Experts found 36 new vulnerabilities in the 4G LTE protocol

Each time the transition to a newer standard of cellular communication means not only an increase in the speed of data exchange, but also allows you to make communication more reliable and protected from unauthorized access. For this, vulnerabilities found in previous protocols are taken, and new methods of security checks are used. In this regard, 5G communication promises to be more reliable than 4G (LTE) communication, which, however, does not exclude the possibility of discovering 5G vulnerabilities in the future. Similarly, the years of 4G operation have not freed this protocol from the discovery of many new vulnerabilities. A recent example to confirm this thesis was a study by South Korean security experts who discovered 4 new dangerous vulnerabilities in the 36G protocol.

Experts found 36 new vulnerabilities in the 4G LTE protocol

Researchers at the Korea Advanced Institute of Science and Technology (KAIST) have applied the same method to finding vulnerabilities in the LTE protocol (network) that is used to find problematic solutions in PC software and serversThis so-called fuzzing method involves attacking (loading) a system with a sequence of incorrect, unexpected, or random data. After the load, the system's response is studied, and defense scenarios or attack escalations are developed. This work can be performed semi-automatically, entrusting the deployment system with the process of transmitting and receiving data, while attack scenarios and analysis of the received data are developed manually. For example, KAIST specialists developed the LTEFuzz utility for testing the security of the LTE protocol and finding vulnerabilities, but they promise not to release it publicly, only to equipment manufacturers and telecom operators.

Experts found 36 new vulnerabilities in the 4G LTE protocol

Over 50 vulnerabilities were discovered using LTEFuzz, 36 of which were completely new. The method made it possible to find 15 already known vulnerabilities, which confirmed the correctness of the chosen technology (if they are known, why were they not closed?). Testing was done on and in collaboration with two unnamed carriers, so regular users weren't affected. And a lot of interesting things were revealed. It was possible to listen to subscribers, read data when exchanging base stations with devices, send fake SMS, block incoming calls, disconnect subscribers from the network, manage traffic and do much more. All vulnerabilities found, including "holes" in the equipment of cellular base stations, were notified by KAIST to vendors and 3GPP and GSMA organizations.




Source: 3dnews.ru
Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster