Monday, April 28, 2025
HomeVulnerabilityThree Critical Attack Flaw Discover Against LTE Networks Standard that Hijack Network...

Three Critical Attack Flaw Discover Against LTE Networks Standard that Hijack Network Connections

Published on

SIEM as a Service

Follow Us on Google News

Researchers uncovered three novel attack Flaw in LTE (4G) network data link layer that allows hackers to perform a different level of attacks in the Mobile communication protocol.

In this case, attack flaw leads to perform 2 passive attacks which is identity mapping attack and a method to perform website fingerprinting and other attack called aLTEr attack that allows an attacker to redirect network connections by performing DNS spoofing.

These 3 individual attacks allow hijacking the network connection via spoofing the network by performing an active aLTEr attack.

- Advertisement - Google News

This flaw mainly used for targetted attacks victims of such targeted attacks in practice are persons of special interest and there is more effort needed to successfully perform this attack against the target.

Researchers focused only on data link layer that maintains the wireless transmission of information between the users and the network.

“Layer two(data link layer) organizes how multiple users can access the resources of the network, helps to correct transmission errors, and protects data through encryption.”

Passive Attack

Passive attacks against LTE network allow performing website fingerprinting attack that leaks leak information about the consumption of data per time unit.

Researchers experiment the website fingerprinting attack against  LTE network and tested different devices on a selection of the 50 most popular websites on the Internet.

They performed website fingerprinting on encryption data link layer traffic in LTE and result proved that average success rate of about 89%.

Active Attack (aLTEr)

Active attack intercepts the all transmissions between the client and network, in this case, Attackers send Spoofed signals to the network or to the device by using a specific device.

Data link layers above mutual authentication on the layers prevent users connected to the fake network which is used by LTE networks. But below layer which is unprotected which allows an attacker can forward high-layer messages.

By using user data redirection attacker can modify the content of a packet if she knows the original plain text, even the packet is encrypted due to this LTE security flaw.

Also in the Active attack, The malicious DNS server performs DNS spoofing, meaning that the domain is resolved to a fake, malicious IP address. As a result, the phone sends a request the wrong IP address.

You can read a complete research work in a technical paper also you can read it from dedicated Website for this research.

Also Read:

Top 5 Most Common Web Application Attacks That Affecting Websites

Protect Your Enterprise Network From Cyber Attack with Strong Web Application Firewall

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

WooCommerce Users Targeted by Fake Security Vulnerability Alerts

A concerning large-scale phishing campaign targeting WooCommerce users has been uncovered by the Patchstack...

Chrome UAF Process Vulnerabilities Actively Exploited

Security researchers have revealed that two critical use-after-free (UAF) vulnerabilities in Google Chrome’s Browser...