New Recording 24
May 11, 2026 21:05
· 50:58
· English
· Whisper Turbo
· 2 Sprekers
Dit transcript verloopt vandaag.
Upgrade voor permanente opslag →
Uitsluitend tonen
0:00
S…
Speaker 1 (New Recording 24)
We try to have all kinds of apps like for banking,
0:04
S…
Speaker 1 (New Recording 24)
transport,
0:04
S…
Speaker 1 (New Recording 24)
any kind of stuff,
0:06
S…
Speaker 1 (New Recording 24)
we have mobile apps today.
0:07
S…
Speaker 1 (New Recording 24)
And today phones seem to be like mini computers.
0:11
S…
Speaker 1 (New Recording 24)
They try to work like a mini computer,
0:13
S…
Speaker 1 (New Recording 24)
do all kinds of computation.
0:14
S…
Speaker 1 (New Recording 24)
Because of another technology called cloud,
0:17
S…
Speaker 1 (New Recording 24)
since all the applications and data are hosted in some server,
0:20
S…
Speaker 1 (New Recording 24)
if you have an internet service in a browser,
0:22
S…
Speaker 1 (New Recording 24)
you can access those services.
0:24
S…
Speaker 1 (New Recording 24)
So phones are considered to be like mini computers and also like today
0:28
S…
Speaker 1 (New Recording 24)
for any digital identity,
0:30
S…
Speaker 1 (New Recording 24)
for your verification,
0:32
S…
Speaker 1 (New Recording 24)
we use smartphones.
0:33
S…
Speaker 1 (New Recording 24)
So what kind of protection do we provide?
0:37
S…
Speaker 1 (New Recording 24)
That is the first question.
0:40
S…
Speaker 1 (New Recording 24)
Usually people use a lock.
0:43
S…
Speaker 1 (New Recording 24)
Right with a four -digit pin or a pattern or your face log.
0:46
S…
Speaker 1 (New Recording 24)
That is like the initial level.
0:48
S…
Speaker 1 (New Recording 24)
Then for each application you have some protection.
0:50
S…
Speaker 1 (New Recording 24)
For data you can have a separate protection like a folder box and kind
0:55
S…
Speaker 1 (New Recording 24)
of stuff.
0:55
S…
Speaker 1 (New Recording 24)
But it's on your user perspective.
0:58
S…
Speaker 1 (New Recording 24)
But what happens on the other perspective?
1:01
S…
Speaker 1 (New Recording 24)
On the other side of a backend.
1:02
S…
Speaker 1 (New Recording 24)
Malverse plays a vital role on all phones.
1:05
S…
Speaker 1 (New Recording 24)
Right, they can have data from your mobile phones.
1:08
S…
Speaker 1 (New Recording 24)
So how do we protect them?
1:10
S…
Speaker 1 (New Recording 24)
And today with any apps like your bank and all,
1:13
S…
Speaker 1 (New Recording 24)
today we go for authentication with your app.
1:17
S…
Speaker 1 (New Recording 24)
For example, even your Microsoft services,
1:18
S…
Speaker 1 (New Recording 24)
if you want to log in,
1:20
S…
Speaker 1 (New Recording 24)
you can use a mobile for Microsoft Authenticator.
1:22
S…
Speaker 1 (New Recording 24)
For your bank,
1:23
S…
Speaker 1 (New Recording 24)
for any transaction,
1:24
S…
Speaker 1 (New Recording 24)
even their bank app for authentication.
1:26
S…
Speaker 1 (New Recording 24)
So we depend on these mobile phones for authentication purposes.
1:31
S…
Speaker 1 (New Recording 24)
So whether we protect this device first,
1:33
S…
Speaker 1 (New Recording 24)
then only I can think about how I can use this device for
1:37
S…
Speaker 1 (New Recording 24)
the authentication.
1:39
S…
Speaker 1 (New Recording 24)
So first reason the dominance.
1:41
S…
Speaker 1 (New Recording 24)
Second reason is act like a mini computer.
1:44
S…
Speaker 1 (New Recording 24)
Third reason we use it for authenticating your transactions.
1:47
S…
Speaker 1 (New Recording 24)
And fourth reason is going to be like a critical infrastructure.
1:51
S…
Speaker 1 (New Recording 24)
Each and every company have their own way of designing their
1:55
S…
Speaker 1 (New Recording 24)
mobile.
1:56
S…
Speaker 1 (New Recording 24)
So how their architecture is safe.
2:00
S…
Speaker 1 (New Recording 24)
who gives a guarantee of protecting their architects.
2:03
S…
Speaker 1 (New Recording 24)
So that is going to be another stuff like each and
2:07
S…
Speaker 1 (New Recording 24)
every country has their own quality of a device usage.
2:10
S…
Speaker 1 (New Recording 24)
Some devices are not allowed to use in UAE.
2:13
S…
Speaker 1 (New Recording 24)
Right, so why they ban it so that they need to find like
2:17
S…
Speaker 1 (New Recording 24)
each and every device How come it is effective?
2:21
S…
Speaker 1 (New Recording 24)
What is allowed and what is not allowed in that?
2:23
S…
Speaker 1 (New Recording 24)
So it's a critical infrastructure and last one is policy dimension Each
2:28
S…
Speaker 1 (New Recording 24)
and every app has their own policy of allowing right then how
2:32
S…
Speaker 1 (New Recording 24)
your mobile conflicts to that context
2:34
S…
Speaker 1 (New Recording 24)
So when you think about phone security,
2:37
S…
Speaker 1 (New Recording 24)
these are the things which we need to come across.
2:39
S…
Speaker 1 (New Recording 24)
Like we use it in everywhere.
2:41
S…
Speaker 1 (New Recording 24)
It used like a mini computer.
2:43
S…
Speaker 1 (New Recording 24)
It is used like your identity verification.
2:45
S…
Speaker 1 (New Recording 24)
It is a critical infrastructure at last policy dimensionality
2:49
S…
Speaker 1 (New Recording 24)
because of various services.
2:51
S…
Speaker 1 (New Recording 24)
So because of these five key concepts,
2:54
S…
Speaker 1 (New Recording 24)
people look for phone security.
2:57
S…
Speaker 1 (New Recording 24)
But when we think about a
3:01
S…
Speaker 1 (New Recording 24)
phone, what it has?
3:03
S…
Speaker 1 (New Recording 24)
It has a hardware.
3:04
S…
Speaker 1 (New Recording 24)
It has a software which is your operating system.
3:07
S…
Speaker 1 (New Recording 24)
And it has application.
3:09
S…
Speaker 1 (New Recording 24)
Whether we have a common hardware,
3:12
S…
Speaker 1 (New Recording 24)
software and application.
3:13
S…
Speaker 1 (New Recording 24)
No.
3:14
S…
Speaker 1 (New Recording 24)
Each and every mobile phone manufacturer have their own hardware.
3:18
S…
Speaker 1 (New Recording 24)
And we use different version of operating system in Android or iOS.
3:22
S…
Speaker 1 (New Recording 24)
And we use different version of your applications.
3:25
S…
Speaker 1 (New Recording 24)
Right.
3:26
S…
Speaker 1 (New Recording 24)
Everything is different.
3:27
S…
Speaker 1 (New Recording 24)
So the ecosystem is dynamic.
3:29
S…
Speaker 1 (New Recording 24)
Every time it's going to be different.
3:32
S…
Speaker 1 (New Recording 24)
And the network that we use that is also not the same.
3:35
S…
Speaker 1 (New Recording 24)
Maybe here we use the same Wi -Fi,
3:37
S…
Speaker 1 (New Recording 24)
but when we go out,
3:38
S…
Speaker 1 (New Recording 24)
everyone have your own data network to work.
3:40
S…
Speaker 1 (New Recording 24)
So even the network lines are different.
3:42
S…
Speaker 1 (New Recording 24)
So nothing is common among the users.
3:46
S…
Speaker 1 (New Recording 24)
So how the security can be provided?
3:49
S…
Speaker 1 (New Recording 24)
So this was the problem,
3:52
S…
Speaker 1 (New Recording 24)
not only now,
3:53
S…
Speaker 1 (New Recording 24)
from the earlier stages.
3:54
S…
Speaker 1 (New Recording 24)
Today we use various techniques as is here,
3:57
S…
Speaker 1 (New Recording 24)
cryptography,
3:58
S…
Speaker 1 (New Recording 24)
access control mechanism,
3:59
S…
Speaker 1 (New Recording 24)
mobile protocols,
4:00
S…
Speaker 1 (New Recording 24)
telecom network design,
4:02
S…
Speaker 1 (New Recording 24)
all these we use today.
4:03
S…
Speaker 1 (New Recording 24)
But if you see the history,
4:05
S…
Speaker 1 (New Recording 24)
there are like four stages of development of attacks.
4:08
S…
Speaker 1 (New Recording 24)
The first one is going to be a phone freaking.
4:11
S…
Speaker 1 (New Recording 24)
When the phone freaking happens,
4:14
S…
Speaker 1 (New Recording 24)
even now it happens,
4:18
S…
Speaker 1 (New Recording 24)
if you use lab line.
4:20
S…
Speaker 1 (New Recording 24)
for any official purpose.
4:21
S…
Speaker 1 (New Recording 24)
It has a duration of office time.
4:25
S…
Speaker 1 (New Recording 24)
After that,
4:26
S…
Speaker 1 (New Recording 24)
it is going to be added.
4:28
S…
Speaker 1 (New Recording 24)
During that time,
4:29
S…
Speaker 1 (New Recording 24)
someone can take that channel and they can use it as like you call
4:33
S…
Speaker 1 (New Recording 24)
to somebody.
4:33
S…
Speaker 1 (New Recording 24)
So that is for phone freaking.
4:35
S…
Speaker 1 (New Recording 24)
Initially, everything was on landline.
4:37
S…
Speaker 1 (New Recording 24)
So they use this phone freaking.
4:39
S…
Speaker 1 (New Recording 24)
Whenever your channel is free,
4:40
S…
Speaker 1 (New Recording 24)
they misuse the channel for the data transfer.
4:43
S…
Speaker 1 (New Recording 24)
Second is when we organize the tribe.
4:46
S…
Speaker 1 (New Recording 24)
Bypassing all and they use your line and you will get the bills.
4:50
S…
Speaker 1 (New Recording 24)
So they are trying to make it as an organized trend.
4:52
S…
Speaker 1 (New Recording 24)
Next deregulation and smartphones and apps.
4:55
S…
Speaker 1 (New Recording 24)
Actually today we are in the stage 4.
4:57
S…
Speaker 1 (New Recording 24)
We use all digital.
5:00
S…
Speaker 1 (New Recording 24)
Your identity is completely available in your mobile phone.
5:03
S…
Speaker 1 (New Recording 24)
The main target in your mobile phone is to steal your identity.
5:06
S…
Speaker 1 (New Recording 24)
So identity theft happens,
5:08
S…
Speaker 2 (New Recording 24)
your banking stuff,
5:09
S…
Speaker 2 (New Recording 24)
malicious apps.
5:10
S…
Speaker 1 (New Recording 24)
We don't know what apps runs in your mobile phone 24 a .m.
5:13
S…
Speaker 1 (New Recording 24)
Whether those apps are legitimate,
5:15
S…
Speaker 1 (New Recording 24)
can you monitor your mobile phone?
5:18
S…
Speaker 1 (New Recording 24)
There is an option with your LMS.
5:22
S…
Speaker 1 (New Recording 24)
But if you enable it,
5:24
S…
Speaker 2 (New Recording 24)
those LMS will learn about you.
5:27
S…
Speaker 1 (New Recording 24)
So in order to avoid that,
5:28
S…
Speaker 1 (New Recording 24)
I need to create my own customized LLM,
5:31
S…
Speaker 1 (New Recording 24)
where it will not share the knowledge with anybody.
5:34
S…
Speaker 1 (New Recording 24)
Only that,
5:35
S…
Speaker 1 (New Recording 24)
LLM will enhance the security of your mobile phone.
5:39
S…
Speaker 1 (New Recording 24)
But if you see here,
5:41
S…
Speaker 2 (New Recording 24)
phone freaking,
5:41
S…
Speaker 2 (New Recording 24)
organized crime,
5:42
S…
Speaker 1 (New Recording 24)
deregulation and smartphone.
5:44
S…
Speaker 1 (New Recording 24)
These are the four stages of attacks.
5:46
S…
Speaker 1 (New Recording 24)
Because of the attacks,
5:48
S…
Speaker 1 (New Recording 24)
there was a development of a new things.
5:50
S…
Speaker 1 (New Recording 24)
When you see these development in mobile technologies,
5:53
S…
Speaker 1 (New Recording 24)
there are two ways in technology development.
5:56
S…
Speaker 1 (New Recording 24)
One is repairing,
5:58
S…
Speaker 1 (New Recording 24)
another one is replacing.
5:59
S…
Speaker 1 (New Recording 24)
Repairing is,
6:00
S…
Speaker 2 (New Recording 24)
oh I develop a technology,
6:02
S…
Speaker 2 (New Recording 24)
there is a problem,
6:02
S…
Speaker 1 (New Recording 24)
I need to resolve it with some enhancement.
6:05
S…
Speaker 2 (New Recording 24)
That is called repairing.
6:06
S…
Speaker 1 (New Recording 24)
Replacing is,
6:07
S…
Speaker 1 (New Recording 24)
oh if this technology has a problem,
6:09
S…
Speaker 2 (New Recording 24)
okay, I will find an algorithm.
6:10
S…
Speaker 2 (New Recording 24)
I move on to the next.
6:11
S…
Speaker 1 (New Recording 24)
Mobile technology works on the second angle.
6:14
S…
Speaker 1 (New Recording 24)
It tries to replace always it goes on to the next next even if you
6:18
S…
Speaker 1 (New Recording 24)
see you use a mobile phone type whether that is the recent one Once
6:24
S…
Speaker 1 (New Recording 24)
you buy a mobile phone within a six months you find that there will be another recent one There
6:29
S…
Speaker 1 (New Recording 24)
will be an advancement of that mobile phone,
6:31
S…
Speaker 1 (New Recording 24)
right?
6:31
S…
Speaker 1 (New Recording 24)
So they always try to go for a new new development
6:36
S…
Speaker 1 (New Recording 24)
So we cannot trust on the device that we hold on it.
6:40
S…
Speaker 1 (New Recording 24)
So we need to be cautious.
6:41
S…
Speaker 1 (New Recording 24)
Very simple recommendation is whenever we install some apps,
6:45
S…
Speaker 1 (New Recording 24)
it mandates you to enable all the services in your mobile phone.
6:48
S…
Speaker 1 (New Recording 24)
But if you give all permission,
6:50
S…
Speaker 1 (New Recording 24)
that app can open anytime and access your resources anytime.
6:53
S…
Speaker 1 (New Recording 24)
But if you restrict,
6:55
S…
Speaker 2 (New Recording 24)
whenever you use,
6:56
S…
Speaker 2 (New Recording 24)
ask me.
6:57
S…
Speaker 1 (New Recording 24)
It will be prompting too much.
6:58
S…
Speaker 1 (New Recording 24)
That is the reason why we give default permissions to every apps.
7:02
S…
Speaker 1 (New Recording 24)
But if you want a safeguard,
7:04
S…
Speaker 1 (New Recording 24)
limit the number of apps that you use and limit the permissions that
7:08
S…
Speaker 2 (New Recording 24)
you provide for those apps.
7:10
S…
Speaker 1 (New Recording 24)
If not,
7:11
S…
Speaker 2 (New Recording 24)
the smartphones and apps in that stage,
7:13
S…
Speaker 1 (New Recording 24)
we will face huge number of attacks.
7:16
S…
Speaker 1 (New Recording 24)
The patterns of vulnerabilities happens with four
7:20
S…
Speaker 2 (New Recording 24)
different people.
7:22
S…
Speaker 1 (New Recording 24)
First one is enthusiasm.
7:24
S…
Speaker 1 (New Recording 24)
They want to break and they want to innovate new things so that is depends
7:29
S…
Speaker 1 (New Recording 24)
on the first Second one is criminals.
7:31
S…
Speaker 1 (New Recording 24)
They are being targeting a certain number of users to bypass For
7:36
S…
Speaker 2 (New Recording 24)
example in banking,
7:37
S…
Speaker 1 (New Recording 24)
you know how many phishing calls or emails we receive to get
7:41
S…
Speaker 1 (New Recording 24)
your credentials So that is going to be criminal accident
7:44
S…
Speaker 1 (New Recording 24)
Third one is regulators.
7:45
S…
Speaker 2 (New Recording 24)
In order to prove this is wrong,
7:48
S…
Speaker 2 (New Recording 24)
they try to break it.
7:49
S…
Speaker 1 (New Recording 24)
And fourth one is industry marketing.
7:51
S…
Speaker 1 (New Recording 24)
In order to say,
7:52
S…
Speaker 2 (New Recording 24)
oh, others are all vulnerable,
7:54
S…
Speaker 1 (New Recording 24)
I am safe,
7:55
S…
Speaker 2 (New Recording 24)
they try to break that thing wrong.
7:57
S…
Speaker 1 (New Recording 24)
So these are the four places where vulnerability comes
8:01
S…
Speaker 1 (New Recording 24)
out of it and phone technology gets outdated every day.
8:05
S…
Speaker 1 (New Recording 24)
Every day there was a new development.
8:08
S…
Speaker 1 (New Recording 24)
For example,
8:09
S…
Speaker 1 (New Recording 24)
if you see your app update,
8:11
S…
Speaker 1 (New Recording 24)
Every week you can see that will be an app update to your mobile phone.
8:15
S…
Speaker 1 (New Recording 24)
So while that happens,
8:16
S…
Speaker 1 (New Recording 24)
always there will be somebody to break your security.
8:19
S…
Speaker 1 (New Recording 24)
So the developers will try to enhance the security.
8:22
S…
Speaker 1 (New Recording 24)
When we think about phone security,
8:25
S…
Speaker 1 (New Recording 24)
we have two things.
8:26
S…
Speaker 1 (New Recording 24)
One is network security,
8:28
S…
Speaker 1 (New Recording 24)
another one is device security.
8:29
S…
Speaker 1 (New Recording 24)
The device security is completely in your control.
8:32
S…
Speaker 1 (New Recording 24)
The user need to know where to connect,
8:35
S…
Speaker 2 (New Recording 24)
where not to connect,
8:36
S…
Speaker 1 (New Recording 24)
what to use and not to use.
8:38
S…
Speaker 1 (New Recording 24)
So everything is in your control.
8:40
S…
Speaker 1 (New Recording 24)
So we are not going to discuss in detail about device security,
8:44
S…
Speaker 1 (New Recording 24)
but we will discuss about network security.
8:46
S…
Speaker 1 (New Recording 24)
Because your device without internet,
8:50
S…
Speaker 1 (New Recording 24)
it is no use to it.
8:51
S…
Speaker 1 (New Recording 24)
So we try to connect your device to your internet service as well as for
8:55
S…
Speaker 1 (New Recording 24)
your data services.
8:56
S…
Speaker 1 (New Recording 24)
Data service is a normal one.
8:58
S…
Speaker 1 (New Recording 24)
So how that network connectivity need to be protected.
9:02
S…
Speaker 1 (New Recording 24)
So you will be focusing on that aspect of network security.
9:06
S…
Speaker 1 (New Recording 24)
So when we think about phone security,
9:08
S…
Speaker 1 (New Recording 24)
three things which will come to your mind.
9:10
S…
Speaker 1 (New Recording 24)
The first one is telecom networking like Atisalat and Doop
9:14
S…
Speaker 1 (New Recording 24)
which they provide you the service.
9:16
S…
Speaker 1 (New Recording 24)
Second one is software and hardware security that you have in your hand.
9:20
S…
Speaker 1 (New Recording 24)
And third one is human factors and policy analytics.
9:23
S…
Speaker 2 (New Recording 24)
How to use.
9:24
S…
Speaker 1 (New Recording 24)
So there are three factors involved in your phone security.
9:28
S…
Speaker 2 (New Recording 24)
So the human.
9:30
S…
Speaker 1 (New Recording 24)
your hardware and software and then your network provider so
9:34
S…
Speaker 1 (New Recording 24)
all these three need to be in a control in order to protect
9:38
S…
Speaker 1 (New Recording 24)
your phone devices if not it is going to be vulnerable so
9:42
S…
Speaker 1 (New Recording 24)
let us try to explore some of the attacks which happens on phone networks
9:47
S…
Speaker 1 (New Recording 24)
because hardware and software is in your control it's a basic social engineering attacks
9:51
S…
Speaker 1 (New Recording 24)
will happen so you need to take care of it and the human factors are of
9:55
S…
Speaker 1 (New Recording 24)
course based on your awareness so we will focus only on the phone networks
10:00
S…
Speaker 1 (New Recording 24)
So let us try to explore the attacks that happens on your phone
10:04
S…
Speaker 1 (New Recording 24)
networks.
10:04
S…
Speaker 1 (New Recording 24)
The first attack which is common attack called phone call metering.
10:09
S…
Speaker 1 (New Recording 24)
What is phone call metering?
10:11
S…
Speaker 1 (New Recording 24)
When you use your mobile networks,
10:14
S…
Speaker 1 (New Recording 24)
there is a metering happens.
10:15
S…
Speaker 1 (New Recording 24)
How many calls you have done,
10:17
S…
Speaker 1 (New Recording 24)
how many SMS you have sent,
10:18
S…
Speaker 1 (New Recording 24)
how much data you have used,
10:20
S…
Speaker 2 (New Recording 24)
right?
10:21
S…
Speaker 1 (New Recording 24)
So can we fake this metering?
10:23
S…
Speaker 2 (New Recording 24)
You
10:28
S…
Speaker 1 (New Recording 24)
will not know because it is billing for you.
10:30
S…
Speaker 1 (New Recording 24)
But what attackers need?
10:32
S…
Speaker 1 (New Recording 24)
Right, so there was an earlier days like they have you seen the button phones Now
10:37
S…
Speaker 1 (New Recording 24)
you have used touch,
10:38
S…
Speaker 1 (New Recording 24)
but in the earlier days they have some button phones There will be a button
10:42
S…
Speaker 1 (New Recording 24)
to attend a call,
10:43
S…
Speaker 1 (New Recording 24)
there will be a button to end your call,
10:45
S…
Speaker 1 (New Recording 24)
there will be a button to send an SMS So everything will be on that buttons,
10:49
S…
Speaker 2 (New Recording 24)
right?
10:49
S…
Speaker 1 (New Recording 24)
So if you press that button that action has happened
10:53
S…
Speaker 1 (New Recording 24)
Right, so if you see the attacks that commonly happens here the classic attacks
10:57
S…
Speaker 1 (New Recording 24)
will be on this like fake coin sounds Right,
11:02
S…
Speaker 1 (New Recording 24)
so that will be triggered because the metering happens based on the power they
11:06
S…
Speaker 1 (New Recording 24)
try to create a fake magic buttons
11:09
S…
Speaker 1 (New Recording 24)
If you press one button,
11:10
S…
Speaker 1 (New Recording 24)
it automatically triggers to press another button.
11:13
S…
Speaker 1 (New Recording 24)
That magic button,
11:14
S…
Speaker 1 (New Recording 24)
then call an identity disruption,
11:16
S…
Speaker 1 (New Recording 24)
like faking your identity as their identity and line tapping,
11:20
S…
Speaker 1 (New Recording 24)
like wire tapping.
11:21
S…
Speaker 1 (New Recording 24)
They do line tapping.
11:22
S…
Speaker 1 (New Recording 24)
These were happening in your wired telephone
11:27
S…
Speaker 2 (New Recording 24)
systems.
11:27
S…
Speaker 1 (New Recording 24)
In wired telephone systems,
11:30
S…
Speaker 1 (New Recording 24)
this call maturing can be easily attacked with these types.
11:33
S…
Speaker 1 (New Recording 24)
To avoid this,
11:36
S…
Speaker 1 (New Recording 24)
They have like a human verification electrical signaling
11:40
S…
Speaker 1 (New Recording 24)
and They call call and authentication today
11:45
S…
Speaker 1 (New Recording 24)
everything is wireless Whatever happens they evaluate with
11:49
S…
Speaker 1 (New Recording 24)
your sim card.
11:49
S…
Speaker 1 (New Recording 24)
They don't evaluate with the phone what I attend what I?
11:53
S…
Speaker 1 (New Recording 24)
They take care with your sim card what your
11:57
S…
Speaker 1 (New Recording 24)
sim card send and receive to your phone networks
12:01
S…
Speaker 1 (New Recording 24)
So since they focus on your SIM card,
12:03
S…
Speaker 1 (New Recording 24)
manipulating your SIM card is quite fast.
12:05
S…
Speaker 1 (New Recording 24)
It will use some enormous technology to differ itself.
12:09
S…
Speaker 1 (New Recording 24)
So today this attack is no more,
12:11
S…
Speaker 1 (New Recording 24)
but in the earlier days of your button systems,
12:14
S…
Speaker 1 (New Recording 24)
this was happening because of lack of authentication.
12:18
S…
Speaker 1 (New Recording 24)
Since there is any single sense to your phone network,
12:22
S…
Speaker 1 (New Recording 24)
there is no authentication.
12:23
S…
Speaker 1 (New Recording 24)
So that is the reason why these attacks were happening by manipulating
12:28
S…
Speaker 2 (New Recording 24)
your phone devices.
12:29
S…
Speaker 1 (New Recording 24)
But today,
12:30
S…
Speaker 1 (New Recording 24)
since we made everything as a digital signal,
12:32
S…
Speaker 1 (New Recording 24)
this attack is quite hard.
12:34
S…
Speaker 1 (New Recording 24)
Everything is your SIM card.
12:36
S…
Speaker 2 (New Recording 24)
So,
12:37
S…
Speaker 1 (New Recording 24)
if you put all the planes to one place,
12:40
S…
Speaker 1 (New Recording 24)
the attacker will also target your place.
12:43
S…
Speaker 1 (New Recording 24)
If you have seen your SIM card place,
12:46
S…
Speaker 1 (New Recording 24)
it has been made with a coil where none of the signals can
12:50
S…
Speaker 1 (New Recording 24)
affect your SIM card.
12:52
S…
Speaker 1 (New Recording 24)
They try to protect your SIM card in an effective way.
12:55
S…
Speaker 1 (New Recording 24)
so that is why this phone call metering attack is not possible but
13:00
S…
Speaker 1 (New Recording 24)
can they manipulate the data that has been
13:04
S…
Speaker 1 (New Recording 24)
sent from your sim card to your mobile so if
13:09
S…
Speaker 1 (New Recording 24)
the problem comes on the second phase called signal so
13:14
S…
Speaker 1 (New Recording 24)
i cannot target your sim card i cannot manipulate your sim card
13:18
S…
Speaker 1 (New Recording 24)
but your sim card gives data to your mobile
13:22
S…
Speaker 1 (New Recording 24)
can that signal can be bypassed
13:27
S…
Speaker 2 (New Recording 24)
Yes.
13:27
S…
Speaker 2 (New Recording 24)
So here if you see,
13:29
S…
Speaker 1 (New Recording 24)
in signaling,
13:30
S…
Speaker 1 (New Recording 24)
it does call setup,
13:32
S…
Speaker 1 (New Recording 24)
routing and termination.
13:34
S…
Speaker 1 (New Recording 24)
So if you are going to make a call,
13:36
S…
Speaker 1 (New Recording 24)
so there must be a path from your mobile phone to the receiver
13:40
S…
Speaker 2 (New Recording 24)
mobile phone.
13:41
S…
Speaker 1 (New Recording 24)
A call setup and routing will be done.
13:43
S…
Speaker 1 (New Recording 24)
And when you disconnect,
13:44
S…
Speaker 1 (New Recording 24)
the termination needs to be done.
13:46
S…
Speaker 1 (New Recording 24)
So there is a process in your connectivity.
13:48
S…
Speaker 1 (New Recording 24)
If you are going to connect two mobile phones by voice data
13:52
S…
Speaker 1 (New Recording 24)
or your digital data,
13:56
S…
Speaker 1 (New Recording 24)
Voice data,
13:57
S…
Speaker 1 (New Recording 24)
we need a dedicated call center,
13:59
S…
Speaker 1 (New Recording 24)
we need a dedicated path to reach your destination.
14:02
S…
Speaker 1 (New Recording 24)
This can be manipulated.
14:05
S…
Speaker 1 (New Recording 24)
If you see here,
14:06
S…
Speaker 1 (New Recording 24)
there are some core vulnerabilities called in -band signaling and injecting
14:11
S…
Speaker 2 (New Recording 24)
the control nodes.
14:12
S…
Speaker 1 (New Recording 24)
So that was why today,
14:14
S…
Speaker 1 (New Recording 24)
the signaling has been made with adopt signals.
14:17
S…
Speaker 2 (New Recording 24)
What is adopt?
14:18
S…
Speaker 2 (New Recording 24)
What do you mean by adopt?
14:20
S…
Speaker 2 (New Recording 24)
Temporary.
14:23
S…
Speaker 1 (New Recording 24)
Previously, we had a fixed signal like ETA.
14:26
S…
Speaker 1 (New Recording 24)
We have a dedicated connection with your mobile network.
14:29
S…
Speaker 1 (New Recording 24)
There will be a dedicated wireless connectivity with your mobile phone.
14:33
S…
Speaker 1 (New Recording 24)
But today,
14:34
S…
Speaker 1 (New Recording 24)
to avoid these problems,
14:36
S…
Speaker 1 (New Recording 24)
if you see here,
14:36
S…
Speaker 1 (New Recording 24)
the vulnerabilities of in -band sickening and in -jet camera phones,
14:40
S…
Speaker 2 (New Recording 24)
because of that,
14:41
S…
Speaker 1 (New Recording 24)
we had force clicking and blue box.
14:43
S…
Speaker 1 (New Recording 24)
These two attacks were happening.
14:45
S…
Speaker 1 (New Recording 24)
They were taking the control of your channel and trying to manipulate the data
14:49
S…
Speaker 1 (New Recording 24)
that has been sent to your mobile phone.
14:51
S…
Speaker 1 (New Recording 24)
To avoid this problem,
14:53
S…
Speaker 1 (New Recording 24)
today we will use at -hoc signals.
14:55
S…
Speaker 2 (New Recording 24)
What does autopsy mean?
14:56
S…
Speaker 2 (New Recording 24)
Set up for a rising.
14:57
S…
Speaker 2 (New Recording 24)
Today,
14:58
S…
Speaker 2 (New Recording 24)
you use not today.
15:00
S…
Speaker 1 (New Recording 24)
this minute you use a particular channel next minute you use a different channel
15:04
S…
Speaker 1 (New Recording 24)
so the channel that we use to connect your mobile station is
15:08
S…
Speaker 1 (New Recording 24)
dynamic so there is no fixed channel so they cannot do
15:12
S…
Speaker 1 (New Recording 24)
these attacks okay but previously it is a fixed channel even when
15:17
S…
Speaker 1 (New Recording 24)
you connect your wi -fi in this classroom it is a fixed
15:21
S…
Speaker 1 (New Recording 24)
channel
15:21
S…
Speaker 1 (New Recording 24)
They use a dedicated port to connect.
15:23
S…
Speaker 1 (New Recording 24)
So if anyone gains access of this signaling,
15:27
S…
Speaker 1 (New Recording 24)
they can manipulate the data that is sent to your Wi -Fi.
15:30
S…
Speaker 1 (New Recording 24)
So this problem has been avoided in your mobile technology
15:34
S…
Speaker 1 (New Recording 24)
using adoption.
15:35
S…
Speaker 1 (New Recording 24)
That is what they say,
15:37
S…
Speaker 1 (New Recording 24)
out -of -band signaling.
15:38
S…
Speaker 1 (New Recording 24)
There is a separate control network
15:43
S…
Speaker 1 (New Recording 24)
which provides you a dynamic signal for connecting.
15:46
S…
Speaker 1 (New Recording 24)
Every 3 seconds your mobile phone responds to your mobile
15:50
S…
Speaker 1 (New Recording 24)
network.
15:51
S…
Speaker 1 (New Recording 24)
which we call it as a heartbeat reporting.
15:53
S…
Speaker 1 (New Recording 24)
Whether your device is live or not,
15:56
S…
Speaker 1 (New Recording 24)
we call it as this heartbeat reporting to your mobile network.
15:59
S…
Speaker 1 (New Recording 24)
That every 3 seconds it uses a different channel for recording.
16:02
S…
Speaker 1 (New Recording 24)
So it is very hard to perform this heartbeat.
16:07
S…
Speaker 1 (New Recording 24)
This is about the connectivity.
16:09
S…
Speaker 1 (New Recording 24)
Third is routing.
16:11
S…
Speaker 1 (New Recording 24)
Can a mobile stations can be hacked?
16:15
S…
Speaker 1 (New Recording 24)
The towers can be hacked.
16:16
S…
Speaker 1 (New Recording 24)
So that is the switching and configuration.
16:19
S…
Speaker 1 (New Recording 24)
So if you take here switching and configuration,
16:22
S…
Speaker 1 (New Recording 24)
which should try to make a path to connect between two entities.
16:26
S…
Speaker 1 (New Recording 24)
That path can be manipulated.
16:29
S…
Speaker 1 (New Recording 24)
So there are many common attacks.
16:31
S…
Speaker 1 (New Recording 24)
You see here land travel,
16:32
S…
Speaker 1 (New Recording 24)
self -privileged installation,
16:34
S…
Speaker 1 (New Recording 24)
social engineering.
16:35
S…
Speaker 1 (New Recording 24)
So these three common attacks happen in the switching and configuration where
16:40
S…
Speaker 1 (New Recording 24)
the routing between the source and destination will be manipulated.
16:44
S…
Speaker 1 (New Recording 24)
To avoid this,
16:45
S…
Speaker 1 (New Recording 24)
today they use the separate standards to control the communication
16:50
S…
Speaker 1 (New Recording 24)
between the towers.
16:51
S…
Speaker 1 (New Recording 24)
It will be like an internal network security,
16:55
S…
Speaker 1 (New Recording 24)
they provide security for the two mobile towers.
16:58
S…
Speaker 1 (New Recording 24)
After this,
17:00
S…
Speaker 1 (New Recording 24)
the N systems,
17:01
S…
Speaker 1 (New Recording 24)
the hardware that we use,
17:03
S…
Speaker 1 (New Recording 24)
which is the insecure N systems.
17:05
S…
Speaker 1 (New Recording 24)
If your mobile phone is not safe,
17:07
S…
Speaker 1 (New Recording 24)
if you download any malicious program to your mobile phone,
17:11
S…
Speaker 1 (New Recording 24)
Without, you will not see anything on your display.
17:14
S…
Speaker 1 (New Recording 24)
But it can make a call,
17:16
S…
Speaker 1 (New Recording 24)
it can send and receive data,
17:17
S…
Speaker 1 (New Recording 24)
it can send SMS.
17:19
S…
Speaker 1 (New Recording 24)
Even if you receive an OTP,
17:21
S…
Speaker 1 (New Recording 24)
it can fetch.
17:22
S…
Speaker 1 (New Recording 24)
There are some apps which can read your messages.
17:25
S…
Speaker 1 (New Recording 24)
For example,
17:26
S…
Speaker 1 (New Recording 24)
there is an app called TrueCaller.
17:28
S…
Speaker 1 (New Recording 24)
So if I install TrueCaller,
17:31
S…
Speaker 1 (New Recording 24)
it can read my call,
17:32
S…
Speaker 1 (New Recording 24)
it can read my SMS,
17:34
S…
Speaker 1 (New Recording 24)
it can read any notification that comes to my mobile phone.
17:37
S…
Speaker 1 (New Recording 24)
So it can read.
17:39
S…
Speaker 1 (New Recording 24)
We think that true caller is safe.
17:41
S…
Speaker 1 (New Recording 24)
If anyone can manipulate that true caller,
17:43
S…
Speaker 1 (New Recording 24)
then they can fix the data by the true caller
17:47
S…
Speaker 1 (New Recording 24)
reading and they can use it for their benefits.
17:50
S…
Speaker 1 (New Recording 24)
If you see here like voice call hacking,
17:52
S…
Speaker 1 (New Recording 24)
PBX fraud which is like the dialing of using stuff and mobile
17:56
S…
Speaker 1 (New Recording 24)
manuals.
17:57
S…
Speaker 1 (New Recording 24)
So these attacks happen to your mobile phone.
18:01
S…
Speaker 1 (New Recording 24)
Why?
18:01
S…
Speaker 1 (New Recording 24)
To steal your stuff.
18:03
S…
Speaker 1 (New Recording 24)
For example, if you touch anything,
18:04
S…
Speaker 1 (New Recording 24)
it will take a screenshot.
18:07
S…
Speaker 1 (New Recording 24)
And it will be sending it to your attacker.
18:09
S…
Speaker 1 (New Recording 24)
So when you touch a password your keyboard screenshot like a key logger it
18:13
S…
Speaker 1 (New Recording 24)
can record your ping and they can use it against you.
18:16
S…
Speaker 1 (New Recording 24)
And they can link your account to any other third
18:20
S…
Speaker 1 (New Recording 24)
party like Google Pay or Sunset Pay and they can fetch your accounts from the banking.
18:24
S…
Speaker 1 (New Recording 24)
So all these things will happen if your end systems are insecure.
18:29
S…
Speaker 1 (New Recording 24)
So we need to have an effective defensive mechanism to protect.
18:33
S…
Speaker 1 (New Recording 24)
So the simple thing is,
18:34
S…
Speaker 1 (New Recording 24)
there are three recommendations.
18:36
S…
Speaker 1 (New Recording 24)
Don't use any default settings.
18:39
S…
Speaker 1 (New Recording 24)
Customize.
18:40
S…
Speaker 1 (New Recording 24)
Try to customize based on your need and usage.
18:43
S…
Speaker 1 (New Recording 24)
If you have any unused feature,
18:45
S…
Speaker 1 (New Recording 24)
disable it.
18:46
S…
Speaker 1 (New Recording 24)
Restrict.
18:47
S…
Speaker 1 (New Recording 24)
Remove all the permissions of those apps.
18:50
S…
Speaker 1 (New Recording 24)
And monitor the usage and permissions.
18:52
S…
Speaker 1 (New Recording 24)
Today, we have GPT's to monitor your mobile phone.
18:56
S…
Speaker 1 (New Recording 24)
You can learn like what happens in your mobile phone.
18:59
S…
Speaker 1 (New Recording 24)
Samsung released a version of that app.
19:03
S…
Speaker 1 (New Recording 24)
It will work only on a Samsung phone.
19:05
S…
Speaker 1 (New Recording 24)
It will be like a local application.
19:07
S…
Speaker 1 (New Recording 24)
It will analyze your mobile phone and every day you can see a look.
19:11
S…
Speaker 1 (New Recording 24)
Like this application uses network for what?
19:15
S…
Speaker 1 (New Recording 24)
What data has been sent and received.
19:16
S…
Speaker 1 (New Recording 24)
You can see the log,
19:18
S…
Speaker 1 (New Recording 24)
analysis with the AR and you can find anything for sure.
19:21
S…
Speaker 1 (New Recording 24)
So we need to have some solutions to monitor your mobile
19:25
S…
Speaker 1 (New Recording 24)
devices.
19:26
S…
Speaker 1 (New Recording 24)
Next one is VOIP.
19:29
S…
Speaker 1 (New Recording 24)
Today we avoid using normal calls.
19:32
S…
Speaker 1 (New Recording 24)
Why everyone doesn't WhatsApp,
19:36
S…
Speaker 1 (New Recording 24)
Instagram,
19:36
S…
Speaker 1 (New Recording 24)
Telegrams.
19:38
S…
Speaker 1 (New Recording 24)
So even if you want to contact them,
19:40
S…
Speaker 1 (New Recording 24)
you try to use those applications.
19:42
S…
Speaker 1 (New Recording 24)
So that we make a call through internet services.
19:46
S…
Speaker 1 (New Recording 24)
We will not use your voice network,
19:49
S…
Speaker 1 (New Recording 24)
we will use your data network.
19:51
S…
Speaker 1 (New Recording 24)
So in EOIPs,
19:52
S…
Speaker 1 (New Recording 24)
today we have AI -justifying apps.
19:55
S…
Speaker 1 (New Recording 24)
If you are going to receive some calls,
19:58
S…
Speaker 1 (New Recording 24)
even the AI we can make a call.
20:00
S…
Speaker 1 (New Recording 24)
AI can talk with you,
20:01
S…
Speaker 1 (New Recording 24)
AI can interact like a human being.
20:03
S…
Speaker 1 (New Recording 24)
So whenever we use this voice calls,
20:05
S…
Speaker 1 (New Recording 24)
we need to be alert on that.
20:08
S…
Speaker 1 (New Recording 24)
Someone can misuse.
20:10
S…
Speaker 1 (New Recording 24)
For example,
20:10
S…
Speaker 1 (New Recording 24)
WhatsApp,
20:11
S…
Speaker 1 (New Recording 24)
we have a recent update.
20:14
S…
Speaker 1 (New Recording 24)
You can install the same across WhatsApp in multiple devices,
20:18
S…
Speaker 1 (New Recording 24)
but you can use WhatsApp calls only on a certain device.
20:22
S…
Speaker 1 (New Recording 24)
You can restrict it.
20:23
S…
Speaker 1 (New Recording 24)
Where do you bring that policy?
20:27
S…
Speaker 1 (New Recording 24)
Because if you are going to enable all services,
20:29
S…
Speaker 1 (New Recording 24)
suppose I use three devices and all the three enable WhatsApp account.
20:33
S…
Speaker 1 (New Recording 24)
So from any device I can make a call.
20:35
S…
Speaker 1 (New Recording 24)
So from any device I can make a call,
20:39
S…
Speaker 1 (New Recording 24)
so I can make a call,
20:40
S…
Speaker 1 (New Recording 24)
so that is fine.
20:41
S…
Speaker 1 (New Recording 24)
If someone can misuse that application,
20:43
S…
Speaker 1 (New Recording 24)
if one of my devices is vulnerable and some malicious wrong controls
20:47
S…
Speaker 1 (New Recording 24)
my WhatsApp, it can send a call,
20:49
S…
Speaker 1 (New Recording 24)
it can send a text to anyone.
20:52
S…
Speaker 1 (New Recording 24)
So until unless it will be notified to me,
20:54
S…
Speaker 1 (New Recording 24)
I will not be aware of that.
20:56
S…
Speaker 1 (New Recording 24)
So in VOID,
Dit transcript werd gegenereerd door AI (automatische spraakherkenning). Kan fouten bevatten..verifieer tegen de oorspronkelijke audio voor kritisch gebruik. AI-beleid
Samenvatting
Klik op Summarize om een AI samenvatting van dit transcript te genereren.
Samengevat...
Vraag AI over dit Transcript
Vraag maar iets over dit transcript De AI zal relevante secties en antwoord vinden.