SMS of death: from analyzing to attacking mobile phones on a large scale

  • Authors:
  • Collin Mulliner;Nico Golde;Jean-Pierre Seifert

  • Affiliations:
  • Security in Telecommunications, Technische Universität Berlin and Deutsche Telekom Laboratories;Security in Telecommunications, Technische Universität Berlin and Deutsche Telekom Laboratories;Security in Telecommunications, Technische Universität Berlin and Deutsche Telekom Laboratories

  • Venue:
  • SEC'11 Proceedings of the 20th USENIX conference on Security
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Mobile communication is an essential part of our daily lives. Therefore, it needs to be secure and reliable. In this paper, we study the security of feature phones, the most common type of mobile phone in the world. We built a framework to analyze the security of SMS clients of feature phones. The framework is based on a small GSM base station, which is readily available on the market. Through our analysis we discovered vulnerabilities in the feature phone platforms of all major manufacturers. Using these vulnerabilities we designed attacks against end-users as well as mobile operators. The threat is serious since the attacks can be used to prohibit communication on a large scale and can be carried out from anywhere in the world. Through further analysis we determined that such attacks are amplified by certain configurations of the mobile network. We conclude our research by providing a set of countermeasures.