IET Networks (Mar 2024)

VoWi‐Fi security threats: Address resolution protocol attack and countermeasures

  • Kuan‐Chu Lu,
  • I.‐Hsien Liu,
  • Keng‐Hao Chang,
  • Jung‐Shian Li

DOI
https://doi.org/10.1049/ntw2.12113
Journal volume & issue
Vol. 13, no. 2
pp. 129 – 146

Abstract

Read online

Abstract B5G/6G networks are facing challenges in the deployment of additional base stations. However, Taiwan's four major operators have launched VoWi‐Fi calling services to maintain signal quality and coverage for customers. These services pose potential threats when users connect to untrusted Wi‐Fi networks. Therefore, the authors utilised commercial equipment to study the security of VoWi‐Fi calling services offered by Taiwan's four major telecom companies. The authors employed address resolution protocol attack methods to develop two verification attacks that bypass existing security measures: one for dropping session initiation protocol packets and the other for dropping voice call packets, both capable of circumventing current security defences. Through real‐world experiments, the authors confirmed their feasibility and assessed their potential harm. Consequently, two defence methods are proposed. The first is an anti‐attack algorithm for app and device manufacturers to detect the security of the user's calling environment. The second is a recommendation for telecom operators to implement new detection mechanisms to safeguard user rights. The cover image is based on the Case Study VoWi‐Fi security threats: Address resolution protocol attack and countermeasures by Kuan‐Chu Lu et al., https://doi.org/10.1049/ntw2.12113

Keywords