Conference item icon

Conference item

White rabbit in mobile: effect of unsecured clock source in smartphones

Abstract:
With its high penetration rate and relatively good clock accuracy, smartphones are replacing watches in several market segments. Modern smartphones have more than one clock source to complement each other: NITZ (Network Identity and Time Zone), NTP (Network Time Protocol), and GNSS (Global Navigation Satellite System) including GPS. NITZ information is delivered by the cellular core network, indicating the network name and clock information. NTP provides a facility to synchronize the clock with a time server. Among these clock sources, only NITZ and NTP are up- dated without user interaction, as location services require manual activation. In this paper, we analyze security aspects of these clock sources and their impact on security features of modern smartphones. In particular, we investigate NITZ and NTP procedures over cellular networks (2G, 3G and 4G) and Wi- Fi communication respectively. Furthermore, we analyze several European, Asian, and American cellular networks from NITZ perspective. We identify three classes of vulnerabilities: specification issues in a cellular protocol, configurational issues in cellular network deployments, and implementation issues in different mobile OS’s. We demonstrate how an attacker with low cost setup can spoof NITZ and NTP messages to cause Denial of Service attacks. Finally, we propose methods for securely synchronizing the clock on smartphones
Publication status:
Published
Peer review status:
Peer reviewed

Actions


Access Document


Publisher copy:
10.1145/2994459.2994465

Authors


More by this author
Institution:
University of Oxford
Division:
MPLS
Department:
Computer Science
Role:
Author


More from this funder
Grant:
*Software Campus project project no. 01IS12056


Publisher:
Association for Computing Machinery
Host title:
ACM CCS 2016 Workshop on Security and Privacy in Smartphones and Mobile Devices (SPSM)
Publication date:
2016-10-01
Acceptance date:
2016-09-03
Event location:
Vienna, Austria
DOI:
ISBN:
9781450345644


Keywords:
Pubs id:
pubs:651431
UUID:
uuid:ec1b3c9e-608e-4cbd-9d7b-7cd708630f70
Local pid:
pubs:651431
Source identifiers:
651431
Deposit date:
2016-10-11

Terms of use



Views and Downloads






If you are the owner of this record, you can report an update to it here: Report update to this record

TO TOP