Figure 9 Subscription Profile Placement in MME. We assume, that once an attacker holds a complete subscriber profile of a user of one operators he can deduct the structure of the profile and by that figure out, what are "nice" items to modify for another subscription. Many of those items can be used for DoS against the user, basically changing the settings to something strange, so that the user would not have a properly working access. The following items could be interesting for an attacker to modify. We will later on elaborate new cases what this subscriber profile contains and what it implies if an attacker gets hold of the subscriber profile. This message contains the MSISDN (phone number) of the user. This answer then contains the requested subscriber profile. The attacker would impersonate the Home-HSS, but due to roaming the visited network would only see the DEA address of the home net-work (which can be spoofed by setting the origin realm and origin host), as the message answer does not really need to go through it is no issue to spoof the origin. The DEA address can be found from IR.21 documents on the internet or brute forcing the operator ranges.

Figure 8 Setting back the MME entry to "old home MME".

The modification of those may hinder proper charging of the user and result in a potential fraud scenario. The message is send not directly to the HSS, but to the DEA of the home operator of this user. Each operator supports different services for his users and has different features deployed therefore each subscriber profile looks somewhat different. The IMSI is embedded into the users UICC card (commonly called SIM card) and does not change during the lifetime of the card, only with replacement of the card it changes.