Beta
323883

Penetration Testing of GSM Network using Man-In-The-Middle Attack

Article

Last updated: 26 Dec 2024

Subjects

-

Tags

Electrical Engineering, Computer Engineering and Electrical power and machines engineering.

Abstract

Even though wireless communication technologies have advanced beyond the Global Systems for Mobile (GSM) Communications standard to mitigate its vulnerabilities, it is still a fallback technology when the coverage is limited and modern protocols aren't available. There is a need for a comprehensive practical demonstration of the pools of vulnerabilities of the GSM architecture in the past decades using man-in-the-middle open-source tools and SDRs amidst the latest developments. It can be shown that an attacker can successfully carry out base station spoofing, IMSI catching, GSM packet sniffing, decoding, decryption and Denial of Service (DoS) attacks. Thus, this paper aims to comprehensively present practical demonstrations of the many vulnerabilities possible with available tools.
We exploited IMSI catching with a rogue BTS deployed using OpenBTS and USRP B210, GSM sniffing and decoding using GR-GSM and RTL-SDR, and A5/1 decryption using clever thinking and rainbow tables. It was observed that the one-way authentication of the GSM protocol allows most mobile devices to easily authenticate to the rogue BTS with spoofed MCC/MNC and that the strongest signal mostly wins. Also, it was observed that the possibilities of attacks on the target user like a DoS, or unencrypted communication, can be successfully carried out because the rogue BTS is in total control.
Though the vulnerabilities of GSM have been made known to the general public some network providers have not taken simple measures to mitigate them, thus this work can serve as a guideline for research purposes and an awareness to the general public

DOI

10.21608/jesaun.2023.226718.1249

Keywords

IMSI catcher, OpenBTS, GR-GSM, Wireshark, A5/1 rainbow tables

Authors

First Name

Nosa

Last Name

Bello

MiddleName

-

Affiliation

Department of Electrical/Electronic Engineering, University of Benin, Benin City, Nigeria

Email

nosabello@uniben.edu

City

Benin

Orcid

0009-0003-7831-3066

First Name

Ogechukwu

Last Name

Kanu

MiddleName

-

Affiliation

Department of Electrical/Electronic Engineering, University of Benin, Benin City, Nigeria

Email

kanu.ogechukwu@eng.uniben.edu

City

Amuwo

Orcid

0000-0002-6237-6682

Volume

52

Article Issue

1

Related Issue

44873

Issue Date

2024-01-01

Receive Date

2023-08-02

Publish Date

2024-01-01

Page Start

12

Page End

26

Print ISSN

1687-0530

Online ISSN

2356-8550

Link

https://jesaun.journals.ekb.eg/article_323883.html

Detail API

https://jesaun.journals.ekb.eg/service?article_code=323883

Order

5

Type

Research Paper

Type Code

1,438

Publication Type

Journal

Publication Title

JES. Journal of Engineering Sciences

Publication Link

https://jesaun.journals.ekb.eg/

MainTitle

Penetration Testing of GSM Network using Man-In-The-Middle Attack

Details

Type

Article

Created At

26 Dec 2024