<?xml version="1.0" encoding="ISO-8859-1"?><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<front>
<journal-meta>
<journal-id>0122-3461</journal-id>
<journal-title><![CDATA[Ingeniería y Desarrollo]]></journal-title>
<abbrev-journal-title><![CDATA[Ing. Desarro.]]></abbrev-journal-title>
<issn>0122-3461</issn>
<publisher>
<publisher-name><![CDATA[Fundación Universidad del Norte]]></publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id>S0122-34612020000200279</article-id>
<article-id pub-id-type="doi">10.14482/inde.38.2.006.31</article-id>
<title-group>
<article-title xml:lang="es"><![CDATA[Ciberseguridad en las redes móviles de telecomunicaciones y su gestión de riesgos]]></article-title>
<article-title xml:lang="en"><![CDATA[Cybersecurity in Mobile Telecommunication Networks and Management Risk]]></article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Álvarez Roldán]]></surname>
<given-names><![CDATA[Miguel Ángel]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Montoya Vargas]]></surname>
<given-names><![CDATA[Héctor Fernando]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
</contrib-group>
<aff id="Af1">
<institution><![CDATA[,Instituto Tecnológico Metropolitano  ]]></institution>
<addr-line><![CDATA[ ]]></addr-line>
<country>Colombia</country>
</aff>
<aff id="Af2">
<institution><![CDATA[,Instituto Tecnológico Metropolitano  ]]></institution>
<addr-line><![CDATA[ ]]></addr-line>
<country>Colombia</country>
</aff>
<pub-date pub-type="pub">
<day>00</day>
<month>12</month>
<year>2020</year>
</pub-date>
<pub-date pub-type="epub">
<day>00</day>
<month>12</month>
<year>2020</year>
</pub-date>
<volume>38</volume>
<numero>2</numero>
<fpage>279</fpage>
<lpage>297</lpage>
<copyright-statement/>
<copyright-year/>
<self-uri xlink:href="http://www.scielo.org.co/scielo.php?script=sci_arttext&amp;pid=S0122-34612020000200279&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://www.scielo.org.co/scielo.php?script=sci_abstract&amp;pid=S0122-34612020000200279&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://www.scielo.org.co/scielo.php?script=sci_pdf&amp;pid=S0122-34612020000200279&amp;lng=en&amp;nrm=iso"></self-uri><abstract abstract-type="short" xml:lang="es"><p><![CDATA[Resumen La tecnología de redes 3.5G y 4G son actual mente las más usadas en Colombia dado el gran despliegue que han realizado los proveedores de servicios de internet, lo que supone un reto de seguridad con respecto a los diferentes ataques a dichas redes. La interceptación de datos a través de ataques de tipo hombre en el medio (MitM, por sus siglas en inglés) y la negación de servicio (DoS, por sus siglas en inglés) (en el smartphone o en la red móvil) son muy factibles. En este artículo de investigación aplicada tiene como objetivo establecer algunos riesgos y posibles impactos asociados a las redes de telecomunicaciones y cómo un atacante con poco recurso computacional puede eventualmente vulnerar el sistema, se muestran algunas vulnerabilidades de seguridad en las redes móviles, los riesgos que esto tiene y su posibilidad de explotación, así como las recomendaciones gene rales para la reducción de dichos riesgos. Para lograr lo anterior, se realizó una investigación de diferentes vulnerabilidades en estas redes de telecomunicaciones, se elaboró un mapa de riesgos para visualizar los posibles impactos, se desarrolló una prueba técnica que consolida un ataque MitM con una captura de tráfico siendo exitoso dicho ataque. Finalmente, se entregan recomendaciones de seguridad en el caso que se logren ejecutar ciberataques, con ello, poder contar con una base para el aseguramiento de redes y sistemas de telecomunicaciones, permitiendo a diferentes personas reconocer las vulnerabilidades poco exploradas en este tipo de sistemas.]]></p></abstract>
<abstract abstract-type="short" xml:lang="en"><p><![CDATA[Abstract The 3.5G and 4G network technologies are, currently, the most used in Colombia, given the great deployment that Internet service providers have made, which represents a security challenge with respect to the different attacks on these networks. The interception of data with &#8220;Man in the middle attacks&#8221; (MiTM) and denial of service - DoS (in the smartphone or in the mobile network) are very feasible. In this article of applied research aims to establish some risks and possible impacts associated with telecommunications networks and how an attacker with little computational resource can eventually compromise the system, some risk and security vulnerabilities in mobile networks and their possibility of exploitation, as well as the general recom mendations for risk reduction are studied. To achieve the above, an investigation of different vulnerabilities in these telecom munications networks was carried out, a risk map, in order to visualize the possible impacts, was made. Then, a technical test was run to capture traffic during the MiTM attack (which was successful), and as a final result, deliver recommendations in the event that they can execute cyber-attacks, with this, to be able to have a basis for the assurance of telecommunications networks and systems, allowing different people to recognize the vulnerabilities little explored in this type of systems.]]></p></abstract>
<kwd-group>
<kwd lng="es"><![CDATA[3.5G]]></kwd>
<kwd lng="es"><![CDATA[4G]]></kwd>
<kwd lng="es"><![CDATA[ataque informático]]></kwd>
<kwd lng="es"><![CDATA[ciberseguridad]]></kwd>
<kwd lng="es"><![CDATA[gestión de riesgos]]></kwd>
<kwd lng="en"><![CDATA[3.5G]]></kwd>
<kwd lng="en"><![CDATA[4G]]></kwd>
<kwd lng="en"><![CDATA[computer attack]]></kwd>
<kwd lng="en"><![CDATA[cybersecurity]]></kwd>
<kwd lng="en"><![CDATA[risk management]]></kwd>
</kwd-group>
</article-meta>
</front><back>
<ref-list>
<ref id="B1">
<label>[1]</label><nlm-citation citation-type="">
<collab>Ministerio de Tecnologías de la Información y las Comunicaciones</collab>
<source><![CDATA[Boletín trimestral de las TIC, enero de 2020]]></source>
<year>2020</year>
</nlm-citation>
</ref>
<ref id="B2">
<label>[2]</label><nlm-citation citation-type="">
<collab>Ministerio de Tecnologías de la Información y las Comunicaciones</collab>
<source><![CDATA[Boletín trimestral de las TIC: cifras primer trimestre de 2019]]></source>
<year>2020</year>
</nlm-citation>
</ref>
<ref id="B3">
<label>[3]</label><nlm-citation citation-type="">
<collab>Ministerio de Tecnologías de la Información y las Comunicaciones</collab>
<source><![CDATA[Boletín trimestral de las TIC: cifras tercer trimestre 2018]]></source>
<year>2019</year>
</nlm-citation>
</ref>
<ref id="B4">
<label>[4]</label><nlm-citation citation-type="">
<collab>Gartner Group</collab>
<source><![CDATA[Gartner says global device shipments will decline 3.7 % in 2019]]></source>
<year>2019</year>
</nlm-citation>
</ref>
<ref id="B5">
<label>[5]</label><nlm-citation citation-type="">
<collab>ESET</collab>
<source><![CDATA[ESET Security Report América Latina 2019]]></source>
<year>2019</year>
</nlm-citation>
</ref>
<ref id="B6">
<label>[6]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Almanza]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[XIX Encuesta Nacional de Seguridad Informática]]></article-title>
<source><![CDATA[Sistemas]]></source>
<year>2019</year>
<edition>151</edition>
<page-range>12-41</page-range></nlm-citation>
</ref>
<ref id="B7">
<label>[7]</label><nlm-citation citation-type="">
<collab>Dinero</collab>
<source><![CDATA[Sistemas operativos iOS y Android se volvieron menos confiables en el 2017]]></source>
<year>2018</year>
</nlm-citation>
</ref>
<ref id="B8">
<label>[8]</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Domenech]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
</person-group>
<source><![CDATA[2017 registró un aumento de las vulnerabilidades en plataformas móviles]]></source>
<year>2018</year>
</nlm-citation>
</ref>
<ref id="B9">
<label>[9]</label><nlm-citation citation-type="">
<collab>National Vulnerability Database</collab>
<source><![CDATA[Statistics results of android]]></source>
<year>2019</year>
</nlm-citation>
</ref>
<ref id="B10">
<label>[10]</label><nlm-citation citation-type="">
<collab>Kaspersky Labs</collab>
<source><![CDATA[¿Qué es un ataque Man-in-the-Middle?]]></source>
<year>2013</year>
</nlm-citation>
</ref>
<ref id="B11">
<label>[11]</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Pérez]]></surname>
<given-names><![CDATA[D.]]></given-names>
</name>
<name>
<surname><![CDATA[Pico]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
</person-group>
<source><![CDATA[A practical attack against GPRS/EDGE/UMTS/HSPA mobile data communi-cations]]></source>
<year>2011</year>
</nlm-citation>
</ref>
<ref id="B12">
<label>[12]</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Grimes]]></surname>
<given-names><![CDATA[C.]]></given-names>
</name>
</person-group>
<source><![CDATA[&#8220;Man-in-the-Middle&#8221;, en Seven deadliest network attacks]]></source>
<year>2010</year>
<page-range>101-20</page-range><publisher-loc><![CDATA[Syngress ]]></publisher-loc>
<publisher-name><![CDATA[Elsevier]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B13">
<label>[13]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Conti]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[&#8220;A survey of man in the middle attacks&#8221;]]></article-title>
<source><![CDATA[IEEE Journal]]></source>
<year>2016</year>
<volume>18</volume>
<numero>3</numero>
<issue>3</issue>
<page-range>2027-51</page-range></nlm-citation>
</ref>
<ref id="B14">
<label>[14]</label><nlm-citation citation-type="">
<collab>Instituto Nacional de Ciberseguridad</collab>
<source><![CDATA[Amenaza vs. vulnerabilidad, ¿sabes en qué se diferencian?]]></source>
<year>2017</year>
</nlm-citation>
</ref>
<ref id="B15">
<label>[15]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Kumar1]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Evolution of mobile wireless communication networks-1G to 5G as well as future prospective of next generation communication network]]></article-title>
<source><![CDATA[IJECT]]></source>
<year>2010</year>
<volume>1</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>68-72</page-range></nlm-citation>
</ref>
<ref id="B16">
<label>[16]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Rodríguez]]></surname>
<given-names><![CDATA[O.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Telefonía móvil celular: origen, evolución, perspectivas]]></article-title>
<source><![CDATA[Ciencias Holguín]]></source>
<year>2005</year>
<volume>11</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>1-8</page-range></nlm-citation>
</ref>
<ref id="B17">
<label>[17]</label><nlm-citation citation-type="">
<collab>National Vulnerability Database</collab>
<source><![CDATA[CVE-2018-11422]]></source>
<year>2019</year>
</nlm-citation>
</ref>
<ref id="B18">
<label>[18]</label><nlm-citation citation-type="">
<collab>National Vulnerability Database</collab>
<source><![CDATA[CVE-2018-11421]]></source>
<year>2019</year>
</nlm-citation>
</ref>
<ref id="B19">
<label>[19]</label><nlm-citation citation-type="">
<collab>National Vulnerability Database</collab>
<source><![CDATA[CVE-2018-5455]]></source>
<year>2018</year>
</nlm-citation>
</ref>
<ref id="B20">
<label>[20]</label><nlm-citation citation-type="">
<collab>National Vulnerability Database</collab>
<source><![CDATA[CVE-2017-7913]]></source>
<year>2017</year>
</nlm-citation>
</ref>
<ref id="B21">
<label>[21]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[García Reis]]></surname>
<given-names><![CDATA[A. L.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[&#8220;Introduction to the software-defined radio approach&#8221;]]></article-title>
<source><![CDATA[IEEE Latin America Transactions]]></source>
<year>2012</year>
<volume>10</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>1156-61</page-range></nlm-citation>
</ref>
<ref id="B22">
<label>[22]</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Díaz]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
</person-group>
<source><![CDATA[Desarrollo de un sistema receptor de FM utilizando radio definida por software]]></source>
<year>2017</year>
<month>,</month>
</nlm-citation>
</ref>
<ref id="B23">
<label>[23]</label><nlm-citation citation-type="">
<collab>GNU Radio Foundation</collab>
<source><![CDATA[About GNU Radio]]></source>
<year>2020</year>
</nlm-citation>
</ref>
<ref id="B24">
<label>[24]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Bhushan]]></surname>
<given-names><![CDATA[B.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[&#8220;Man-in-the-middle attack in wireless and computer networking: a review&#8221;]]></article-title>
<source><![CDATA[International Conference on Advances in Computing, Communication &amp; Automation (ICACCA) (Fall), IEEE, Dehradun]]></source>
<year>2017</year>
<edition>3</edition>
<page-range>1-6</page-range></nlm-citation>
</ref>
<ref id="B25">
<label>[25]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Yubo]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[&#8220;Fake BTS attacks of GSM system on software radio platform&#8221;]]></article-title>
<source><![CDATA[Journal of Networks]]></source>
<year>2012</year>
<volume>7</volume>
<numero>2</numero>
<issue>2</issue>
</nlm-citation>
</ref>
<ref id="B26">
<label>[26]</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Alrashede]]></surname>
<given-names><![CDATA[H.]]></given-names>
</name>
</person-group>
<source><![CDATA[&#8220;IMSI Catcher Detection Method for Cellular Networks&#8221;]]></source>
<year>2019</year>
<conf-name><![CDATA[ International Conference on Computer Applications &amp; Information Security (ICCAIS)]]></conf-name>
<conf-loc>Riyadh </conf-loc>
<page-range>1-6</page-range></nlm-citation>
</ref>
<ref id="B27">
<label>[27]</label><nlm-citation citation-type="">
<collab>Kaspersky Labs.</collab>
<source><![CDATA[Amenazas de seguridad móvil dirigidas a dispositivos Android]]></source>
<year>2019</year>
</nlm-citation>
</ref>
<ref id="B28">
<label>[28]</label><nlm-citation citation-type="">
<collab>National Vulnerability Database</collab>
<source><![CDATA[CVE-2019 detail]]></source>
<year>2019</year>
</nlm-citation>
</ref>
<ref id="B29">
<label>[29]</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Lee]]></surname>
<given-names><![CDATA[K.]]></given-names>
</name>
</person-group>
<source><![CDATA[An Empirical study of wireless carrier authentication for SIM Swaps]]></source>
<year>2020</year>
</nlm-citation>
</ref>
<ref id="B30">
<label>[30]</label><nlm-citation citation-type="">
<collab>Portal IsSMS2FASecure.com</collab>
<source><![CDATA[Security analysis of SMS-enabled websites]]></source>
<year>2020</year>
</nlm-citation>
</ref>
<ref id="B31">
<label>[31]</label><nlm-citation citation-type="book">
<collab>International Organization for Standardization</collab>
<source><![CDATA[ISO/IEC 27005:2018 Information technology - Security techniques - Information security risk management]]></source>
<year>2018</year>
<publisher-loc><![CDATA[Suiza ]]></publisher-loc>
<publisher-name><![CDATA[International Organization for Standardization]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B32">
<label>[35]</label><nlm-citation citation-type="">
<collab>Municipio de Viterbo Carlas</collab>
<source><![CDATA[Plan de tratamiento de riesgos de seguridad y privacidad de la información]]></source>
<year>2019</year>
</nlm-citation>
</ref>
<ref id="B33">
<label>[33]</label><nlm-citation citation-type="">
<collab>National Institute of Standards and Technology</collab>
<source><![CDATA[Guide for Conducting Risk Assessments - NIST]]></source>
<year>2012</year>
</nlm-citation>
</ref>
<ref id="B34">
<label>[34]</label><nlm-citation citation-type="book">
<collab>International Organization for Standardization</collab>
<source><![CDATA[Norma técnica ISO/IEC 27001:2013]]></source>
<year>2013</year>
<edition>2</edition>
<publisher-loc><![CDATA[Suiza ]]></publisher-loc>
<publisher-name><![CDATA[International Organization for Standardization]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B35">
<label>[35]</label><nlm-citation citation-type="">
<collab>Unión Internacional de Telecomunicaciones</collab>
<source><![CDATA[Information technology - Open Systems Interconnection - The Directory: Overview of concepts, models and services]]></source>
<year>2019</year>
</nlm-citation>
</ref>
<ref id="B36">
<label>[36]</label><nlm-citation citation-type="">
<collab>National Institute of Standards and Technology</collab>
<source><![CDATA[Security and Privacy Controls for Federal Information Systems and Organization]]></source>
<year>2013</year>
</nlm-citation>
</ref>
</ref-list>
</back>
</article>
