HAXPO: This is a Public Service Announcement: Hacking LTE Public Warning Systems

This talk will be LIVE STREAMED on YouTube: http://youtube.com/hitbsecconf


 

Public warning system (PWS) based on mobile communication system is used to alert the public to emergency events such as earthquakes, tsunamis, hurricanes, etc.

We studied the PWS in LTE network and uncovered vulnerabilities of PWS in LTE air interfaces, i.e., the warning messages of the PWS are not encrypted or signed when they are transmitted over the air. Thus, it is possible that a malicious PWS warning messages can be transmitted. We simply use a low cost soft define radio (SDR) device and modify code of the LTE open source project srsLTE in order to forge the warning messages.

Both Apple and Android test mobile phones are affected by our forged warning messages. Fake PWS warning messages can cause serious panics among the population, they also could be used to send advertising or spam messages. The public warning system may become paralyzed and useless under the threat of the abuse of fake warning messages.

HAXPO TRACK
Location: Track 4 / HAXPO Date: May 9, 2019 Time: 11:30 am - 12:00 pm Weiguang Li