Cellular Metasploit: Lessons from 15 Years of Cellular Security Research
Speaker
Yongdae Kim
IEEE Fellow and Professor in the Department of
Electrical Engineering and the Graduate School of Information Security at KAIST,KAIST ICT Endowed Chair Professorship
Title
"Cellular Metasploit: Lessons from 15 Years of Cellular Security Research"
Abstract
Over the past 15 years, my research has experimentally analyzed the
security of commercial cellular ecosystems—including standards,
commercial networks, devices, and implementations. Through protocol
analysis, implementation testing, large-scale measurements, and
responsible disclosures to standards bodies, vendors, and mobile
operators, recurring structural patterns have emerged that explain why
many cellular vulnerabilities persist across generations.
In this talk, I introduce Cellular Metasploit, a conceptual framework
distilled from these empirical studies. Rather than treating
vulnerabilities as isolated bugs, it explains how assumptions in
standards, implementations, deployments, and operational practices
interact to produce exploitable weaknesses across the cellular stack.
Representative case studies and live demonstrations on commercial
systems illustrate these patterns in practice.
Finally, I discuss how these lessons can help shape 6G research. Many
recurring attack patterns are rooted in architectural decisions,
backward compatibility, and the complexity of the cellular ecosystem,
making them difficult to eliminate once standardized. Understanding
these patterns is essential to avoiding another generation of
long-lived vulnerabilities.
Speaker Bio
Yongdae Kim is an IEEE Fellow and Professor in the Department of
Electrical Engineering and the Graduate School of Information Security
at KAIST, where he holds the KAIST ICT Endowed Chair Professorship. He
is also a member of the National Academy of Engineering of Korea. He
received his Ph.D. in Computer Science from the University of Southern
California in 2002 and was a faculty member at the University of
Minnesota from 2002 to 2012. He previously served as KAIST Chair
Professor (2013–2016), Director of the KAIST Cyber Security Research
Center (2018–2020), Chair of the NDSS Steering Committee, General
Chair of ACM CCS 2021, and Program Chair of ACM WiSec 2022. His
research focuses on experimentally discovering and analyzing security
vulnerabilities in commercial cyber-physical systems, particularly
cellular networks, drones, and autonomous vehicles.