{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T10:37:24Z","timestamp":1743071844004,"version":"3.40.3"},"publisher-location":"Cham","reference-count":54,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031709029"},{"type":"electronic","value":"9783031709036"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-70903-6_11","type":"book-chapter","created":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T22:04:30Z","timestamp":1725487470000},"page":"208-228","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Wherever I May Roam: Stealthy Interception and\u00a0Injection Attacks Through Roaming Agreements"],"prefix":"10.1007","author":[{"given":"Swantje","family":"Lange","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Francesco","family":"Gringoli","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Matthias","family":"Hollick","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiska","family":"Classen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,9,5]]},"reference":[{"key":"11_CR1","unstructured":"3GPP: Network Domain Security (NDS); IP network layer security. Technical Specification (TS) 33.210, 3GPP (2022). version 17.1.0"},{"key":"11_CR2","unstructured":"3GPP: Network Identity and TimeZone (NITZ). Technical Specification (TS) 22.042, 3GPP (2022). version 17.0.0"},{"key":"11_CR3","unstructured":"3GPP: Characteristics of the Universal Subscriber Identity Module (USIM) application. Technical Specification (TS) 31.102, 3GPP (2023). version 18.0.0"},{"key":"11_CR4","unstructured":"3GPP: Procedures for the 5G System (5GS). Technical Specification (TS) 23.502, 3GPP (2023). version 18.4.0"},{"key":"11_CR5","unstructured":"3GPP: Public Land Mobile Network (PLMN) Interconnection. Technical Specification (TS) 29.573, 3GPP (2023). version 18.5.0"},{"key":"11_CR6","unstructured":"3GPP: Security architecture and procedures for 5G system. Technical Specification (TS) 33.501, 3GPP (2023). version 18.4.0"},{"key":"11_CR7","unstructured":"3GPP: Service principles. Technical Specification (TS) 22.101, 3GPP (2023). version 18.5.0"},{"key":"11_CR8","unstructured":"3GPP: System architecture for the 5G System (5GS). Technical Specification (TS) 23.501, 3GPP (2023). version 18.4.0"},{"key":"11_CR9","unstructured":"3GPP: Lawful Interception (LI) architecture and functions. Technical Specification (TS) 33.127, 3GPP (2024). version 18.7.0"},{"key":"11_CR10","unstructured":"3GPP: Lawful Interception (LI) Implementation Guidance. Technical Specification (TS) 33.929, 3GPP (2024). version 0.0.21"},{"key":"11_CR11","unstructured":"3GPP: Lawful Interception requirements. Technical Specification (TS) 33.126, 3GPP (2024). version 19.0.0"},{"key":"11_CR12","unstructured":"3GPP: Protocol and procedures for Lawful Interception (LI). Technical Specification (TS) 33.128, 3GPP (2024). version 18.7.0"},{"key":"11_CR13","unstructured":"Amnesty Tech: NSO Group spyware used against Moroccan journalist days after company pledged to respect human rights (2020). https:\/\/www.amnesty.org\/en\/latest\/news\/2020\/06\/nso-spyware-used-against-moroccan-journalist"},{"key":"11_CR14","unstructured":"Amnesty Tech: Predator Files: Technical deep-dive into Intellexa Alliance\u2019s surveillance products (2023). https:\/\/securitylab.amnesty.org\/latest\/2023\/10\/technical-deep-dive-into-intellexa-alliance-surveillance-products\/"},{"key":"11_CR15","unstructured":"Apple: About Lockdown Mode (2023). https:\/\/support.apple.com\/en-us\/105120"},{"key":"11_CR16","unstructured":"Apple: Apple device support for private 5G and LTE networks (2023). https:\/\/support.apple.com\/guide\/deployment\/support-for-private-5g-and-lte-networks-depac6747317\/web"},{"key":"11_CR17","unstructured":"Apple: iOS 17.3 Firmware for iPhone 14 Pro (2023). https:\/\/updates.cdn-apple.com\/2024WinterFCS\/fullrestores\/042-81174\/16619A78-E8C1-453B-A996-6826E5A4FCB8\/iPhone15,2_17.3_21D50_Restore.ipsw"},{"key":"11_CR18","unstructured":"Apple: Bug Reporting Profiles and Logs (2024). https:\/\/developer.apple.com\/bug-reporting\/profiles-and-logs\/"},{"key":"11_CR19","doi-asserted-by":"crossref","unstructured":"Arnold, L., Hollick, M., Classen, J.: Catch you cause i can: busting rogue base stations using cellguard and the apple cell location database. Under Submission (2024)","DOI":"10.1145\/3678890.3678898"},{"key":"11_CR20","unstructured":"Association, G.: VoLTE Implementation Guide (2021). https:\/\/www.gsma.com\/get-involved\/working-groups\/wp-content\/uploads\/2021\/01\/VoLTE-Implementation-Guide-Jan-2021.pdf"},{"key":"11_CR21","unstructured":"Beniamini, G.: Over The Air - Vol. 2, Pt. 3: Exploiting The Wi-Fi Stack on Apple Devices (2017). https:\/\/googleprojectzero.blogspot.com\/2017\/10\/over-air-vol-2-pt-3-exploiting-wi-fi.html"},{"key":"11_CR22","unstructured":"CellularPrivacy: Android IMSI-Catcher Detector (2023). https:\/\/github.com\/CellularPrivacy\/Android-IMSI-Catcher-Detector"},{"key":"11_CR23","doi-asserted-by":"publisher","unstructured":"Classen, J., Gringoli, F., Hermann, M., Hollick, M.: Attacks on wireless coexistence: exploiting cross-technology performance features for inter-chip privilege escalation. In: IEEE Symposium on Security and Privacy, pp. 1229\u20131245 (2022). https:\/\/doi.org\/10.1109\/SP46214.2022.9833639","DOI":"10.1109\/SP46214.2022.9833639"},{"key":"11_CR24","doi-asserted-by":"publisher","unstructured":"Classen, J., Heinrich, A., Reith, R., Hollick, M.: Evil never sleeps: when wireless malware stays on after turning off iPhones. In: Proceedings of the 15th ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2022, pp. 146-156. ACM, New York (2022). https:\/\/doi.org\/10.1145\/3507657.3528547","DOI":"10.1145\/3507657.3528547"},{"key":"11_CR25","unstructured":"ComcSoft Corporation: iNetTools - Ping, DNS, Port Scan (2024). https:\/\/apps.apple.com\/de\/app\/inettools-ping-dns-port-scan\/id561659975"},{"key":"11_CR26","doi-asserted-by":"publisher","unstructured":"Dabrowski, A., Pianta, N., Klepp, T., Mulazzani, M., Weippl, E.: IMSI-catch me if you can: IMSI-catcher-catchers. In: Proceedings of the 30th Annual Computer Security Applications Conference, ACSAC 2014, pp. 246-255. ACM, New York (2014). https:\/\/doi.org\/10.1145\/2664243.2664272","DOI":"10.1145\/2664243.2664272"},{"key":"11_CR27","unstructured":"Electronic Frontier Foundation: Crocodile Hunter (2022). https:\/\/github.com\/efforg\/crocodilehunter"},{"key":"11_CR28","unstructured":"Ettus Research: Usrp x310 (2024). https:\/\/www.ettus.com\/all-products\/X310-KIT\/"},{"key":"11_CR29","unstructured":"Google: Android 14 introduces first-of-its-kind cellular connectivity security features (2023). https:\/\/security.googleblog.com\/2023\/08\/android-14-introduces-first-of-its-kind.html"},{"key":"11_CR30","unstructured":"GSM Association: TS.25 mobile network codes and names guidelines and application form (2018). https:\/\/www.gsma.com\/newsroom\/gsma_resources\/ts-25-mobile-network-codes-and-names-guidelines-and-application-form\/"},{"key":"11_CR31","unstructured":"GSMK: Prodcuts: Network Security (2023). https:\/\/www.gsmk.de\/products\/network-security\/"},{"key":"11_CR32","unstructured":"Huntley, S.: Buying spying: how the commercial surveillance industry works and what can be done about it (2024). https:\/\/blog.google\/threat-analysis-group\/commercial-surveillance-vendors-google-tag-report\/"},{"key":"11_CR33","doi-asserted-by":"crossref","unstructured":"Karakoc, B., F\u00fcrste, N., Rupprecht, D., Kohls, K.: Never let me down again: bidding-down attacks and mitigations in 5G and 4G. In: Proceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks. WiSec 2023 (2023). https:\/\/doi.org\/10.1145\/3558482.3581774","DOI":"10.1145\/3558482.3581774"},{"key":"11_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1007\/978-3-030-88418-5_7","volume-title":"Computer Security \u2013 ESORICS 2021","author":"T Kr\u00f6ll","year":"2021","unstructured":"Kr\u00f6ll, T., Kleber, S., Kargl, F., Hollick, M., Classen, J.: ARIstoteles \u2013 dissecting apple\u2019s baseband interface. In: Bertino, E., Shulman, H., Waidner, M. (eds.) ESORICS 2021. LNCS, vol. 12972, pp. 133\u2013151. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-88418-5_7"},{"key":"11_CR35","unstructured":"Lee, S.: Open5GS (2023). https:\/\/open5gs.org\/open5gs\/release\/2023\/12\/04\/release-v2.7.0.html"},{"key":"11_CR36","doi-asserted-by":"crossref","unstructured":"Li, Z., et al.: FBS-radar: uncovering fake base stations at scale in the wild. In: NDSS (2017)","DOI":"10.14722\/ndss.2017.23098"},{"key":"11_CR37","doi-asserted-by":"publisher","unstructured":"Maier, D., Seidel, L., Park, S.: BaseSAFE: baseband sanitized fuzzing through emulation. In: Proceedings of the 13th ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2020, pp. 122-132. ACM, New York (2020). https:\/\/doi.org\/10.1145\/3395351.3399360","DOI":"10.1145\/3395351.3399360"},{"key":"11_CR38","unstructured":"Marczak, B., Scott-Railton, J., Roethlisberger, D., Razzak, B.A., Anstis, S., Deibert, R.: Predator in the Wires (2023). https:\/\/citizenlab.ca\/2023\/09\/predator-in-the-wires-ahmed-eltantawy-targeted-with-predator-spyware-after-announcing-presidential-ambitions\/"},{"key":"11_CR39","unstructured":"Miller, G., Parsons, C.: Finding You (2023). https:\/\/citizenlab.ca\/2023\/10\/finding-you-teleco-vulnerabilities-for-location-disclosure\/"},{"key":"11_CR40","unstructured":"Miru, G.: Path of least resistance: cellular baseband to application processor escalation on mediatek devices (2017). https:\/\/comsecuris.com\/blog\/posts\/path_of_least_resistance\/"},{"key":"11_CR41","doi-asserted-by":"publisher","unstructured":"Ney, P., Smith, I., Cadamuro, G., Kohno, T.: SeaGlass: enabling city-wide IMSI-catcher detection. In: Proceedings on Privacy Enhancing Technologies (2017). https:\/\/doi.org\/10.1515\/popets-2017-0027","DOI":"10.1515\/popets-2017-0027"},{"key":"11_CR42","unstructured":"Operation Zero: Prices (2023). https:\/\/opzero.ru\/en\/prices\/"},{"key":"11_CR43","unstructured":"Osmocom: Simtrace 2 (2024). https:\/\/osmocom.org\/projects\/simtrace2\/wiki"},{"key":"11_CR44","unstructured":"Park, S.: Why we cannot win: on fake base stations and their detection methods (2023). https:\/\/api-depositonce.tu-berlin.de\/server\/api\/core\/bitstreams\/99520397-8b47-4ea4-acd6-2b17c9a78bd4\/content"},{"key":"11_CR45","unstructured":"Pesonen, L.: GSM Interception (1999). http:\/\/www.tml.tkk.fi\/Opinnot\/Tik-110.501\/1999\/papers\/gsminterception\/netsec.html"},{"key":"11_CR46","unstructured":"Quintin, C.: Google releases \u201cDisable 2G\u201d feature for new android smartphones (2022). https:\/\/www.eff.org\/de\/deeplinks\/2022\/01\/victory-google-releases-disable-2g-feature-new-android-smartphones"},{"key":"11_CR47","unstructured":"Ravn\u00e5s, O.A.V.: Frida (2024). https:\/\/frida.re"},{"key":"11_CR48","unstructured":"Ruge, J., Classen, J., Gringoli, F., Hollick, M.: Frankenstein: advanced wireless fuzzing to exploit new bluetooth escalation targets. In: 29th USENIX Security Symposium (USENIX Security 2020), pp. 19\u201336. USENIX Association (2020). https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/ruge"},{"key":"11_CR49","unstructured":"Security Research Labs: SnoopSnitch (2022). https:\/\/opensource.srlabs.de\/projects\/snoopsnitch"},{"key":"11_CR50","unstructured":"Sevens, B., Lecinge, C.: Spyware vendor targets users in Italy and Kazakhstan (2022). https:\/\/blog.google\/threat-analysis-group\/italian-spyware-vendor-targets-users-in-italy-and-kazakhstan\/"},{"key":"11_CR51","unstructured":"Silvanovich, N.: How To Hack Shannon Baseband (2023). https:\/\/www.youtube.com\/watch?v=LJ1NzJLMDUs"},{"key":"11_CR52","unstructured":"Software Radio Systems: srsRAN Project (2024). https:\/\/www.srsran.com\/5g"},{"key":"11_CR53","unstructured":"StreamSoft: PingTools Network Utilities (2024). https:\/\/play.google.com\/store\/apps\/details?id=ua.com.streamsoft.pingtools"},{"key":"11_CR54","unstructured":"Zerodium: Zerodium Payouts (2019). https:\/\/zerodium.com\/program.html"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-70903-6_11","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,27]],"date-time":"2024-11-27T19:49:30Z","timestamp":1732736970000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-70903-6_11"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031709029","9783031709036"],"references-count":54,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-70903-6_11","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"5 September 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Bydgoszcz","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Poland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 September 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2024.org","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}