Mobile Subscriber Profile Data Privacy Breach via 4G Diameter Interconnection
SS7, Diameter, IPX, securityAbstract
The interconnection network (IPX) connects telecommunication networks with each other on the globe. The IPX network enables features like voice and data roaming with your mobile device while traveling. Designed as a closed network it is now opening and unauthorized entities now misuse the IPX network for their purposes. The majority of the IPX still runs the Signalling System No 7 (SS7) protocol stack, while the more technically advanced operators roll out and deploy Diameter based LTE roaming. SS7 is known to suffer from many attacks. The first attacks using the Diameter protocol appeared. We will show how an attacker can breach the subscriber’s privacy by deducting the subscriber profile from the Home Subscriber Service (HSS) and use the obtained information. The subscriber profile contains all key information related to the users’ subscription e.g. location, billing information, MSISDN etc. We will close with a recommendation how to prevent such an attack.
International Telecommunication Union (ITU) - T, Signalling System No.7 related specifications,
Nordsveen Arve M., Norsk Telemuseum, ‘Mobiltelefonens historie i Norge’ (2005).
3rd Generation Partnership Project (3GPP), TS 29.002, ‘Mobile Application Part (MAP) specification,’ v14.3.0, Release 14, (2017).
Internet Engineering Task Force, IETF RFC 6733 ‘Diameter Base Protocol’, October 2012.
Internet Engineering Task Force, IETF RFC 3588, ‘Diameter Base Protocol’, September 2003.
3rd Generation Partnership Project (3GPP), TS 33.210, ‘3G Security, Network Domain Security (NDS), IP Network Layer Security’ v14.0.0 Release 14 (2016).
3rd Generation Partnership Project (3GPP), TS 29.272, ‘Evolved Packet System (EPS); Mobility Management Entity (MME) and Serving GPRS Support Node (SGSN) related interfaces based on Diameter protocol’, v14.3.0, Release 14 (2017).
3rd Generation Partnership Project (3GPP), TR 29.805, ‘InterWorking Function (IWF) between MAP based and Diameter based interfaces’, v 8.0.0, Release 8 (2008).
3rd Generation Partnership Project (3GPP), TS 29.305, ‘InterWorking Function (IWF) between MAP based and Diameter based interfaces’, v 14.0.0, Release 14 (2017).
Holtmanns, S., Rao S., and Oliver, I. (2016). ‘User Location Tracking Attacks for LTE Networks Using the Interworking Functionality’, IFIP Networking Conference, Vienna, Austria.
Engel, T. (2008). ‘Locating Mobile Phones using Signaling System 7’, 25th Chaos Communication Congress 25C3.∼tobias/25c3-locating-mobile-phones.pdf
Engel, T. (2014). ‘SS7: Locate. Track. Manipulate’, 31st Chaos Computer Congress 31C3.∼tobias/31c3-ss7-locate-track-manipulate.pdf
Positive Technologies, ‘SS7 Security Report’, 2014.
Nohl, K. (2014). SR Labs, ‘Mobile self-defense’, 31st Chaos Communication Congress 31C3.
Nohl, K., and Melette L. (2015). ‘Chasing GRX and SS7 vulns’, Chaos Computer Camp.
Positive Technologies, ‘Mobile Internet traffic hijacking via GTP and GRX’, (2015).
Rao, S., Holtmanns, S., Oliver, I., and Aura, T. (2015). ‘Unblocking Stolen Mobile Devices Using SS7-MAP Vulnerabilities: Exploiting the Relationship between IMEI and IMSI for EIR Access.’ Trustcom/BigDataSE/ISPA, 2015 IEEE. Vol. 1. IEEE.
Fox-Brewster, T. (2016). Forbes, ‘Hackers can steal your facebook account with just a phone number’.
Fox-Brewster, T. (2016). Forbes, ‘Watch as hackers hijack WhatsApp accounts via critical telecoms flaw’.
Rao, S., Holtmanns, S., Oliver, I., and Aura, T. (2016). ‘We know where you are’, IEEE NATO CyCon, In 8th International Conference on Cyber Conflict, 277–294.
Kotte, B., Holtmanns S., and Rao, S. (2016). ‘Detach me not – DoS attacks against 4G cellular users worldwide from your desk’, Blackhat Europe.
Holtmanns, S., and Oliver, I. (2017). ‘SMS and One-Time-Password Interception in LTE Networks’, IEEE ICC Conference, Paris.
3rd Generation Partnership Project (3GPP), TS 29.344, ‘Proximity-services (ProSe) function to Home Subscriber Server (HSS) aspects’ v14.1.0, Release 14, (2017).
3rd Generation Partnership Project (3GPP), TS 32.422, ‘Telecommunication management; Subscriber and equipment trace; Trace control and configuration management,’ v14.0.0, Release 14, (2017).
3rd Generation Partnership Project (3GPP), TS 29.061, ‘Interworking between the Public Land Mobile Network (PLMN) supporting packet based services and Packet Data Networks (PDN)’ v14.3.0, Release 14, (2017),
Telecom Dictionary, SS7 Stack,
Puzankov, S. (2017). Positive Technology, ‘Stealthy SS7 Attacks’, IEEE Network and Systems Security (NSS), International Workshop on 5G Security.
Mashukov, S. (2017). Positive Technology, ‘Diameter Security: An Auditors Viewpoint’, IEEE Network and Systems Security (NSS), International Workshop on 5G Security.
Holtmanns, S., Oliver, I., and Miche, Y. (2017). Nokia Bell Labs, ‘Subscriber Profile Extraction and Modification via Diameter Interconnection’, IEEE Network and Systems Security (NSS), International Workshop on 5G Security.
ETSI, (1998). SMG27, ‘Status Report from SMG10 to SMG27’, Annex D,
3rd Generation Partnership Project (3GPP), TS 33.200, ‘3G Security; Network Domain Security (NDS); Mobile Application Part (MAP) application layer security,’ v1.0.1, Release 4, (2001).
Telecom Dictionary, ‘SS7 Protocol Stack’