[论文解读] 9-1-1 DDoS: Threat, Analysis and Mitigation
本文展示了如何通过利用蜂窝网络协议和基带固件后门程序,使移动电话僵尸网络能够发起匿名的DDoS攻击,针对911紧急服务系统。攻击者可隐藏设备标识(IMSI/IMEI),使呼叫无法被网络或紧急中心阻止。仅需不到6,000台被感染设备,攻击者即可使北卡罗来纳州等整个州的911服务瘫痪数天,暴露出紧急基础设施中的关键安全漏洞。
The 911 emergency service belongs to one of the 16 critical infrastructure sectors in the United States. Distributed denial of service (DDoS) attacks launched from a mobile phone botnet pose a significant threat to the availability of this vital service. In this paper we show how attackers can exploit the cellular network protocols in order to launch an anonymized DDoS attack on 911. The current FCC regulations require that all emergency calls be immediately routed regardless of the caller's identifiers (e.g., IMSI and IMEI). A rootkit placed within the baseband firmware of a mobile phone can mask and randomize all cellular identifiers, causing the device to have no genuine identification within the cellular network. Such anonymized phones can issue repeated emergency calls that cannot be blocked by the network or the emergency call centers, technically or legally. We explore the 911 infrastructure and discuss why it is susceptible to this kind of attack. We then implement different forms of the attack and test our implementation on a small cellular network. Finally, we simulate and analyze anonymous attacks on a model of current 911 infrastructure in order to measure the severity of their impact. We found that with less than 6K bots (or $100K hardware), attackers can block emergency services in an entire state (e.g., North Carolina) for days. We believe that this paper will assist the respective organizations, lawmakers, and security professionals in understanding the scope of this issue in order to prevent possible 911-DDoS attacks in the future.
研究动机与目标
- 调查利用移动电话僵尸网络发起匿名DDoS攻击911紧急服务的可行性。
- 分析911基础设施中导致此类攻击可绕过检测与阻止的技术与监管漏洞。
- 评估匿名紧急呼叫泛洪对网络可用性与紧急响应的实际影响。
- 基于在小型蜂窝网络上对攻击模型的仿真与测试,提出缓解策略。
提出的方法
- 利用蜂窝网络协议,使具有随机化或伪装IMSI与IMEI标识的设备能够发起紧急呼叫。
- 在基带固件中实现后门程序,对移动设备进行匿名化处理,防止网络或紧急中心识别其身份。
- 在小型蜂窝网络上开展受控的DDoS攻击,以验证攻击的可行性与行为特征。
- 对当前美国911基础设施的模型进行大规模匿名攻击仿真,评估攻击影响的严重性。
- 使用网络仿真工具测量在攻击条件下呼叫阻断率、服务降级程度及恢复时间。
- 分析FCC规定中要求无论主叫身份如何均须立即路由呼叫的条款,该规定构成了此类攻击的攻击向量。
实验结果
研究问题
- RQ1具备匿名标识的移动电话僵尸网络是否能够绕过网络层面的紧急呼叫检测与阻止?
- RQ2当前911基础设施的设计在多大程度上使其易受来自匿名来源的大规模DDoS攻击?
- RQ3使一个大范围地理区域的911服务不可用,所需的最少被攻陷设备数量是多少?
- RQ4现有FCC规定在多大程度上促进了此类攻击的可行性?
- RQ5匿名DDoS攻击对911呼叫处理与紧急响应时间的可测量影响是什么?
主要发现
- 通过在设备中植入可随机化或伪装IMSI与IMEI标识的后门程序,可实现对911的匿名DDoS攻击。
- 由于FCC规定要求无论主叫身份如何均须立即路由呼叫,此类攻击无法在网路层面被阻止。
- 仅需少于6,000台被攻陷设备,攻击者即可使北卡罗来纳州等整个州的911服务瘫痪数天。
- 该攻击在技术上是可行的,并已在小型蜂窝网络上实现验证。
- 仿真结果显示,由于缺乏主叫身份认证与速率限制机制,911基础设施极易受到大规模匿名呼叫泛洪的影响。
- 当前架构缺乏检测或缓解来自匿名来源重复紧急呼叫的机制,形成关键安全缺口。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。