There may be no hotter topic in telecom right now than IP Multimedia Subsystem (IMS), an evolving standard that promises to offer a common way for multiple wireless and wireline networks to deliver multimedia applications.
Fixed and mobile network operators are expected to invest $10.1 billion in IMS capital infrastructure between 2006 and 2011, and generate $49.6 billion in service revenue from IMS-enabled applications within that time, according to ABI Research.
But there may be no more discouraging a topic than securing an IMS network. Recent events and published reports indicate that IMS security specifications are lacking, and that the architecture may open up more vulnerabilities than benefits.
“There definitely were security gaps in the standard right out of the gate,” says Tom Valovic, a telecom analyst at IDC. “Many vendors are somewhat vague concerning the types of security issues associated with wireless.”
Gaps in fixed-line applications are being addressed with standards efforts such as TISPAN and products such as session border controllers, Valovic says. Yet wireless remains a challenge, he says.
“I’ve seen less definition on the wireless side,” Valovic says.
That’s one of the reasons Verizon Wireless decided to develop Advances to IMS (A-IMS), a framework for mobile networks that attempts to fill in perceived gaps in IMS. And Sipera Systems, a maker of products for VoIP, mobile and multimedia security, recently authored an article in a monthly industry periodical describing a litany of vulnerabilities unique to and inherited by IMS.
In that article, Sipera claims to have identified in its labs more than 90 “major classes” of unique vulnerabilities and over 20,000 attacks that can be launched against IMS networks. Most of these vulnerabilities and attacks, however, are common to IP data and VoIP networks as well, says Sipera CTO Krishna Kurapati.
But securing IMS is a much tougher task.
“You have multiple channels of communication and states [in IMS] that complicates matters,” Kurapati says, referring to the various packet data gateways, call servers, media gateways and home subscriber servers that IMS specifies. “There are multiple states that are getting involved simultaneously. You could launch multiple attacks against each of those servers and clients.”
And building an attack mechanism for IMS is easy and inexpensive, Kurapati says. IMS specifications are published on the Third Generation Partnership Project (3GPP) Web site, and other components are available freely as open source software.
Hackers can also write scripts to read IMS Subscriber Identity Module (SIM) cards with which to gain access to the IMS network, he says.
Once inside, a hacker can launch denial of service (DoS) and distributed DoS attacks by flooding IMS elements with calls, as well as stealth attacks, in which certain IMS elements are targeted for floods by one or more DoS sources, Kurapati says.
Fuzzy protocols
IMS networks are also vulnerable to protocol fuzzing, VoIP spam, fraud and rogue devices, Kurapati says. Protocol fuzzing is used to test applications by sending them semi-valid input to determine how the application reacts, and then fixing it if necessary.
Any attack on an IMS network could potentially affect the billions of users currently on wireline and wireless networks, he says.
“With IMS, there’s no access restriction,” he says. “From the Internet, you can buy a stolen credit card, buy a SIM card, get it on, and you are already communicating with 99% of the other people using traditional telephones. There’s a huge liability for carriers to understand that they are punching a hole in a dam.”
The 3GPP standards shortchange IMS on security, according to Kurapati. The 3GPP says it never intended to standardize every potential security alternative available to carriers for IMS.
“We are doing the security standards for those parts of the system that need to be standardized,” says Valtteri Niemi, a Nokia official who chairs the 3GPP security group, referring to authentication, privacy and network-to-network interfaces. “It’s clear that there are many other security features needed in the launched IMS systems where the security is not described in the standards.”
The 3GPP standardizes security protocols between terminal and network, and interfaces between network elements so they can interoperate, Niemi says. For others, 3GPP writes guidelines for securing IMS implementations within elements that are not standardized by the group.
Niemi says Sipera is assuming that all IMS security is based only on what is standardized within the 3GPP, Niemi says.
“That’s a misunderstanding,” he says. “There is no idea [to include] the whole system and the robust implementations in the standards because that would simply be too much. There’s lots of best practices, and the vendors have to take good care of their implementations.”
Niemi says Sipera oversimplifies the SIM card situation.
“It gives an impression that it’s easy to hack those cards,” Niemi said. IMS for GSM/UMTS operators allows them to have proprietary algorithms in the cards to help prevent such attacks, he says.
“In the past, there has been some incidents with people being able to hack certain SIM cards,” Niemi says. “But that doesn’t imply that those particular SIM cards would be using IMS. It doesn’t mean that other cards, newer cards from other operators — or even cards from the same operator — would contain the same algorithms which had the vulnerability.”
Niemi also notes there’s no need to “hack” the SIM card; you have the card or you don’t. If you have a SIM card you’re a fully authenticated user to whatever network supports it.
“The card is the token which authenticates you,” he says.
Bad implementation
The only vulnerability that could be considered unique to IMS, Niemi says, is a “bad implementation” of the IMS architecture that could induce a buffer overflow on an IMS server. Then again, buffer overflow is similar to a vulnerability in any network element in any network — not just IMS, he says.
IMS security work is ongoing, Niemi says. Every release adds new features — for example, the 3GPP is working with the packet cable industry and WiMAX Forum to secure IMS networks accessed by broadband cable, and fixed and mobile WiMAX access networks, he says.
So IMS security work is never complete — nor is it incomplete, Niemi says.
“I wouldn’t say that we are lacking” in regard to standardizing IMS security, Niemi concludes. “Sometimes for clarity, it’s mentioned in our specifications that this is not describing all of the security features of IMS systems. Typically, this disclaimer is self-evident for people in the industry.”
It was self-evident enough for Verizon Wireless to develop A-IMS and attempt to coalesce the industry around its extensions. Verizon Wireless has said that a key reason for developing A-IMS was the security limitations in the IMS specifications from 3GPP and 3GPP2, its CDMA-based counterpart.
“A-IMS is being developed in response to a number of shortcomings and deficiencies with the existing MMD [3GPP2 Multimedia Domain] standards as identified by Verizon,” the carrier states in its executive summary on A-IMS. “A-IMS will allow carriers to support a broader suite of applications on their network, and offer those applications to a broader business and consumer base while providing a level of control and security which is superior to that available with an MMD/IMS-only approach.
“The security enhancements that A-IMS provides are substantial,” Verizon Wireless claims in its executive summary. Specifically, the framework provides “posture assessment,” allowing access to the network to only those endpoints compliant with software policy admission.
A-IMS also integrates intrusion detection and antimalware, and provides for a separate “Security Operations Center” for real-time response to security threats, according to the summary.
Verizon Wireless officials were not available to comment for this story. But A-IMS vendor Alcatel-Lucent acknowledges the limited scope of IMS security standards, and the role of vendors and operators in taking the baton from the 3GPP.
“If you’re just implementing IMS standards, you’re not sufficiently secure,” says Bob Thornberry, director of Alcatel-Lucent’s network security office. “You really need to look at each deployment individually.
“We work very closely with our customers to understand their security needs and to provide the security in the overall solution that’s needed, which would be [IMS] standards-compliant but involve other security as well.”
A key consideration is whether access to the IMS network is from the Internet or through a private IP intranet, says Dave Strand, a security architect in Alcatel-Lucent’s Bell Laboratories. The Sipera article implies access from the Internet, he says.
“IMS networks are predominantly going to be created by private intranets,” Strand says. “Access via the Internet is really going to be limited to those services that require connectivity to a fixed-location PC.
“The [IMS] networks that are being built have far more defense measures being built into them with far more layers of defense,” Strand says. “The Internet is the Wild West.”
Limiting the openness of the IMS infrastructure is key to limiting security breaches, an analyst agrees.
“If the underlying transport of the network is all private, it’s very difficult for me to see how that isn’t secure,” says Bob Johnson, senior analyst in the datacom and telecom practice at Venture Development Corp., which two months ago issued a research note stating that functionally complete IMS infrastructures are two years late in deployment. “Now the concept of just a wide open transport network underneath it — there’s plenty of opportunity there to be hacked. The telcos have traditionally never been open to that concept.”
Nevertheless, the sheer scope of the IMS framework requires intense security scrutiny. Therefore, it’s incumbent upon carriers to contain their IMS networks — constructing an often-criticized “walled garden” — in order to maintain security, Johnson says.“If you don’t find an orderly manner in which to deploy services you do definitely open up this can of worms.”




