CAPEC-618: Cellular Broadcast Message Request

Detailed Draft 严重程度: Low

CAPEC版本: 3.9

更新日期: 2023-01-24

攻击模式描述

In this attack scenario, the attacker uses knowledge of the target’s mobile phone number (i.e., the number associated with the SIM used in the retransmission device) to cause the cellular network to send broadcast messages to alert the mobile device. Since the network knows which cell tower the target’s mobile device is attached to, the broadcast messages are only sent in the Location Area Code (LAC) where the target is currently located. By triggering the cellular broadcast message and then listening for the presence or absence of that message, an attacker could verify that the target is in (or not in) a given location.

前提条件

  • The attacker must have knowledge of the target’s mobile phone number.

所需技能

Low Open source and commercial tools are available for this attack.

后果影响

影响范围: Other

技术影响: Other

说明: An attacker could verify that the target is in (or not in) a given location.

缓解措施

Frequent changing of mobile number.

关键信息

CAPEC ID: CAPEC-618

抽象级别: Detailed

状态: Draft

典型严重程度: Low

相关攻击模式
相关CWE弱点