Conference item
White rabbit in mobile: effect of unsecured clock source in smartphones
- Abstract:
- With its high penetration rate and relatively good clock accuracy, smartphones are replacing watches in several market segments. Modern smartphones have more than one clock source to complement each other: NITZ (Network Identity and Time Zone), NTP (Network Time Protocol), and GNSS (Global Navigation Satellite System) including GPS. NITZ information is delivered by the cellular core network, indicating the network name and clock information. NTP provides a facility to synchronize the clock with a time server. Among these clock sources, only NITZ and NTP are up- dated without user interaction, as location services require manual activation. In this paper, we analyze security aspects of these clock sources and their impact on security features of modern smartphones. In particular, we investigate NITZ and NTP procedures over cellular networks (2G, 3G and 4G) and Wi- Fi communication respectively. Furthermore, we analyze several European, Asian, and American cellular networks from NITZ perspective. We identify three classes of vulnerabilities: specification issues in a cellular protocol, configurational issues in cellular network deployments, and implementation issues in different mobile OS’s. We demonstrate how an attacker with low cost setup can spoof NITZ and NTP messages to cause Denial of Service attacks. Finally, we propose methods for securely synchronizing the clock on smartphones
- Publication status:
- Published
- Peer review status:
- Peer reviewed
Actions
Access Document
- Files:
-
-
(Preview, Accepted manuscript, pdf, 1.2MB, Terms of use)
-
- Publisher copy:
- 10.1145/2994459.2994465
Authors
+ Deutsche Zentrum für Luft und Raumfahrt
More from this funder
- Grant:
- *Software Campus project project no. 01IS12056
- Publisher:
- Association for Computing Machinery
- Host title:
- ACM CCS 2016 Workshop on Security and Privacy in Smartphones and Mobile Devices (SPSM)
- Publication date:
- 2016-10-01
- Acceptance date:
- 2016-09-03
- Event location:
- Vienna, Austria
- DOI:
- ISBN:
- 9781450345644
- Keywords:
- Pubs id:
-
pubs:651431
- UUID:
-
uuid:ec1b3c9e-608e-4cbd-9d7b-7cd708630f70
- Local pid:
-
pubs:651431
- Source identifiers:
-
651431
- Deposit date:
-
2016-10-11
Terms of use
- Copyright holder:
- ACM
- Copyright date:
- 2016
- Notes:
- © 2016 ACM
If you are the owner of this record, you can report an update to it here: Report update to this record