dmitry kurbatov sergey puzankov vladimir kropotov ... r2 1600...dmitry kurbatov sergey puzankov...

65
Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones Incidents Detection and Forensics in Telco Networks ptsecurity.com

Upload: nguyenxuyen

Post on 25-Jun-2018

239 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Dmitry Kurbatov

Sergey Puzankov

Vladimir Kropotov

Fractured Backbones –

Incidents Detection and

Forensics in Telco Networks ptsecurity.com

Page 2: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

About us

Joint research of Incident Response and Telco Security Teams

Page 3: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Introduction

Page 4: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Technologies behind telco networks

Чем мы пользуемся сегодня

и на основе каких технологий

это работает

Page 5: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Types of Incidents

• Subscriber location tracking

• Call interception (wiretapping)

• SMS interception and spoofing

• DoS, including balance DoS

• Other Fraudulent activities

Phone number

+7 777 5555555 GPS location

Page 6: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Incidents statistics. Major threats

Service Disruption

Data Leakage

Fraud

Percentage of vulnerable networks

Page 7: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Incidents statistics. Data leakage

Subscriber’s Balance Disclosure

Terminating SMS Interception

Subscriber Location Discovery

Voice Call Interception

Subscriber’s Data Leakage

Percentage of vulnerable networks

Page 8: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Incidents statistics. Fraud

Terminating Call Redirection

Money Transfer via USSD

Subscriber Profile Change

Originating Call Redirection

Percentage of vulnerable networks

Page 9: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Incident victims

• Mobile operator subscribers • Mobile operator • Other Mobile operators and their subscribers • Third parties (often Banks and Their clients)

Page 10: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Prerequisites of attacks

• Internal intruder or Staff initiated attacks • Level0 (almost) Kiddies - attacks that not require deep

technical knowledge •SMS fraud as preliminary stage of malware based attacks •Fraud with social engineering (direct target is victim) •Proxified fraud with social engineering

• Level1(Locally initiated) - attacks that require technical knowledge about Radio Access Network protocols

•IMSI Catcher •Bluetooth •Calls and SMS from the subscriber located nearby

•Level2 (Global impact) - attacks that require technical knowledge about telco infrastructure and protocols

Page 11: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Lightweight scenarios (Level0)

Page 12: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Kiddies fraud examples Typosquatting works well even here

http://journal.tinkoff.ru/declined/ Not legit Legit

You received

30000 RUB,

please follow

the link for

confirmation

Purchase. Card

*1234. Ammount

600 RUB.

Drugstore

2000…

Available

balance

82634.32 RUB

Page 13: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Central bank not only in emails...

Mature player and kiddies used the same brand name

http://www.rbc.ru/finances/17/03/20

16/56e97c089a794797e5b8e6b3

/Cental Bank of

Russian Federation/

Your banking cards

accounts was

suspended!

Info: +79649910054

Page 14: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Social engineering telco staff

• Temporary redirect calls and SMS to another number

• Own victim email, social networks accounts, messengers and in some cases Money (Banking OTP TBD)

• Fast WIN

Page 15: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Cases (Level1)

Page 16: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

SMS interception

Page 17: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call interception

• Originating call • Terminating call

Page 18: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call interception. MitM

Page 19: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Level2 Cases (global impact)

Page 20: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Telco infrastructure, technical view

Page 21: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Telco infrastructure, technical view

Page 22: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Telco infrastructure, technical view

Page 23: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Telco infrastructure, technical view

Page 24: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

IMSI Disclosure

Page 25: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Money fraud cases

•Infect smartphone with malware. •Use fake base station (IMSI catcher) and to make software clone of SIM card. •Conduct an attack via SS7 network forging USSD request.

Page 26: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

USSD manipulation

Request the balance *100#. Balance is 128.55 Roubles

Page 27: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

USSD manipulation

*145*xxxxxx81142*10# - Transfer 10 Roubles to the number xxxxxx81142

Page 28: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

USSD manipulation

Cool security mechanism. Just send *145*851# to confirm the transaction

Page 29: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

USSD manipulation

New balance is 118.55 Roubles. (10 Roubles ~ 0.15 €)

Page 30: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Calls or SMS on behalf particular person located anywhere

• SMS spoofing

Page 31: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

More sophisticated attacks

Page 32: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Example

Page 33: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco
Page 34: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Fraud case 1

Page 35: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789 Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 36: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

RegisterSS (IMSI, CFU, 5312345678)

RegisterSS

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 37: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number)

RegisterSS (IMSI, CFU, 5312345678)

RegisterSS

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 38: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

RegisterSS (IMSI, CFU, 5312345678)

RegisterSS

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 39: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

RegisterSS (IMSI, CFU, 5312345678)

RegisterSS

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 40: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

SendRoutingInfo (CFU, 5312345678)

RegisterSS (IMSI, CFU, 5312345678)

RegisterSS

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 41: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

SendRoutingInfo (CFU, 5312345678)

RegisterSS (IMSI, CFU, 5312345678)

RegisterSS

InitialDP (B-Number, 5312345678)

ApplyCharging, Continue

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 42: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

SendRoutingInfo (CFU, 5312345678)

RegisterSS (IMSI, CFU, 5312345678)

RegisterSS

ApplyCharging, Continue

IAM (A-Number, 5312345678)

Number 88612345670

IMSI 466901234567891

InitialDP (B-Number, 5312345678)

Zimbabwe

Cuba

Page 43: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

SendRoutingInfo (CFU, 5312345678)

RegisterSS (IMSI, CFU, 5312345678)

RegisterSS

ApplyCharging, Continue

IAM (A-Number, 5312345678)

Who pays?

Number 88612345670

IMSI 466901234567891

InitialDP (B-Number, 5312345678)

Zimbabwe

Cuba

Page 44: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Who pays?

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

SendRoutingInfo (CFU, 5312345678)

RegisterSS (IMSI, CFU, 5312345678)

RegisterSS

ApplyCharging, Continue

IAM (A-Number, 5312345678)

Number 88612345670

IMSI 466901234567891

InitialDP (B-Number, 5312345678)

Zimbabwe

Cuba

Page 45: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Who pays?

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

SendRoutingInfo (CFU, 5312345678)

RegisterSS (IMSI, CFU, 5312345678)

RegisterSS

ApplyCharging, Continue

IAM (A-Number, 5312345678)

Number 88612345670

IMSI 466901234567891

InitialDP (B-Number, 5312345678)

Zimbabwe

Cuba

Page 46: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Fraud case 2

Page 47: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789 Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 48: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 49: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number)

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 50: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 51: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 52: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

ProvideSubscriberInfo (IMSI)

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 53: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

ProvideSubscriberInfo (IMSI)

ProvideSubscriberInfo (Location = Home)

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 54: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

ProvideSubscriberInfo (IMSI)

ProvideSubscriberInfo (Location = Home)

SendRoutingInfo (Location = Home)

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 55: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

ProvideSubscriberInfo (IMSI)

ProvideSubscriberInfo (Location = Home)

SendRoutingInfo (Location = Home)

InitialDP (A-Num, B-Num, Location)

ApplyCharging, Continue

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 56: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

ProvideSubscriberInfo (IMSI)

ProvideSubscriberInfo (Location = Home)

SendRoutingInfo (Location = Home)

InitialDP (A-Num, B-Num, Location)

ApplyCharging, Continue

SendRoutingInfo (MSISDN)

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 57: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

ProvideSubscriberInfo (IMSI)

ProvideSubscriberInfo (Location = Home)

SendRoutingInfo (Location = Home)

InitialDP (A-Num, B-Num, Location)

ApplyCharging, Continue

SendRoutingInfo (MSISDN)

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 58: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

ProvideSubscriberInfo (IMSI)

ProvideSubscriberInfo (Location = Home)

SendRoutingInfo (Location = Home)

InitialDP (A-Num, B-Num, Location)

ApplyCharging, Continue

SendRoutingInfo (MSISDN)

ProvideRoaminNumber (IMSI)

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 59: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

ProvideSubscriberInfo (IMSI)

ProvideSubscriberInfo (Location = Home)

SendRoutingInfo (Location = Home)

InitialDP (A-Num, B-Num, Location)

ApplyCharging, Continue

SendRoutingInfo (MSISDN)

ProvideRoaminNumber (IMSI)

ProvideRoamingNumber (MSRN = 5312345678)

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 60: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

26121456789

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

ProvideSubscriberInfo (IMSI)

ProvideSubscriberInfo (Location = Home)

SendRoutingInfo (Location = Home)

InitialDP (A-Num, B-Num, Location)

ApplyCharging, Continue

SendRoutingInfo (MSISDN)

ProvideRoaminNumber (IMSI)

ProvideRoamingNumber (MSRN = 5312345678)

SendRoutingInfo (MSRN = 5312345678)

Number 88612345670

IMSI 466901234567891 Zimbabwe

Page 61: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Voice call redirection with a fraudulent activity

Billing

GMSC

HLR

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

ProvideSubscriberInfo (IMSI)

ProvideSubscriberInfo (Location = Home)

SendRoutingInfo (Location = Home)

InitialDP (A-Num, B-Num, Location)

ApplyCharging, Continue

SendRoutingInfo (MSISDN)

ProvideRoaminNumber (IMSI)

ProvideRoamingNumber (MSRN = 5312345678)

SendRoutingInfo (MSRN = 5312345678)

IAM (A-Number, 5312345678)

26121456789 Number 88612345670

IMSI 466901234567891 Zimbabwe

Cuba

Page 62: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Who pays?

Billing

GMSC

HLR

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

ProvideSubscriberInfo (IMSI)

ProvideSubscriberInfo (Location = Home)

SendRoutingInfo (Location = Home)

InitialDP (A-Num, B-Num, Location)

ApplyCharging, Continue

SendRoutingInfo (MSISDN)

ProvideRoaminNumber (IMSI)

ProvideRoamingNumber (MSRN = 5312345678)

SendRoutingInfo (MSRN = 5312345678)

IAM (A-Number, 5312345678)

26121456789 Number 88612345670

IMSI 466901234567891 Zimbabwe

Cuba

Page 63: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Who pays?

Billing

GMSC

HLR

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

ProvideSubscriberInfo (IMSI)

ProvideSubscriberInfo (Location = Home)

SendRoutingInfo (Location = Home)

InitialDP (A-Num, B-Num, Location)

ApplyCharging, Continue

SendRoutingInfo (MSISDN)

ProvideRoaminNumber (IMSI)

ProvideRoamingNumber (MSRN = 5312345678)

SendRoutingInfo (MSRN = 5312345678)

IAM (A-Number, 5312345678)

26121456789 Number 88612345670

IMSI 466901234567891 Zimbabwe

Cuba

Page 64: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Who pays?

Billing

GMSC

HLR

UpdateLocation (IMSI, Fake MSC/VLR)

InsertSubscriberData (Profile)

IAM (A-Number, B-Number) SendRoutingInfo (MSISDN)

ProvideSubscriberInfo (IMSI)

ProvideSubscriberInfo (Location = Home)

SendRoutingInfo (Location = Home)

InitialDP (A-Num, B-Num, Location)

ApplyCharging, Continue

SendRoutingInfo (MSISDN)

ProvideRoaminNumber (IMSI)

ProvideRoamingNumber (MSRN = 5312345678)

SendRoutingInfo (MSRN = 5312345678)

IAM (A-Number, 5312345678)

26121456789 Number 88612345670

IMSI 466901234567891 Zimbabwe

Cuba

Page 65: Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov ... R2 1600...Dmitry Kurbatov Sergey Puzankov Vladimir Kropotov Fractured Backbones – Incidents Detection and Forensics in Telco

Thank you!

ptsecurity.com