Evaluation of Privacy and Security of GSM Using Low-Cost Methods
Sławomir Kukliński, Michal Czerwinski, Jędrzej Bieniasz, Katarzyna H. Kaminska, Daniel Paczesny, Krzysztof Szczypiorski
Abstract
Sławomir Kukliński, Michal Czerwinski, Jędrzej Bieniasz, Katarzyna H. Kaminska, Daniel Paczesny, Krzysztof Szczypiorski
Abstract
Today the global mobile population is amounted to 4 billion unique users which represents at least half of the world population. The used mobile networks consist of dozen of radio communication technologies among which the most popular ones are GSM, UMTS, CDMA, LTE and incoming 5G networks. The present research on security is mostly focused on the newest technologies, like LTE and 5G, whereas GSM or UMTS are considered as the legacy technologies with the established landscape of security and privacy. The older technologies, however, are still in use: LTE or UMTS can make the fallback to GSM when they are congested or their radio signal quality is bad, GSM based data transmission (GPRS/EDGE), due to wide coverage is still the technology that is used by most payment systems and telemetry. GSM is also recognized as a safe bay for bad actors communications as it is basics communication technology for older types of cellphones which are harder to hack. These aspects were motivations to revisit the problem of mobile networks security from two perspectives: (1) common users security and privacy matters; (2) tracking bad actors using mobile network forensics techniques. To that extent the paper consists of an analysis of the GSM mobile network from the perspective of privacy and security controls. First, the theoretical review of GSM network security mechanisms is provided to indicate potential vulnerabilities of the system. Then, a practical verification of GSM systems security in order to check of the misalignment between mobile technologies standards and practical realizations by mobile network operators. The main results of these experiments are obtained by using modern and relatively low-cost equipment which is feasible to intercept communications of users of the GSM network.
OpenAlex reports 3 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Today the global mobile population is amounted to 4 billion unique users which represents at least half of the world population. The used mobile networks consist of dozen of radio communication technologies among which the most popular ones are GSM, UMTS, CDMA, LTE and incoming 5G networks. The present research on security is mostly focused on the newest technologies, like LTE and 5G, whereas GSM or UMTS are considered as the legacy technologies with the established landscape of security and privacy. The older technologies, however, are still in use: LTE or UMTS can make the fallback to GSM when they are congested or their radio signal quality is bad, GSM based data transmission (GPRS/EDGE), due to wide coverage is still the technology that is used by most payment systems and telemetry. GSM is also recognized as a safe bay for bad actors communications as it is basics communication technology for older types of cellphones which are harder to hack. These aspects were motivations to revisit the problem of mobile networks security from two perspectives: (1) common users security and privacy matters; (2) tracking bad actors using mobile network forensics techniques. To that extent the paper consists of an analysis of the GSM mobile network from the perspective of privacy and security controls. First, the theoretical review of GSM network security mechanisms is provided to indicate potential vulnerabilities of the system. Then, a practical verification of GSM systems security in order to check of the misalignment between mobile technologies standards and practical realizations by mobile network operators. The main results of these experiments are obtained by using modern and relatively low-cost equipment which is feasible to intercept communications of users of the GSM network.
Key concepts: GSM, Customised Applications for Mobile networks Enhanced Logic, UMTS frequency bands, Computer science, Service data point, General Packet Radio Service, Mobile telephony, Computer security