Norbert Ludant

dblp:214/6602 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
5since 2021 · last 2025
0009-0008-2674-1700ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 first-author · 4 since 2021Computer networks · 2 · 1 since 2021
YearPublicationVenuePosition
2025 Low-Layer Attacks Against 4G/5G Networks
Norbert Ludant, Marinos Vomvas, Stavros Dimou, Guevara Noubir
WISEC1
2023 From 5G Sniffing to Harvesting Leakages of Privacy-Preserving Messengers
abstract
We present the first open-source tool capable of efficiently sniffing 5G control channels, 5GSniffer and demonstrate its potential to conduct attacks on users privacy. 5GSniffer builds on our analysis of the 5G RAN control channel exposing side-channel leakage. We note that decoding the 5G control channels is significantly more challenging than in LTE, since part of the information necessary for decoding is provided to the UEs over encrypted channels. We devise a set of techniques to achieve real-time control channels sniffing (over three orders of magnitude faster than brute-forcing). This enables, among other things, to retrieve the Radio Network Temporary Identifiers (RNTIs) of all users in a cell, and perform traffic analysis. To illustrate the potential of our sniffer, we analyse two privacy-focused messengers, Signal and Telegram. We identify privacy leaks that can be exploited to generate stealthy traffic to a target user. When combined with 5GSniffer, it enables stealthy exposure of the presence of a target user in a given location (solely based on their phone number), by linking the phone number to the RNTI. It also enables traffic analysis of the target user. We evaluate the attacks and our sniffer, demonstrating nearly 100% accuracy within 30 seconds of attack initiation.
Norbert Ludant, Pieter Robyns, Guevara Noubir
SP1
2022 In-depth study of RNTI management in mobile networks: Allocation strategies and implications on data trace analysis
Giulia Attanasio, Claudio Fiandrino, Marco Fiore 0001, Jörg Widmer, Norbert Ludant, Bastian Bloessl, Konstantinos Kousias, Özgü Alay, Lise Jacquot, Razvan Stanica
Comput. Networks5
2021 Linking Bluetooth LE & Classic and Implications for Privacy-Preserving Bluetooth-Based Protocols
abstract
Bluetooth Low Energy advertisements are increasingly used for proximity privacy-preserving protocols. We investigate information leakage from BLE advertisements. Our analysis, among other things, reveals that the design of today’s Bluetooth chips enables the linking of BLE advertisements to Bluetooth Classic (BTC) frames, and to a globally unique identifier (BDADDR). We demonstrate that the inference of the BDADDR from BLE advertisements is robust achieving over 90% reliability across apps, mobile devices, density of devices, and tens of meters away from the victims. We discuss the implications of current chipsets vulnerability on privacy-preserving protocols. The attack, for instance, reveals the BDADDR of devices of infected users of contact-tracing apps. We also discuss how the vulnerability can lead to de-anonymization of victims. Furthermore, current mobile devices do not allow selective disabling of BTC independently of BLE which renders simple countermeasures impractical. We developed several mitigations for the Android OS and the Bluetooth stack and demonstrate their efficacy.
Norbert Ludant, Tien Dang Vo-Huu, Sashank Narain, Guevara Noubir
SP1
2021 SigUnder: a stealthy 5G low power attack and defenses
abstract
The 3GPP 5G cellular system is hailed as a major step towards more ubiquitous and pervasive communications infrastructure (including for V2X, Smart Grid, and Healthcare). We disclose and evaluate SigUnder, an attack that enables an adversary to overshadow the Signal Synchronization Block (SSB) with an injected signal at 3.4dB below the legitimate signal (prior work required 3dB above). The attack exploits the polar coding mechanism of 5G and the physical layer OFDM structure. It can be used to make previous DoS and over-shadowing attacks lower-power and stealthy, but also enables new attacks unique to 5G such as setting the cellBarred field in the 5G MIB (and blocking access to a cell). We develop techniques (e.g., phase prediction) to make the attack feasible in a practical setup, and evaluate its performance both in simulations and over the air experiments. We also introduce SICUnder, an extension of Successive Interference Cancellation (SIC) to be able to address the unique challenges that SigUnder poses and demonstrate it effectiveness relatively to standard SIC.
Norbert Ludant, Guevara Noubir
WISEC1
2019 Performance Evaluation of Single Base Station ToA-AoA Localization in an LTE Testbed
abstract
Precise localization is becoming an integral part of mobile network architectures, not only to provide location-based services but also to optimize the operation of the network itself through suitable context information. Location systems are of particular importance for indoor settings where GPS may be unavailable. While upcoming 5G systems will provide improved location accuracy, for a long time to come many areas will only have LTE coverage, and ubiquitous localization will thus also have to rely on LTE technology. To evaluate the location accuracy that can be achieved with current mobile systems, we implement a localization algorithm in a standard-compliant LTE testbed based on software-defined radios. We assess the localization accuracy in representative indoor scenarios. Despite a bandwidth of only 20MHz, the results show a good median error around 2m, but significantly larger errors may occur in non-line-of-sight cases. Nevertheless, the accuracy is sufficient for a range of potential applications.
Alejandro Blanco, Norbert Ludant, Pablo Jiménez Mateo, Yi Wang 0018, Jörg Widmer
PIMRC2
2019 openLEON: An end-to-end emulation platform from the edge data center to the mobile user
Claudio Fiandrino, Alejandro Blanco, Pablo Jiménez Mateo, Carlos Andrés Ramiro, Norbert Ludant, Jörg Widmer
Comput. Commun.5
2017 Data-driven performance evaluation of carrier aggregation in LTE-Advanced
abstract
Carrier aggregation increases the throughput of LTE mobile networks by aggregating bandwidth at different frequencies. The theoretical effectiveness of carrier aggregation has been widely studied in the literature and operators claim it substantially increases the network data rate. However, to the best of our knowledge no practical evaluation of the performance of carrier aggregation has been performed using real traffic data. We perform a thorough measurement-based study to assess how carrier aggregation improves the service offered in selected locations in Madrid, Spain. Although the best results for data rate boost are in line with the operator claims, we find that resource usage in aggregated bands is frequently suboptimal, and higher data rates could be achieved by simply overloading a single band. On the other hand, the quality of service achieved by users effectively exploiting carrier aggregation could not be achieved without it.
Norbert Ludant, Nicola Bui, Ana García Armada, Jörg Widmer
PIMRC1