety Networking
LTE and Satellite: Solutions for Rural and Public Safety Networking
 
Virtualization of motes, gateways and networks new.pptx
Virtualization of motes, gateways and networks new.pptxVirtualization of motes, gateways and networks new.pptx
Virtualization of motes, gateways and networks new.pptx
 
5. Firetide Next Generation Wireless Infrastructure for City Surveillance.pdf
5. Firetide Next Generation Wireless Infrastructure for City Surveillance.pdf5. Firetide Next Generation Wireless Infrastructure for City Surveillance.pdf
5. Firetide Next Generation Wireless Infrastructure for City Surveillance.pdf
 
IOT Protocols
IOT  Protocols IOT  Protocols
IOT Protocols
 
Lemko X4T Outdoor
Lemko X4T OutdoorLemko X4T Outdoor
Lemko X4T Outdoor
 
ch5-Fog Networks and Cloud Computing
ch5-Fog Networks and Cloud Computingch5-Fog Networks and Cloud Computing
ch5-Fog Networks and Cloud Computing
 
lecture10-wireless.pptx
lecture10-wireless.pptxlecture10-wireless.pptx
lecture10-wireless.pptx
 
M2M One & M2M Connectivity - Developing a Cellular IoT or M2M Solution in Aus...
M2M One & M2M Connectivity - Developing a Cellular IoT or M2M Solution in Aus...M2M One & M2M Connectivity - Developing a Cellular IoT or M2M Solution in Aus...
M2M One & M2M Connectivity - Developing a Cellular IoT or M2M Solution in Aus...
 
Wireless personal area networks(PAN)
Wireless personal area networks(PAN)Wireless personal area networks(PAN)
Wireless personal area networks(PAN)
 

More from 3G4G

TechKnowledge Technology Stories - Part 3: Satellites - Our Friends In The Sk...
TechKnowledge Technology Stories - Part 3: Satellites - Our Friends In The Sk...TechKnowledge Technology Stories - Part 3: Satellites - Our Friends In The Sk...
TechKnowledge Technology Stories - Part 3: Satellites - Our Friends In The Sk...3G4G
 
Misc: What are No Mobile Coverage Zones called?
Misc: What are No Mobile Coverage Zones called?Misc: What are No Mobile Coverage Zones called?
Misc: What are No Mobile Coverage Zones called?3G4G
 
TechKnowledge Technology Stories - Part 2: Connecting Everything Everywhere…
TechKnowledge Technology Stories - Part 2: Connecting Everything Everywhere…TechKnowledge Technology Stories - Part 2: Connecting Everything Everywhere…
TechKnowledge Technology Stories - Part 2: Connecting Everything Everywhere…3G4G
 
TechKnowledge Technology Stories - Part 1: Smaller, Faster, Cheaper and More…
TechKnowledge Technology Stories - Part 1: Smaller, Faster, Cheaper and More…TechKnowledge Technology Stories - Part 1: Smaller, Faster, Cheaper and More…
TechKnowledge Technology Stories - Part 1: Smaller, Faster, Cheaper and More…3G4G
 
Beginners: An Quick Introduction to 3GPP
Beginners: An Quick Introduction to 3GPPBeginners: An Quick Introduction to 3GPP
Beginners: An Quick Introduction to 3GPP3G4G
 
Misc: Mobile Technology and Healthcare
Misc: Mobile Technology and HealthcareMisc: Mobile Technology and Healthcare
Misc: Mobile Technology and Healthcare3G4G
 
Should we stop the shutdown of 2G/3G to save lives??
Should we stop the shutdown of 2G/3G to save lives??Should we stop the shutdown of 2G/3G to save lives??
Should we stop the shutdown of 2G/3G to save lives??3G4G
 
Opinion – 5G Reality Check: Speeds
Opinion – 5G Reality Check: SpeedsOpinion – 5G Reality Check: Speeds
Opinion – 5G Reality Check: Speeds3G4G
 
Technology Introduction Series: Edge Computing tutorial.pdf
Technology Introduction Series: Edge Computing tutorial.pdfTechnology Introduction Series: Edge Computing tutorial.pdf
Technology Introduction Series: Edge Computing tutorial.pdf3G4G
 
6G: Potential Use Cases and Enabling Technologies
6G: Potential Use Cases and Enabling Technologies6G: Potential Use Cases and Enabling Technologies
6G: Potential Use Cases and Enabling Technologies3G4G
 
3GPP SON Series: SON Management in HetNets and Enhanced ICIC (eICIC)
3GPP SON Series: SON Management in HetNets and Enhanced ICIC (eICIC)3GPP SON Series: SON Management in HetNets and Enhanced ICIC (eICIC)
3GPP SON Series: SON Management in HetNets and Enhanced ICIC (eICIC)3G4G
 
3GPP SON Series: Energy Savings (ES)
3GPP SON Series: Energy Savings (ES)3GPP SON Series: Energy Savings (ES)
3GPP SON Series: Energy Savings (ES)3G4G
 
3GPP SON Series: Cell Outage Detection and Compensation (COD & COC)
3GPP SON Series: Cell Outage Detection and Compensation (COD & COC)3GPP SON Series: Cell Outage Detection and Compensation (COD & COC)
3GPP SON Series: Cell Outage Detection and Compensation (COD & COC)3G4G
 
3GPP SON Series: Minimization of Drive Testing (MDT)
3GPP SON Series: Minimization of Drive Testing (MDT)3GPP SON Series: Minimization of Drive Testing (MDT)
3GPP SON Series: Minimization of Drive Testing (MDT)3G4G
 
3GPP SON Series: Coverage and Capacity Optimization (CCO)
3GPP SON Series: Coverage and Capacity Optimization (CCO)3GPP SON Series: Coverage and Capacity Optimization (CCO)
3GPP SON Series: Coverage and Capacity Optimization (CCO)3G4G
 
3GPP SON Series: SON in 3GPP Release-10 – Self-healing
3GPP SON Series: SON in 3GPP Release-10 – Self-healing3GPP SON Series: SON in 3GPP Release-10 – Self-healing
3GPP SON Series: SON in 3GPP Release-10 – Self-healing3G4G
 
3GPP SON Series: RACH Optimization
3GPP SON Series: RACH Optimization3GPP SON Series: RACH Optimization
3GPP SON Series: RACH Optimization3G4G
 
3GPP SON Series: Mobility Robustness Optimization (MRO)
3GPP SON Series: Mobility Robustness Optimization (MRO)3GPP SON Series: Mobility Robustness Optimization (MRO)
3GPP SON Series: Mobility Robustness Optimization (MRO)3G4G
 
3GPP SON Series: SON in 3GPP Release-9 – Self-optimization
3GPP SON Series: SON in 3GPP Release-9 – Self-optimization3GPP SON Series: SON in 3GPP Release-9 – Self-optimization
3GPP SON Series: SON in 3GPP Release-9 – Self-optimization3G4G
 
Beginners: Energy Consumption in Mobile Networks - RAN Power Saving Schemes
Beginners: Energy Consumption in Mobile Networks - RAN Power Saving SchemesBeginners: Energy Consumption in Mobile Networks - RAN Power Saving Schemes
Beginners: Energy Consumption in Mobile Networks - RAN Power Saving Schemes3G4G
 

More from 3G4G (20)

TechKnowledge Technology Stories - Part 3: Satellites - Our Friends In The Sk...
TechKnowledge Technology Stories - Part 3: Satellites - Our Friends In The Sk...TechKnowledge Technology Stories - Part 3: Satellites - Our Friends In The Sk...
TechKnowledge Technology Stories - Part 3: Satellites - Our Friends In The Sk...
 
Misc: What are No Mobile Coverage Zones called?
Misc: What are No Mobile Coverage Zones called?Misc: What are No Mobile Coverage Zones called?
Misc: What are No Mobile Coverage Zones called?
 
TechKnowledge Technology Stories - Part 2: Connecting Everything Everywhere…
TechKnowledge Technology Stories - Part 2: Connecting Everything Everywhere…TechKnowledge Technology Stories - Part 2: Connecting Everything Everywhere…
TechKnowledge Technology Stories - Part 2: Connecting Everything Everywhere…
 
TechKnowledge Technology Stories - Part 1: Smaller, Faster, Cheaper and More…
TechKnowledge Technology Stories - Part 1: Smaller, Faster, Cheaper and More…TechKnowledge Technology Stories - Part 1: Smaller, Faster, Cheaper and More…
TechKnowledge Technology Stories - Part 1: Smaller, Faster, Cheaper and More…
 
Beginners: An Quick Introduction to 3GPP
Beginners: An Quick Introduction to 3GPPBeginners: An Quick Introduction to 3GPP
Beginners: An Quick Introduction to 3GPP
 
Misc: Mobile Technology and Healthcare
Misc: Mobile Technology and HealthcareMisc: Mobile Technology and Healthcare
Misc: Mobile Technology and Healthcare
 
Should we stop the shutdown of 2G/3G to save lives??
Should we stop the shutdown of 2G/3G to save lives??Should we stop the shutdown of 2G/3G to save lives??
Should we stop the shutdown of 2G/3G to save lives??
 
Opinion – 5G Reality Check: Speeds
Opinion – 5G Reality Check: SpeedsOpinion – 5G Reality Check: Speeds
Opinion – 5G Reality Check: Speeds
 
Technology Introduction Series: Edge Computing tutorial.pdf
Technology Introduction Series: Edge Computing tutorial.pdfTechnology Introduction Series: Edge Computing tutorial.pdf
Technology Introduction Series: Edge Computing tutorial.pdf
 
6G: Potential Use Cases and Enabling Technologies
6G: Potential Use Cases and Enabling Technologies6G: Potential Use Cases and Enabling Technologies
6G: Potential Use Cases and Enabling Technologies
 
3GPP SON Series: SON Management in HetNets and Enhanced ICIC (eICIC)
3GPP SON Series: SON Management in HetNets and Enhanced ICIC (eICIC)3GPP SON Series: SON Management in HetNets and Enhanced ICIC (eICIC)
3GPP SON Series: SON Management in HetNets and Enhanced ICIC (eICIC)
 
3GPP SON Series: Energy Savings (ES)
3GPP SON Series: Energy Savings (ES)3GPP SON Series: Energy Savings (ES)
3GPP SON Series: Energy Savings (ES)
 
3GPP SON Series: Cell Outage Detection and Compensation (COD & COC)
3GPP SON Series: Cell Outage Detection and Compensation (COD & COC)3GPP SON Series: Cell Outage Detection and Compensation (COD & COC)
3GPP SON Series: Cell Outage Detection and Compensation (COD & COC)
 
3GPP SON Series: Minimization of Drive Testing (MDT)
3GPP SON Series: Minimization of Drive Testing (MDT)3GPP SON Series: Minimization of Drive Testing (MDT)
3GPP SON Series: Minimization of Drive Testing (MDT)
 
3GPP SON Series: Coverage and Capacity Optimization (CCO)
3GPP SON Series: Coverage and Capacity Optimization (CCO)3GPP SON Series: Coverage and Capacity Optimization (CCO)
3GPP SON Series: Coverage and Capacity Optimization (CCO)
 
3GPP SON Series: SON in 3GPP Release-10 – Self-healing
3GPP SON Series: SON in 3GPP Release-10 – Self-healing3GPP SON Series: SON in 3GPP Release-10 – Self-healing
3GPP SON Series: SON in 3GPP Release-10 – Self-healing
 
3GPP SON Series: RACH Optimization
3GPP SON Series: RACH Optimization3GPP SON Series: RACH Optimization
3GPP SON Series: RACH Optimization
 
3GPP SON Series: Mobility Robustness Optimization (MRO)
3GPP SON Series: Mobility Robustness Optimization (MRO)3GPP SON Series: Mobility Robustness Optimization (MRO)
3GPP SON Series: Mobility Robustness Optimization (MRO)
 
3GPP SON Series: SON in 3GPP Release-9 – Self-optimization
3GPP SON Series: SON in 3GPP Release-9 – Self-optimization3GPP SON Series: SON in 3GPP Release-9 – Self-optimization
3GPP SON Series: SON in 3GPP Release-9 – Self-optimization
 
Beginners: Energy Consumption in Mobile Networks - RAN Power Saving Schemes
Beginners: Energy Consumption in Mobile Networks - RAN Power Saving SchemesBeginners: Energy Consumption in Mobile Networks - RAN Power Saving Schemes
Beginners: Energy Consumption in Mobile Networks - RAN Power Saving Schemes
 

Recently uploaded

costume and set research powerpoint presentation
costume and set research powerpoint presentationcostume and set research powerpoint presentation
costume and set research powerpoint presentationphoebematthew05
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Benefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksBenefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksSoftradix Technologies
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Bluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfBluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfngoud9212
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024BookNet Canada
 
Science&tech:THE INFORMATION AGE STS.pdf
Science&tech:THE INFORMATION AGE STS.pdfScience&tech:THE INFORMATION AGE STS.pdf
Science&tech:THE INFORMATION AGE STS.pdfjimielynbastida
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDGMarianaLemus7
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 

Recently uploaded (20)

costume and set research powerpoint presentation
costume and set research powerpoint presentationcostume and set research powerpoint presentation
costume and set research powerpoint presentation
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Benefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksBenefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other Frameworks
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Bluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfBluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdf
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
 
Science&tech:THE INFORMATION AGE STS.pdf
Science&tech:THE INFORMATION AGE STS.pdfScience&tech:THE INFORMATION AGE STS.pdf
Science&tech:THE INFORMATION AGE STS.pdf
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDG
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 

4G LTE Man in the Middle Attack with a Hacked Femtocell

  • 1. 4G LTE Man in the Middle Attack with a Hacked Femtocell Xiaodong Zou (aka Seeker) @xdzou 8/30/2019
  • 2. Agenda •Who am I •4G LTE RAN Security in the Real World •How to Root a 4G Femtocell •Man in the Middle Attack with a 4G Femtocell •Design of HBoS (Hacking Box of S1) •Q&A
  • 3. Who Am I • Hacker and HAM, My Lifelong Hobbies • Entrepreneur, Educator • Angel Investor • Founder and President at HiTeam Institute of Software Engineering • Seeking for Visiting Research Scholar Opportunity • Twitter: @xdzou • Email: zouxd@hiteam.com • WeChat: 70772177 • Callsign: BD4ET
  • 4. My Collection of Small Cells •More than 100 Femtocells, Pico Cells, Nano Cells, Micro Cells •TD-LTE, LTE FDD •WCDMA, TDS-CDMA •GSM, CDMA
  • 5. My Huawei BTS3900 4G LampSite •BBU 3910 •RHUB 3908 •pRRU 3902 •ETP 48100 •GPS Antenna
  • 6. Why Purchase So Many Small Cells •Cheap and Easy to Get •for Statistics •Collect Old Versions of Firmwares •Build Up Telecom Labs for Training and Researching
  • 7. What I Discovered, in the Real World •4G Small Cells are easy to get from Taobao.com, but they rarely work properly •4G Internet Backhual is hard to get, that's why a proxy server is needed Base Stations Internet Backhaul Private Network Backhaul IPSec Enabled Default LMT Password 4G Small Cells 5% 95% 20% 99% 2G/3G Femtocells 90% 10% 95% 95% Macro Cells 0% 100% <1% 100%
  • 8. X2 UE eNodeB S-GW P-GW PCRFMME IMS HSS S1-MME LTE Uu S1-U S10 S11 S5 SGi S7 RX+ S6a Ch, Sx PCRF: Policy Control and Charging Rule Function IMS: IP Multimedia Subsystem EPC: Evolved Packet Core SAE: System Architecture Evolution LTE: Long-Term Evolution EPS: Evolved Packet System EPCE-UTRAN UE: User Equipment S-GW: Serving Gateway P-GW: PDN Gateway MME: Mobility Management Entity eNB: evolved Node B HSS: Home Subscriber Server 4G LTE Network Logical Architecture
  • 9. Small Cell and Backhual Network Small Cell Access Network Backhaul Network Residential / SMB Femtocells Operator’s Core Network P-CSCF MME HSS S6a SGiS5 VoLTE, Internet and other IP Services S-GW S11 PDN-GW S1-MME S1-U ACS SeGW HeNB-GW • SeGW (Security Gateway): provides authentication of HeNB, secure tunnelling of communication between HeNB and MME, using IPSec. • ACS (Auto Configuration Server): managing large number of HeNBs automatically, using TR-069. • HeNB-GW (Home eNodeB Gateway): aggregation of S1-MME and/or S1-U.
  • 10. Why Focus on Small Cells Security •50%-70% of the cellular traffic is consumed indoors •Most data applications are expected to be used indoors •Huge amount of small cells in 5G era •Very cheap devices, not so secure •Could be physically touched by attackers
  • 11. Backhaul of Small Cells •xPON (GPON, EPON) • Copper UTP to ONU(Optical Network Unit) •PTN, IP RAN • Fiber • Copper UTP to FOT(Fiber Optical Transceiver) •Internet • Copper UTP
  • 12. Flaws in Small Cells Backhaul •IPSec is Optional. • 3GPP TS 33.401: In case the S1 management plane interfaces are trusted (e.g. physically protected), the use of protection based on IPsec/IKEv2 or equivalent mechanisms is not needed •The Pratical Problem: • xPON is secure, the operators consider it as trusted network. • Network Cable (Fiber or Copper) from a small cell to the ONU could be 100 meters, but was ignored by the operators. • Network traffics in most of the cables are not protected by IPSec, which means plain text and opened to man-in-the-middle attack.
  • 13. Pico Cell: Ericsson ENC-nRBS01
  • 17. Comba ENB-35: UART root access
  • 18. Comba ENB-35: gain remote root access
  • 19. rooted Comba ENB-35: root shell
  • 20. rooted Comba ENB-35: firmware dir
  • 21. Pico Cell: ZTE BS8102
  • 22. rooted ZTE BS8102: root shell
  • 23. Pico Cell: Huawei BTS3203
  • 24. Pico Cell: Datang fbs3211/3221
  • 29. Compromised Femtocell-- IMSI Catcher •IP •IMSI •IMEI •Location •VoLTE • MSISDN • IMEI • Cell-ID • IP
  • 30. Root a FemtoCell •Purchase a Working 3G/4G FemtoCell •Get Root Shell •Get IPSec Keys •Eveasdropping Network Traffics •Man in the Middle Attacks •Attack Core Network
  • 31. Tools to Root a FemtoCell (1) •Digital Meter •CP2102 •SEGGER J-Link
  • 32. Tools to Root a FemtoCell (2) •BUS Pirate •JTAGulator •NAND/NOR Flash Programmer + TSOP48/56 Slot •Soldering Station
  • 33. Tools to Root a FemtoCell (3) • TR-069 Server: GenieACS • Update Firmware • Upload, Modify Configuration • IDA Pro, Ghidra • QEmu • OpenOCD • Binwalk • firmware-mod-kit • HEX Editor
  • 34. Compromised Femtocell in a Backpack •12V Battery Pack •Internet Access • Portable 4G WiFi Router: • with RJ-45 Slot • Huawei WiFi2 Pro •Backhaul via Internet
  • 35. Make a Rooted Femtocell Portable •The Femtocell Comes with a Internet Backhaul • Just need a battery pack and a portable 4G router •Private Backhaul, but Still Working • Add an Internet Access Point to the Private Backhaul • Connect more Femtocells to the Core Network? • Perform some Man-in-the-Middle Attacks? •Backhaul not Working Anymore • Build up a test environment with your own core ntwork and USIM cards, for telecom/IoT security research
  • 36. Wide Range of Attacking Scenarios •Not only Femtocell with Private Backhaul •Any 4G LTE Backhaul without IPSec Protection • Be able to change the configuration of the eNodeB • or not •Rooted 4G Femtocell with IPSec Protection
  • 37. Hacking the S1 Interface
  • 38. Protocols in the Backhaul •User Plane: GTP-U •Control Plane: SCTP • S1-AP,form eNodeB to MME •Network Management: TR-069 (HTTP/HTTPS) •IPSec Tunnel(from eNodeB to SeGW)
  • 39. Implant at Backhaul(Hacking Box of S1) •Dual RJ45 Ports •USIM Slot •mini PCI-e 4G Module •12V Battery Pack or PoE
  • 40. Hacking Box of S1: Gateway Mode •Need to Modify the Configuration of the eNodeB, Change the IP Address of MME to the Address of HBoS. •Modify the Source Code of srsLTE. •Working as a Home eNodeB Gateway Offers Control-Plane (S1-AP) Aggregation. •Enables the MME to View the Cluster of Femtocells as a Single Entity. •Offers User-Plane (GTP-U) Aggregation Functions. •Allows the S-GW to view the Cluster of Femtocells as a Single Entity. •Perform MitM Attacks on S1-AP and GTP-U.
  • 42. Hacking Box of S1: Transparent Mode •No Need to Modify the Configuration of the eNodeB. •MitM Attacks Mainly Focus on User-Plane (GTP-U). •Can not Provide more eNodeBs to Access the EPC. •Kernel Module, BPF filters.
  • 43. The Limitations of HBoS •Transparent Mode: • Only User Plane Data Attacks • No Control Plane Attack • More eNodeB Access is not Allowed •Gateway Mode: • User Plane Attacks • Limited Control Plane Attacks
  • 44. Q&A