This page provides a systematic analysis of existing FBS detection mechanisms and explains how their underlying detection logic informs Devilray’s operational variants. We decompose prior detection techniques into detection primitives, i.e., observable features that can reveal the presence of an FBS.
Below table presents a comprehensive analysis of 22 existing FBS detection works. We focus on characterizing detection primitives across operational layers; seven operational variants (V1-V7) are derived from these primitives combined with protocol specifications. We then examine how existing systems combine these primitives.
We identify three domains where FBS behavior can be detected: access-layer, protocol-layer, and physical-layer. They are based on our unified model and the characteristics of cellular communications.
Access-layer. This domain corresponds to the connection hijacking phase where FBS operations transition from passive observation and signal broadcasting to actively interacting with UEs to set up the link. In this process, the FBS disconnects UEs from legitimate cells and redirects them to itself, generating observable artifacts such as radio link failures.
Protocol-layer. FBSs execute attacks over hijacked connections, a process that primarily aligns with the application phase and requires communication with UEs through standard cellular protocols. Such communication produces detectable patterns in signaling messages, reject sequences, and protocol violations. The standardized nature of cellular protocols thus offers a rich foundation for detection mechanisms based on message analysis and behavioral patterns.
Physical-layer. Beyond the active interaction domains, physical-layer characteristics also provide useful indicators for FBS detection. When the hardware setup of FBSs relies on relatively low-cost components with limited capabilities compared to commercial infrastructure, they exhibit distinctive RF characteristics and signal quality variations.
Signal strength
A core behavior of FBSs during connection hijacking is attracting UEs by transmitting stronger signals than legitimate base stations. This effect is particularly pronounced when hijacking is assisted by jamming: by suppressing legitimate cells, an FBS can more readily dominate UE measurements and induce selection via the capture effect. Accordingly, prior work has attempted to detect hijacking by monitoring whether received signal power exceeds an absolute threshold or by using the disappearance of neighboring legitimate cells (e.g., under jamming) as evidence of FBS activity~\cite{eaglesecurity}.
In addition to thresholding, some systems treat signal strength as a consistency/localization signal by (i) comparing reported Reference Signal Received Power (RSRP) or Reference Signal Received Quality (RSRQ) against expected values from a signal-strength map or known base station locations/topology, or (ii) using multi-point signal-strength patterns to localize a suspected FBS.
RRC procedure failures
Victims experience RRC procedure failures during the connection hijacking phase that can reveal FBS presence. Specifically in jamming, following to our empirical study, the FBS disrupts the UE's link to the legitimate cell, causing Radio Link Failure (RLF) and leading to RRC Connection Reestablishment Request with "other failure" causes. In case of handover, the UE sends RRC Reconfiguration Complete but the FBS cannot proceed due to missing context, triggering "handover failure" and subsequent RRC Connection Reestablishment Request with "handover failure" causes.
These failure patterns can help detecting hijacking, though similar traffic patterns also arise in specific benign situations including UE in congestion or mobility. Prior works focus on failure outcomes as standalone indicators, or treated them as part of a broader detector system.
IMSI-exposing and reject messages
IMSI-exposing message patterns can reveal FBS activities aimed at identity tracking. Legitimate networks typically request IMSI sparingly and under specific conditions such as initial network attach or GUTI expiration, while FBS generates excessive identity requests for IMSI-catching. To collect IMSIs, FBS can send various signaling messages to UEs, such as Identity Request, NAS Reject, and others.
Based on this knowledge, several prior works detect FBS activity by monitoring for IMSI-exposing messages on the control plane. Specifically, Marlin identifies suspicious situations of IMSI-catcher presence by monitoring statistical increases in 53 IMSI-exposing messages, including NAS Reject with specific causes and Identity Request messages. Rayhunter monitors IMSI-relevant messages including IMSI paging and IMSI Identity Request messages.
Reject messages are another indicator of FBS activities, typically issued when authentication is required but cannot be completed, as FBSs lack the capability to correctly perform authentication procedures. This process disconnects UE links and returns them to legitimate networks after performing attacks. As an attack purpose, they are also exploited for service denial and downgrade attacks along with IMSI-catching. These patterns can be used to identify FBS activities by monitoring the frequency, cause values, and contextual abnormalities of reject messages.
Cell information
FBS deployments can be detected by anomalies of several configurations. These include misconfigurations of cell information parameters, such as invalid TAC, cell IDs, or use of non-standard frequency bands that can be indicators of FBS. Monitoring broadcast messages can also be helpful, as FBSs may transmit malicious messages to influence UE behavior. For instance, cell reselection priorities or barred cell status in SIB messages can mislead UEs into connecting to an FBS or prevent them from connecting to legitimate networks. Additionally, malicious paging messages may be used to elicit UE responses, enabling identity exposure or DoS through repeated, targeted paging.
Based on these observations, detectors flag an FBS when the observed cell information appears abnormal or distinguishable from legitimate cells. Common examples include cells advertising PLMN/TAC/cell IDs that are different from neighbors or not registered in a database, as well as cells whose broadcast information is inconsistent such as containing unusually small timer values or missing neighbor-cell information.
3G/2G redirection and null ciphers
Detection systems can also monitor redirection messages and null cipher usage. These indicators target specific application scenarios: redirection to legacy networks and SMS injection or eavesdropping through encryption downgrade.
Redirection occurs through multiple mechanisms specified in 3GPP standards. Regarding RRC connection management, RRC Connection Release messages may contain redirectedCarrierInfo to force cell selection steering UEs toward specific RATs or frequencies. Additionally, SIB messages can specify legacy technology priorities to induce inter-RAT reselection.
On the one hand, null cipher can be exploited to eavesdrop on UE communications. During the RRC connection and NAS Attach procedure, it can propose null encryption algorithms via Security Mode Command to disable encryption and expose UE data.
Note that redirection and ciphering changes can occur in benign operations. For example, UE autonomously performs cell search on lower-generation RATs if it fails to find any suitable cells. Additionally, networks can use redirection for congestion management and load balancing, and ciphering changes for emergency calls.
RF characteristics
FBS signals might exhibit unique RF characteristics that can be used to differentiate them from legitimate network transmissions. These include signal bandwidth variations, frequency stability (center frequency offset), time synchronization offset, phase characteristics, and magnitude deviations in pilot signals, reflecting hardware specifications and transmission conditions. For example, FBSleuth demonstrates this detection approach by measuring these physical-layer features. Other approaches utilized signal noise distributions or round-trip time analysis for additional RF characteristics.
Transmission timing error
Apple's patent describes using clock synchronization capabilities and Doppler effects for FBS detection. Building on this concept, transmission timing error can serve as a detection primitive. Legitimate cells typically achieve precise clock synchronization through GPS or external clock sources from their mobile operators, which provide accurate timing information to all cells in the network and ensure coordinated operation across the network. This synchronization is critical for maintaining network stability, enabling seamless handovers between cells, compensating for timing/frequency offsets, and preventing inter-cell interference.
In contrast, resource-constrained FBS relies on less accurate internal clocks, which introduce timing misalignment and signal distortions such as frequency offset. By focusing on the clock synchronization capabilities of legitimate cells, the inherent timing misalignment in FBS transmissions can be utilized to differentiate them from legitimate cells.
We also examine how existing detection systems combine these primitives in practice. We analyze existing detection systems across three dimensions:
Detection technique. Anomaly detection identifies deviations from normal network behavior while signature-based detection matches observed patterns against known attack signatures
Detection timing. We define five phases: pre-, mid-, and post-hijacking (before any FBS interaction, during redirection, and after UE connection but before attacks); and mid-/post-attack (during misuse and after-the-fact detection). Early phases allow prevention; later ones support confirmation and forensics.
Detection entity. FBS detection can occur on the UE side, network side, or via third-party systems. UE-side detection runs on user devices, often via apps, relies on local observation. Network-side detection uses MNO infrastructure to aggregate data from UEs or base stations. Third-party detection leverages external systems -- independent of both MNO and UE -- using dedicated hardware or data from multiple sources.
Then we organize our analysis primarily by detection technique as this captures the core operational logic underlying different systems.
Identifying deviations from normal behavior in legitimate networks, suspicious patterns can be detected and flagged as potential FBS activity. This approach typically focuses on monitoring emerged cells showing abnormal signal strength, message transmissions, unexpected cell location and unusual cell information.
CellGuard determines the presence of FBS by scoring the likelihood of a cell being malicious based on the Apple Location Service (ALS) database including cell information. With cell location information in the ALS database, CellGuard running on iPhone verifies the existence of connected cells and cell configurations (frequency channel and cell ID) against the database. Additionally, it calculates the distance between the UE and approximate location of the cell and monitors network reject messages, bandwidth, and signal power level to determine anomalies in cell behavior.
Crocodile Hunter, developed by Electronic Frontier Foundation (EFF), also scores suspiciousness of cells by collecting their configurations (PLMN, TAC, cell ID, frequency channel) and its location to compare with open cell database, OpenCelliD, and monitoring signal power fluctuations.
EFF also released Rayhunter, a new FBS detection tool that monitors specific indicators including IMSI paging, IMSI Identity Request, SIB and RRC Connection Release messages associated with 2G redirection, and null ciphers over Security Mode Command and RRC Connection Reconfiguration messages to identify FBS activities. Marlin identifies IMSI-Catchers by monitoring the statistical increase of 53 IMSI-related messages, including NAS Reject with specific causes, and Identity Request messages.
EAGLE Security, developed by Int64 Team, also operates as a UE-side Android application that validates cell configurations against the OpenCelliD database similar to Crocodile Hunter. The app evaluates multiple criteria to assign "wiring probability" scores: database presence verification, distance comparison between recorded and measured cell locations, PLMN validity checks, and analysis of whether multiple cells or only single cells are visible at the current location. Violations of these criteria increase the suspicion score for potential FBS detection.
FBS-Radar collects recently connected cell information (e.g., cell ID, signal strength, and connection time), MAC addresses of nearby WiFi access points, and SMS contents from UEs and stores this data in a cloud server. Based on the collected data, FBS-Radar analyzes cell information using a location database of cells and WiFi, and examines SMS contents using machine learning models to identify FBS activities sending spam SMSes.
Heijligenberg et al. suggested an FBS detection method monitoring Tracking Area Update (TAU) messages with dummy TAC values and comparing cell power from UE measurement reports with the signal strength map at the network side. Similarly, Huang et al. and Nakarmi et al. proposed methods to identify FBS by modeling expected signal strength received at the UE. Additionally, Karaçay et al. introduced an FBS localization method using observed signal strengths of cells in UE measurement reports and trilateration with a signal propagation model.
Other approaches, Murat, Park, Steig et al., collect measurement reports from UEs, including neighboring cell lists, signal strength, or RLF reports, and analyze them against network databases to identify FBS activities.
IMSI-Catcher-Catchers, Overwatch, and SeaGlass are designed to collect cell information or monitor IMSI-exposing messages through scalable deployments of UEs or sensor networks and build a database of regional cells to identify suspicious activities. These systems rely on the assumption that legitimate base stations exhibit consistent and predictable behaviors over time and across geographic locations. They collect information such as cell IDs, signal strength, broadcast parameters, and encryption status, along with precise GPS coordinates. By aggregating this data, they construct a baseline model of known legitimate cells. Detection is then performed by identifying inconsistencies such as previously unseen cell IDs and unexpected changes in broadcast configurations and cell locations when compared to the reference database.
As a comprehensive documentation, Apple's patent presents a detection technique that combines various detection primitives, including monitoring signal strength, cell information, TA commands, time synchronization capability, and Doppler effect for detecting mobile FBSs. However, the document only theoretically describes this detection technique without providing experimental results or practical implementation details. Separately, LeopardSeal introduces a method to detect call interception by FBS by monitoring the round trip timing of voice signals.
As another methodology, attack signatures can be used to identify FBS activities. These signatures are typically based on known attack patterns, such as specific message sequences or behaviors associated with FBS operations. By comparing observed behaviors against these signatures, detection systems can identify FBS attacks.
PHOENIX utilizes a signature-based approach to detect FBS attacks by monitoring specific message patterns, including RLF reports. It focuses on identifying attack signatures, which consist of undesired message sequences not present in benign cellular behaviors. FBSDetector employs signatures of abnormal activities and multi-step attacks of FBS with large-scale datasets. Based on machine learning techniques, it is also designed to cover unseen and reshaped FBS attacks.
FBSleuth is a representative work that employs RF fingerprinting as signatures to distinguish signals between FBS and legitimate cells in 2G networks. Based on the hardware imperfections inherent in FBS equipment, it models fingerprints with RF characteristics such as modulation errors and instantaneous phase and frequency, and applies machine learning techniques to classify these fingerprints. Ali et al. proposed a similar approach to detect FBS by analyzing signal distortion derived from hardware limitations of FBS.