GSM security
GSM security feature consist of
- Authentication - network operator can verify the identity of the subscriber making it infeasible to clone someone else’s mobile phone
- Confidentiality - protects voice, data and sensitive signalling information (e.g. dialled digits) against eavesdropping on the radio path
- Anonymity - protects against someone tracking the location of the user or identifying calls made to or from the user by eavesdropping on the radio path
· GSM security Treats
• Only provides access security – communications and signalling traffic in the fixed network are not protected.
• Does not address active attacks, whereby some network elements (e.g. BTS: Base Station)
• Only as secure as the fixed networks to which they connect
• Lawful interception only considered as an after-thought
• Terminal identity cannot be trusted
• Difficult to upgrade the cryptographic mechanisms
• Lack of user visibility (e.g. doesn’t know if encrypted or not)
And this will lead to
• Eavesdropping. This is the capability that the intruder eavesdrops signalling and data connections associated with other users. The required equipment is a modified MS.
• Impersonation of a user. This is the capability whereby the intruder sends signalling and/or user data to the network, in an attempt to make the network believe they originate from the target user. The required equipment is again a modified MS.
• Impersonation of the network. This is the capability whereby the intruder sends signalling and/or user data to the target user, in an attempt to make the target user believe they originate from a genuine network. The required equipment is modified BTS.
GPRS Security features
Security services are protections and assurances that provide mitigation against various threats. They
are generally known as:
- Integrity - is a security service that assures that data cannot be altered in an unauthorized or malicious manner.
- Confidentiality - is the protection of data from disclosure to third parties.
- Authentication - provides assurance that a party in data communication is who or what they claim to be.
- Authorization - is a security service that ensures that a party may only perform the actions that they’re allowed to perform
- Availability - means that data services are usable by the appropriate parties in the manner intended.
GPRS treats
Confidentiality
There is no protection of data from an MS to the public data network or corporate network. It is assumed that data can be seen by third parties if IP Security or application layer security is not being used.
Integrity
Data sent over public data networks can potentially be changed by intermediaries unless higher layer security is being used.
Authentication and Authorization
Unless layer 2 or layer 3 tunnels are used at the GGSN to the corporate network, it may be possible for one MS to access the corporate network of another customer. The source address of network traffic cannot be relied upon for authentication and authorization purposes because the MS or hosts beyond the MS can create packets with any addresses regardless of the IP address assigned to the MS.
Hi Kian Kiang!!!!!! :D
ReplyDeleteI think your research is very short. And where are the diagrams and images and everything? Tsk. It is not good to do a post on GSM without diagram because diagrams allow us to see things clearly and understand better.
Anyways, you did not have any solution for GPRS THREATS not TREATS. Oh, and also your GSM. Where are the solution for that? hmmm, Kian Kiang I think there are still work that needs to be done. Thank you.
ZAHIDAH
Hi, after i read your post, i understand what are the GSM and GPRS's features and threats. And you did a lot of research for this post.
ReplyDelete