Mobile networks under new types of denial-of-service attack

June 9, 2009 - 8:00am | Fraud | News |
| More
  
Mobile networks under new types of denial-of-service attack
Senior telecoms security researcher warned last week about new danger for the security of mobile data networks - new types of denial of service attacks.

According to Krishan Sabnani, vice president of networking research at Bell Labs, the launch of those attacks is possible thanks to inherent weaknesses in the mobile IP protocol. As he commented, attacks are relatively straightforward to mount, but hard to detect and defeat.

Those new attacks take form of repeatedly setting up and releasing connections thereby creating congestion at radio network controllers, which in its own turn causes problems for legitimate subscribers. This form is similar to the SYN Flood assaults, problem on the fixed-line (wired) internet. Another type of attacks sends packets preventing mobile devices from going into a sleep mode, in such a way decreasing battery life.

Another types of attack against mobile IP networks outlined by Sabnani are: placing defective devices on a network that generate false traffic which is hard to pin down; and excessive port scanning as a result of connected devices that are infected with computer malware. 

"We need to especially monitor the mobile networks – with limited bandwidth and terminal battery — for DOS attacks," Sabnani said at the Cyber Infrastructure Protection Conference at City College of New York. As he suggested, the worse thing is that the resources needed to launch an attack might be out of all proportion to the damage that could be inflicted. "One cable modem user with 500Kbps upload capacity can attack over one million mobile users simultaneously," he said.

Bell Labs' is developing security appliances designed for mobile network architecture and protocols. "We have developed algorithms based on traffic profiling and statistical models that can detect low-volume wireless DOS attacks," Sabnani explained. "The system detects and mitigates traffic that will cause RNC signaling overload, unnecessary airlink usage, paging overload, and unnecessary subscriber battery drain."





RSS feed Subscribe to Ecommerce Journal RSS feed

0 points

   Tell us what topics you want to be covered in the Ecommerce Journal?  
Image CAPTCHA
  


Comments on Mobile networks under new types of denial-of-service attack




Similar Articles on Ecommerce Journal by sections

FIGURES
PAYMENT SYSTEMS
BANKS
PLASTIC CARDS
ECOMMERCE-CHECKED
INVESTMENT INDUSTRY
FRAUD
ANALYTICS
OTHER THEMES
INTERVIEWS
LAW ASPECTS