While the industry focuses on 5G, 2G and 3G networks still vulnerable to attacks
From Positive Technologies.
Positive Technologies has published a report that analyzes security in mobile networks using the SS7 protocol. Developed in partnership with 28 telecommunications operators in Europe, Asia, Africa and South America between 2018 and 2019, the study shows that SMS tracking and interception and location attacks can be conducted through 2G and 3G networks at present.
Positive Technologies researchers simulated attack activities to evaluate possible failures in the SS7 protocol, used to receive and distribute signaling messages. According to the company, in addition to the architectural security flaws that already exist in the protocol, the risk lies in the fact that cybercriminals can illegally purchase access to SS7 networks on the dark web. In this way, 2G and 3G networks become vulnerable, allowing hackers to track every movement of a customer, listen to calls, intercept SMS messages, instigate fraud or even interrupt operator services.
"From the client's point of view, it is scary to think that there are vulnerabilities in the mobile phone network and that, even so, you won't know if your phone has been affected. That is, messages, calls and location can be tracked without your knowledge, "warns Giovani Henrique, CEO of Positive Technologies for Latin America. "It is important that mobile operators establish partnerships with companies specializing in risk mitigation to ensure the security and visibility of their networks, identify existing vulnerabilities and reduce the impact of these threats," he adds.
According to Positive Technologies experts, security researchers in the sector have warned of the risks of SS7 for decades. However, the failures have become more serious in recent years. The company claims that, in the last three years, the percentage of vulnerable networks has increased in almost all categories of threats, such as information disclosure, location, call interception, financial fraud and denial of service attacks (DoS).
"Although the security of SS7 was improving, with the concentration of operators in the implementation of 5G technology, progress has stopped and the risks of 2G and 3G networks are currently a threat," Henrique explains.
According to the executive, operators plan to close their 2G and 3G networks in the future, but the GSMA reports that these networks of the previous generation will still be available to the public in the next five years. “This means that SS7 will not be a thing of the past in the short term. In addition, the most recent networks are also designed using the network infrastructure of the previous generation, which means that they are affected by the same security problems as SS7," Henrique warns. "Some 4G functions still depend on 2G/3G systems, including sending SMS messages and establishing call connections," he explains.
According to the European Agency for Network and Information Security (ENISA), only 30% of EU operators have implemented the GSMA recommendations. This does not necessarily mean that risk mitigation plans do not work, but that the security tools in use are not enough.
"First, operators must ensure that the correct processes exist to ensure that their mobile networks do not have blind spots," says Henrique. For the executive, only with a comprehensive approach – which includes regular monitoring of any anomaly to detect illegitimate activities – and with compliance with GSMA guidelines, operators can guarantee a higher level of protection against cyber attacks. "We must be aware of 4G and 5G to avoid the same problems as in the past," he warns.
The report is the second in a four-part series on telecommunications security, in which Positive Technologies experts analyze the SS7, Diameter and GTP networks to demonstrate the extent of security problems in modern communications networks. The full document can be accessed here.
About Positive Technologies
Positive Technologies is a global cyber security company, based in Europe. Its solution for IT security in telecommunications helps network operators improve their business performance and protect their customers and services. By offering greater visibility of infrastructure vulnerabilities and guaranteeing customer services, Positive Technologies helps increase customer confidence, boost revenue with value-added security services and protect emerging telecommunications technologies, such as 5G and IoT.
Subscribe to the leading business intelligence platform in Latin America with different tools for Providers, Contractors, Operators, Government, Legal, Financial and Insurance industries.
News in: ICT
How Equinix is laying the groundwork for LatAm’s next big data boom
BNamericas speaks with Eduardo Carvalho, the company's president for Latin America, about market expansions, Mexico's energy gridlock, Colombian gr...
Argentina's fintech ecosystem grows by 11.7% and now includes 383 local startups
A total of 40 new fintech startups have joined the local ecosystem.
Subscribe to Latin America’s most trusted business intelligence platform.
Other projects in: ICT
Get critical information about thousands of ICT projects in Latin America: what stages they're in, capex, related companies, contacts and more.
- Project: Scala AI City (Phase 1)
- Current stage:
- Updated:
2 weeks ago
- Project: Espírito Santo fiber optic network (ES-Digital)
- Current stage:
- Updated:
3 weeks ago
- Project: V.OA Data Center
- Current stage:
- Updated:
3 weeks ago
- Project: Mega Lobster Data Center (Phase 1)
- Current stage:
- Updated:
3 weeks ago
- Project: Antarctic Submarine Cable
- Current stage:
- Updated:
1 month ago
- Project: Cerrillos Data Center
- Current stage:
- Updated:
1 month ago
- Project: Fiber Optic communications installation - Third phase (IFO III)
- Current stage:
- Updated:
1 month ago
- Project: Nova Lurín Data Cente
- Current stage:
- Updated:
1 month ago
- Project: Expansion of the Scala Huechuraba Campus Data Center
- Current stage:
- Updated:
1 month ago
- Project: CloudHQ Paulínia Data Center (GRU Technological Campus) - Second Stage
- Current stage:
- Updated:
1 month ago
Other companies in: ICT
Get critical information about thousands of ICT companies in Latin America: their projects, contacts, shareholders, related news and more.
- Company: ASUR NET  (Liberty Networks)
-
The description included in this profile was taken directly from an official source and has not been modified or edited by the BNamericas’ researchers. However, it may have been...
- Company: Huawei Technologies de México S.A. de C.V.  (Huawei Technologies de México)
-
Huawei Technologies de México S.A. de C.V., branch of the Chinese Huawei Technologies, offers information technologies and communication services and solutions. Its broadband se...
- Company: Thales Group
-
Thales is a French company that provides solutions to governments, institutions, cities and companies in five key areas: aerospace, space, land transport, identity and digital s...
- Company: Yangtze Optical Fibre and Cable Joint Stock Ltd. Co.  (YOFC)
-
The description included in this profile was taken directly from an official source and has not been modified or edited by the BNamericas’ researchers. However, it may have been...
- Company: KIO Networks Group  (KIO Networks)
-
The description contained in this profile was taken directly from an official source and has not been edited or modified by BNamericas researchers, but may have been automatical...
- Company: Uber Technologies Inc.  (Uber)
-
Uber Technologies, Inc. is a San Francisco-based company that provides ground transport e-commerce services. Through the company's website and app, the user can request a car an...
- Company: Arelion
-
The description included in this profile was taken directly from an official source and has not been modified or edited by the BNamericas’ researchers. However, it may have been...
- Company: Hostdime Perú
- Company: Gtd Colombia S.A.S.  (Gtd Colombia)
-
The description included in this profile was taken directly from an official source and has not been modified or edited by BNamericas’ content team. However, it may have been au...