Client-Side Vulnerabilities in Commercial VPNs

Siddharth Rao, Tien Bui, Markku Antikainen, Tuomas Aura

Tutkimustuotos: Artikkeli kirjassa/konferenssijulkaisussaConference contributionScientificvertaisarvioitu

Abstrakti

Internet users increasingly rely on commercial virtual private network (VPN) services to protect their security and privacy. The VPN services route the client’s traffic over an encrypted tunnel to a VPN gateway in the cloud. Thus, they hide the client’s real IP address from online services, and they also shield the user’s connections from perceived threats in the access networks. In this paper, we study the security of such commercial VPN services. The focus is on how the client applications set up VPN tunnels, and how the service providers instruct users to configure generic client software. We analyze common VPN protocols and implementations on Windows, macOS and Ubuntu. We find that the VPN clients have various configuration flaws, which an attacker can exploit to strip off traffic encryption or to bypass authentication of the VPN gateway. In some cases, the attacker can also steal the VPN user’s username and password. We suggest ways to mitigate each of the discovered vulnerabilities.
AlkuperäiskieliEnglanti
OtsikkoSecure IT Systems
Alaotsikko24th Nordic Conference, NordSec 2019, Aalborg, Denmark, November 18–20, 2019, Proceedings
KustantajaSpringer
Sivut103-119
Sivumäärä17
ISBN (elektroninen)978-3-030-35055-0
ISBN (painettu)978-3-030-35054-3
DOI - pysyväislinkit
TilaJulkaistu - 2019
OKM-julkaisutyyppiA4 Artikkeli konferenssijulkaisussa
TapahtumaNordic Conference on Secure IT Systems - Aalborg, Tanska
Kesto: 18 marrask. 201920 marrask. 2019
Konferenssinumero: 24
https://nordsec2019.cs.aau.dk/

Julkaisusarja

NimiLecture Notes in Computer Science
KustantajaSpringer
Vuosikerta11875
ISSN (painettu)0302-9743
ISSN (elektroninen)1611-3349

Conference

ConferenceNordic Conference on Secure IT Systems
LyhennettäNordSec
Maa/AlueTanska
KaupunkiAalborg
Ajanjakso18/11/201920/11/2019
www-osoite

Sormenjälki

Sukella tutkimusaiheisiin 'Client-Side Vulnerabilities in Commercial VPNs'. Ne muodostavat yhdessä ainutlaatuisen sormenjäljen.

Siteeraa tätä