About the speaker

Vadim Yanitskiy

Talk structure (1)

Talk structure (2)

2G/3G network (infra)structure

gsm_infra.png

2G/3G network (infra)structure

Circuit switched and Packet Switched domains

2G/3G network (infra)structure

MS (Mobile Station) - mobile phone + SIM-card

2G/3G network (infra)structure

BTS (Base Transceiver Station)

BSC (Base Station Controller)

PCU (Packet Control Unit)

2G/3G network (infra)structure

HLR (Home Location Register)

VLR (Visitor Location Register)

MSC (Mobile Switching Center)

SGSN (Serving GPRS Support Node)

2G/3G network (infra)structure

GGSN (GPRS Gateway Support Node)

Axillary nodes

UMTS specific elements

4G network (infra)structure

lte_infra.png

4G network (infra)structure

Similar infrastructure, different abbreviations

2G/3G/4G network (infra)structure

Basic principles of the cellular coverage

2G/3G/4G network (infra)structure

Service provider identification

2G/3G/4G network (infra)structure

Subscriber identification (1)

2G/3G/4G network (infra)structure

Subscriber identification (2)

2G/3G/4G network (infra)structure

Subscriber identification (3)

2G Radio Interface basics

Shared medium access

2G Radio Interface basics

Shared medium access

2G Radio Interface basics

TDMA frame / slot hierarchy

tdma_hier.png

2G Radio Interface basics

Control TDMA frame structure

tdma_mf51.png

2G Radio Interface basics

Traffic TDMA frame structure

tdma_mf25.png

2G Radio Interface basics

Convolutional coding

2G Radio Interface basics

Data transfer technologies (plugins)

2G Radio Interface security

Subscriber identity masquerading

2G Radio Interface security

Authentication

2G Radio Interface security

The A5/x encryption

2G Radio Interface security

The myth of frequency hopping

Known attacks and vulnerabilities of 2G RAN

IMSI / TMSI Detach Attack

Known attacks and vulnerabilities of 2G RAN

Paging Response Race Condition

Radio Interface security evolution

2G GSM

Radio Interface security evolution

2.5G (E)GPRS

Radio Interface security evolution

3G UMTS (1)

Radio Interface security evolution

3G UMTS (2)

Radio Interface security evolution

4G LTE (1)

Radio Interface security evolution

4G LTE (2)

Radio Interface security evolution

4G LTE (3)

Known attacks and vulnerabilities

IMSI catchers coming soon…

Thanks for your attention!

Questions?