Leveraging private APNs for mobile network traffic analysis

Aapo Oksman

DEF CON 32 Main Stage · Day 1 · Main Stage

Overview

In an era where ubiquitous connectivity defines our digital landscape, the security of mobile network traffic remains a critical yet often overlooked frontier. Aapo Oksman's DEF CON 32 talk, "Leveraging private APNs for mobile network traffic analysis," delves into the significant challenges of monitoring and securing data transmitted over cellular networks, particularly for Internet of Things (IoT) and other specialized devices. While traditional network analysis tools suffice for Ethernet or Wi-Fi traffic, the unique architecture of cellular networks often renders these methods ineffective, creating a blind spot for security professionals and privacy-conscious users alike.

Watch on YouTube

Visual summary for Leveraging private APNs for mobile network traffic analysis by Aapo Oksman
Visual summary for Leveraging private APNs for mobile network traffic analysis by Aapo Oksman

Key moments

  1. 2:00 The challenge of analyzing cellular-only device traffic
  2. 2:50 Key reasons to analyze mobile network traffic
  3. 4:45 Understanding mobile network fundamentals
  4. 6:40 How devices interface with cellular modems
  5. 8:45 Leveraging private APNs for traffic interception
  6. 9:40 Essential for advanced mobile malware detection

Leveraging Private APNs for Mobile Network Traffic Analysis

Speakers: Aapo Oksman

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=4lQ2GnmTFkY

Overview

In an era where ubiquitous connectivity defines our digital landscape, the security of mobile network traffic remains a critical yet often overlooked frontier. Aapo Oksman's DEF CON 32 talk, "Leveraging private APNs for mobile network traffic analysis," delves into the significant challenges of monitoring and securing data transmitted over cellular networks, particularly for Internet of Things (IoT) and other specialized devices. While traditional network analysis tools suffice for Ethernet or Wi-Fi traffic, the unique architecture of cellular networks often renders these methods ineffective, creating a blind spot for security professionals and privacy-conscious users alike.

Oksman, a seasoned security researcher with expertise in IoT, cryptography, and network protocols, highlights that many modern devices, especially those in industrial IoT (IIoT) or embedded systems, rely exclusively on cellular connectivity (e.g., 4G, 5G, NB-IoT). This presents a formidable obstacle to understanding device behavior, detecting malicious activity, or conducting thorough security audits. The talk proposes a powerful solution: the strategic implementation of private Access Point Names (APNs) to gain unparalleled visibility and control over mobile network traffic, offering a robust mechanism for both offensive and defensive security operations. This approach is particularly vital for organizations targeted by advanced persistent threats where on-device security measures may be compromised.

The core premise of Oksman's presentation is that by routing cellular traffic through a controlled, private infrastructure, organizations can achieve the same level of granular inspection and policy enforcement typically associated with wired or Wi-Fi networks. This capability addresses a crucial gap in enterprise security, enabling comprehensive monitoring for data exfiltration, command-and-control communications, and privacy breaches that would otherwise go undetected. For anyone involved in securing modern connected devices, understanding and implementing private APNs as a traffic analysis mechanism is becoming an indispensable tool.

Background

▶ Watch: The challenge of analyzing cellular-only device traffic (2:00)

The pervasive nature of the Internet of Things (IoT) has led to an explosion in devices that connect to the internet in novel ways. While many traditional computing devices, like laptops or desktop PCs, rely on wired Ethernet or Wi-Fi for connectivity, a growing segment of IoT, particularly in industrial, automotive, and remote sensing applications, leverages cellular networks. These devices often prioritize cost-efficiency and specialized functionality, leading to designs that frequently omit conventional network interfaces in favor of integrated cellular modems. This architectural choice, while practical for deployment, introduces significant hurdles for security analysis.

For devices connected via Ethernet or Wi-Fi, traffic monitoring is relatively straightforward. An analyst can simply place their laptop in-line with an Ethernet cable, configure a Wi-Fi access point to act as a man-in-the-middle, or use network taps and promiscuous mode sniffing. Tools like Wireshark or tcpdump can then capture and analyze all incoming and outgoing packets, revealing communication patterns, protocols, and potential vulnerabilities. However, this simplicity vanishes when dealing with cellular connections.

Cellular networks, often referred to as mobile networks, operate on a fundamentally different paradigm. They encompass various generations, from 2G and 3G to the widely adopted 4G LTE, and the rapidly expanding 5G, along with specialized variants like NB-IoT (Narrowband IoT) designed for low-power, wide-area communication. These networks rely on specific frequency bands and proprietary radio protocols, making direct "eavesdropping" with standard network tools virtually impossible for an external observer. Unlike Wi-Fi, where a device connects to a local access point, cellular devices communicate with a mobile network operator's (MNO) base stations, which are distributed across vast geographical areas.

The core component enabling cellular connectivity in devices is the modem. These are highly complex, specialized mini-computers often running their own embedded operating systems. They handle the intricate details of cellular communication, including radio modulation, authentication with the network via a Subscriber Identity Module (SIM) card, and the establishment of an IP connection. From the device's main CPU (which might run Linux, Windows, or a real-time operating system), the modem often appears as a network interface, abstracting away the underlying cellular complexities. This abstraction, while simplifying development, creates a "black box" scenario for security analysts. The traffic leaves the device, enters the MNO's infrastructure, and then typically exits to the public internet, all without an easily accessible point for interception or inspection by the device owner or security team.

This lack of visibility poses substantial risks. For privacy-conscious users, it means an inability to verify what data their devices are sending to unknown servers, potentially including unencrypted personal information. For offensive security professionals conducting penetration tests, the inability to observe or tamper with cellular traffic represents a significant blind spot, potentially leading to incomplete security audits. From a defensive perspective, the challenge is even greater: advanced malware or compromised firmware on a device might bypass on-device security measures (like endpoint detection and response or VPNs) and communicate exclusively over the cellular link, completely evading detection by local network monitoring. Identifying and mitigating such threats necessitates a method to gain control over the cellular traffic stream itself, a challenge that traditional security tools are ill-equipped to meet.

Key Findings

▶ Watch: Understanding mobile network fundamentals (4:45)

The central revelation of Aapo Oksman's talk is that private Access Point Names (APNs) offer a robust, scalable, and enterprise-grade solution for gaining comprehensive visibility and control over mobile network traffic from connected devices. This approach effectively transforms the "black box" of cellular communication into a transparent, manageable conduit for security analysis. By leveraging private APNs, organizations can overcome the inherent challenges of monitoring cellular traffic, which are otherwise inaccessible through conventional network sniffing or on-device software.

Oksman demonstrates that instead of allowing devices to connect to the public internet via a standard, public APN provided by the mobile network operator, a private APN can be established. This private APN effectively redirects all cellular data traffic from designated devices through a customer-controlled network infrastructure. This redirection occurs at the mobile network operator's core network level, meaning that the traffic is routed to the customer's server or firewall before it ever reaches the public internet.

This capability is a game-changer for several reasons:

  1. Full Traffic Visibility: It provides a direct point of interception for all IP traffic originating from or destined for cellular-connected devices, enabling deep packet inspection, logging, and real-time analysis.
  2. Bypassing On-Device Protections: Since the interception occurs external to the device, even sophisticated malware or compromised operating systems that might disable or evade on-device security agents (like VPNs or endpoint protection) cannot circumvent this network-level control. The traffic simply must pass through the private APN infrastructure.
  3. Centralized Control and Policy Enforcement: Organizations can implement unified security policies, firewall rules, intrusion detection systems, and data loss prevention mechanisms at a central point, applying them consistently across an entire fleet of cellular-connected devices, regardless of their physical location.
  4. Scalability and Cost-Effectiveness: While initial setup may involve some cost, the speaker notes that for thousands of devices, the per-device cost becomes "quite inexpensive." This makes private APNs a viable solution for large-scale IoT deployments.

In essence, the key finding is that private APNs provide the missing link for securing cellular IoT and mobile device ecosystems, offering a powerful mechanism to ensure privacy, detect threats, and maintain compliance in environments increasingly reliant on mobile connectivity.

Technical Deep Dive

▶ Watch: How devices interface with cellular modems (6:40)

At the heart of cellular communication lies the Access Point Name (APN). An APN is essentially a gateway that connects a mobile device to a data network. When a device with a SIM card establishes a data connection (e.g., 4G or 5G), it sends a request to the mobile network operator (MNO) specifying an APN. This APN determines the type of network connection and the specific services it can access. For most consumers, this is a generic public APN (e.g., "internet.mnc001.mcc001.gprs") that routes traffic directly to the public internet. However, the true power for security analysis emerges with private APNs.

A private APN functions differently. Instead of directing traffic to the public internet, it routes all data from subscribed SIM cards to a dedicated, secure network infrastructure controlled by the customer. This infrastructure can be a private server, a corporate firewall, or a specialized security appliance. The process typically involves a contractual agreement with an MNO, where the MNO provisions a unique APN for the customer and configures their core network to forward all traffic associated with that APN to a specified endpoint.

The architecture for leveraging private APNs for traffic analysis can be broken down into several key components and data flow stages:

  1. The Mobile Device: This could be an IoT device, an industrial sensor, or even a smartphone. It contains a modem (often a sophisticated mini-computer running its own OS) and a SIM card. The device's operating system (Linux, Windows, RTOS) communicates with the modem, offloading the complexities of cellular connectivity. Crucially, the device is configured to use the specific private APN provided by the customer. This configuration can often be pushed remotely or set during manufacturing.
  1. The SIM Card: The SIM card plays a vital role in authenticating the device to the mobile network. For private APN setups, the SIM cards are often specially provisioned by the MNO to be associated with the customer's private APN. This ensures that only authorized devices can access the private network.
  1. Mobile Network Operator (MNO) Infrastructure: When the device powers on and connects, its modem communicates with the MNO's base stations (cell towers). The SIM card authenticates the device to the MNO's core network. Instead of routing the IP traffic through the MNO's standard internet gateway, the MNO's Gateway GPRS Support Node (GGSN) or Packet Gateway (PGW) identifies the private APN and, based on the customer's agreement, establishes a secure tunnel (often an IPsec tunnel) to the customer's designated endpoint.
  1. Customer's Private Network Endpoint: This is the critical component for analysis. It can be:
  • A dedicated server: A Linux server running tools like Wireshark, tcpdump, Suricata, or Zeek can capture, log, and analyze all incoming and outgoing packets.
  • An existing corporate firewall: Integrating the private APN with an enterprise firewall allows the application of existing security policies, intrusion prevention systems (IPS), and content filtering rules to cellular traffic.
  • A Security Information and Event Management (SIEM) system: Traffic logs and alerts generated from the analysis can be fed into a SIEM for centralized monitoring, correlation, and incident response.

The data flow is therefore:

Device (Modem + SIM) -> MNO Base Station -> MNO Core Network (identifies private APN) -> Secure Tunnel (e.g., IPsec) -> Customer's Server/Firewall -> Internet (if allowed by customer's policies).

This architecture provides an unparalleled vantage point. All traffic, whether encrypted or not, passes through the customer's control point. While the content of encrypted traffic (e.g., HTTPS) remains opaque without further decryption (e.g., through TLS interception, which is a separate challenge), the metadata (source/destination IP, port, protocol, volume, timing) is fully visible. This allows for:

  • Protocol Analysis: Identifying unusual or unauthorized protocols.
  • Domain Name System (DNS) Monitoring: Detecting communication with known malicious domains or suspicious C2 (Command and Control) servers.
  • Anomaly Detection: Flagging deviations from normal device behavior, such as sudden spikes in data usage or connections to unexpected geographical locations.
  • Policy Enforcement: Blocking unwanted traffic, restricting access to specific services, or enforcing time-based communication windows.

The speaker emphasizes that the modems themselves are complex, often running separate operating systems. This complexity means that even if the main device OS is compromised, the modem's behavior might be difficult to alter without deep hardware access. However, by controlling the APN, the network path can be controlled regardless of the device's internal state. This makes private APNs a robust defense against advanced malware that might attempt to bypass on-device security layers. The setup costs, while present, become economically viable for organizations managing "thousands of devices," demonstrating scalability.

Demo / Proof of Concept

▶ Watch: Leveraging private APNs for traffic interception (8:45)

While the talk did not feature a live, detailed technical demonstration of a private APN setup in action, Aapo Oksman clearly outlined the conceptual framework and the practical implications of such a deployment. The "proof of concept" is inherent in the architecture described: routing all mobile network traffic from target devices to a user-controlled endpoint, such as a private server or an existing corporate firewall.

The speaker explicitly mentions the possibility of connecting an IPsec tunnel from the private APN gateway to an "existing firewall" or "my server." This statement serves as the conceptual demonstration of how the solution works. In a practical setup, an analyst would configure a device with a SIM card provisioned for the private APN. Once the device connects, all its cellular traffic would be directed through the MNO's infrastructure and then via the IPsec tunnel to the analyst's chosen network appliance.

On this endpoint, standard network analysis tools would be employed. For example, a Linux server receiving the traffic could run:

  • tcpdump or Wireshark: To capture and inspect raw packet data, revealing communication patterns, protocols, and data payloads (if unencrypted).
  • Suricata or Zeek: To perform deep packet inspection, identify known threats, detect anomalies, and generate detailed network logs.
  • Firewall rules (e.g., iptables): To filter, block, or redirect specific types of traffic based on source/destination, port, or protocol.

The outcome of such a conceptual demonstration would be the undeniable visibility of all cellular traffic, enabling the analyst to:

  • Identify all external endpoints the device communicates with.
  • Determine the types of data being transmitted.
  • Detect attempts to connect to unauthorized servers or services.
  • Observe traffic patterns that might indicate malicious activity, even if the on-device security has been compromised.

Thus, while a step-by-step live demo was not presented, the talk effectively demonstrated how a private APN setup acts as a powerful proof of concept for comprehensive mobile network traffic analysis.

Defensive Implications

▶ Watch: Essential for advanced mobile malware detection (9:40)

The strategic implementation of private APNs offers profound defensive advantages, transforming a significant blind spot in network security into a robust point of control and visibility. For organizations operating large fleets of IoT devices, critical infrastructure, or managing employee mobile devices, the ability to analyze and control cellular traffic at the network edge is indispensable.

  1. Comprehensive Traffic Visibility and Logging: Private APNs provide a centralized choke point for all cellular traffic. This means every packet originating from or destined for a connected device passes through the organization's controlled infrastructure. This allows for comprehensive logging, enabling detailed audit trails, forensic investigations, and compliance reporting that would be impossible with traditional methods. Security teams can capture full packet data, metadata, and flow information, feeding it into Security Information and Event Management (SIEM) systems for correlation and long-term storage.
  1. Detection of Advanced Malware and Evasion Techniques: A key vulnerability highlighted by Oksman is that "mobile phone malware infections might not communicate at all over VPN or wifi." Advanced persistent threats (APTs) and sophisticated malware often target the operating system at a low level, allowing them to bypass on-device security controls like VPN clients, endpoint detection and response (EDR) agents, or local firewalls. By communicating directly over the cellular modem, such malware can exfiltrate data or receive command-and-control (C2) instructions undetected. A private APN, however, intercepts this traffic before it reaches the public internet, making it an invaluable tool for detecting and neutralizing these elusive threats.
  1. Centralized Policy Enforcement and Filtering: Instead of relying on individual device configurations, which can be tampered with or misconfigured, security policies can be enforced centrally at the private APN gateway. This allows organizations to:
  • Filter unwanted traffic: Block connections to known malicious IP addresses, restrict access to specific domains, or prevent communication over unauthorized ports.
  • Enforce geographical restrictions: Limit device communication to specific regions or countries.
  • Implement data loss prevention (DLP): Monitor and prevent the exfiltration of sensitive data over cellular links.
  • Control device behavior: Restrict devices to only communicate with whitelisted servers, ensuring they only perform their intended functions.
  1. Enhanced Incident Response: In the event of a suspected compromise, the logs and real-time traffic analysis from a private APN can significantly accelerate incident response. Security analysts can quickly identify the source of anomalous traffic, pinpoint compromised devices, and enact immediate mitigation strategies (e.g., blocking a device's cellular access or isolating it) directly from their network control center.
  1. Protection for Critical IoT and IIoT Deployments: Industrial IoT (IIoT) devices, remote sensors, and critical infrastructure components often rely on cellular connectivity in isolated or hostile environments. The security of these devices is paramount. Private APNs provide a robust perimeter defense, ensuring that even if an IIoT device is physically tampered with or infected, its network communications remain under strict scrutiny and control, preventing potential disruptions or sabotage.
  1. Privacy and Regulatory Compliance: For organizations handling sensitive data, private APNs help ensure that cellular traffic adheres to privacy regulations (e.g., GDPR, CCPA). By routing traffic through a controlled environment, data exfiltration attempts are detectable, and the organization can maintain a clear chain of custody for all mobile data, demonstrating due diligence in protecting user privacy.

In summary, private APNs empower defenders with an essential capability: extending enterprise-grade network security and monitoring to the increasingly critical domain of cellular-connected devices, thereby closing a significant security gap.

Key Takeaways

  • Cellular Traffic is a Blind Spot: Traditional network analysis tools are ineffective for monitoring mobile network traffic, creating a significant security and privacy gap for IoT and other cellular-connected devices.
  • Private APNs Offer Unparalleled Visibility: By establishing a private Access Point Name (APN), organizations can route all cellular traffic from their devices through a controlled, dedicated infrastructure (e.g., a server or firewall).
  • Bypasses On-Device Protections: This network-level interception mechanism is crucial for detecting advanced malware or compromised devices that might bypass or disable on-device security software.
  • Enables Centralized Security: Private APNs allow for centralized logging, deep packet inspection, policy enforcement, and threat detection, extending enterprise-grade security to mobile device fleets.
  • Critical for IoT/IIoT Security: This approach is particularly vital for securing industrial IoT, remote sensors, and other specialized devices that rely exclusively on cellular connectivity.
  • Scalable and Cost-Effective: While requiring an initial setup, the solution becomes cost-effective for large deployments, making it a viable strategy for organizations with thousands of cellular-connected devices.

About the Speaker(s)

Aapo Oksman is a dedicated security researcher and consultant with a strong focus on IoT and embedded devices. His expertise spans various critical areas, including cryptography and network protocols. Outside of his professional consulting work, Aapo is an active participant in the bug bounty community, particularly interested in hardware bug bounty programs. He also contributes to the cybersecurity community as a coach for a Finnish Capture The Flag (CTF) team, demonstrating his commitment to fostering talent and knowledge in the field. His work centers on understanding how devices operate, identifying vulnerabilities, and developing robust security solutions.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

Oksman's talk on leveraging private APNs for mobile network traffic analysis is a critical piece of defensive innovation. It addresses a glaring blind spot in modern security: the cellular network. By demonstrating how to reroute cellular device traffic through a controlled infrastructure, this research provides an indispensable mechanism for deep packet inspection, policy enforcement, and threat detection, effectively neutralizing sophisticated malware and data exfiltration attempts that bypass on-device security. This is not just a theoretical exercise; it's a highly actionable strategy that will define how serious organizations secure their IoT and mobile device fleets.

Heather Calloway (CISO) — STRONG ACCEPT

Aapo Oksman's talk on leveraging private APNs provides a critical, actionable solution to a pervasive blind spot in modern enterprise security: the unmonitored cellular traffic of IoT and mobile devices. By demonstrating how private APNs enable centralized visibility and control, the presentation offers a clear path for organizations to extend their security perimeter, mitigate significant business risks like data exfiltration and command-and-control, and achieve robust compliance in an increasingly mobile-dependent landscape. While implementation requires strategic engagement with mobile network operators, the institutional benefits for risk ownership and operational security are…

→ Top-rated talks at DEF CON 32 Main Stage

All talks from DEF CON 32 Main Stage