Thursday, 5 January 2012

GPRS Security Feature, Threats and Solution

GPRS Security Feature, Threats and Solution
General packet radio service (GPRS) is a packet oriented mobile data service on the 2G and 3G cellular communication system's global system for mobile (GSM). It provides moderate-speed data transfer, by using unused time division multiple access.
GPRS Security Feature
·         Identity Confidentiality
This is to provide privacy to the subscriber so it will be difficult to identify the person from thier signal over the radio and connections to the SGSN. It is also used to protect identity such as dialed digits and addresses.

·         User and signaling data confidentiality
This is derived by using function A3/8 as in GSM.

·         Authorization
It is a security service that ensures a party may only perform the actions that they are allowed to perform.

·         Availability
Data services are usable by the appropriate parties in the manner intended.
GPRS threats
Most common types of attack on availability would be denial of service attack. Below are some of the DOS attack.
·         DNS Flood
It can be flooded with either correctly or malformed DNS queries or other traffic thereby denying subscribers the ability to locate the proper GGSN to use as an external gateway.

·         DNS Cache Poisoning
An attacker to forge DNS queries or responses that cause a given user’s APN to resolve to the wrong GGSN or even none at all is possible. Sometimes it can prevent subscribers from being able to pass data at all.
·         Overbilling attacks
This is by a malicious mobile station that hijacks an IP address of another mobile station and invokes a download from a malicious server on the internet. Once the download begins, the malicious mobile station exits the session. The mobile station under attack, receiving the download traffic, gets charged for traffic it did not solicit. The same malicious party could execute this attack for the purpose of sending broadcasts of unsolicited data in the direction of subscriber cell phones. The effect is still the same, in that the subscriber is billed for  data that they did not solicited and might not have wanted.

GPRS solution
The fundamental issue with security is the lack of security inherent. Implementing IPSec between roaming partners and managing traffic rates, can eliminate a majority of the threats.

·         Overbilling Attack Prevention
Enables the firewall to of an attack. The firewall is then able to terminate the “hanging” sessions and/or tunnels, thus cutting off the unwanted traffic. As such, this prevents the GPRS subscriber from being “overbilled.”

Reference:

2 comments:

  1. Hi! I've observed that your threats and features findings are detailed. I liked the fact that you put up some diagrams as a guidance to help with better understanding and to avoid a very wordy blog. Good job there!

    ReplyDelete
  2. Post is very intresting, and mentions alot on GPRS. It has a lot of major points needed in GPRS.

    ReplyDelete