Bad Neighbors: On Understanding VPN Provider Networks
Teemu Rytilahti (Ruhr University Bochum), Thorsten Holz (CISPA, Helmholtz Center for Information Security)

TL;DR
This study conducts a large-scale analysis of VPN provider networks to evaluate their security configurations, revealing widespread lack of traffic filtering that could expose internal networks or other customers.
Contribution
The paper introduces an automated measurement system to assess VPN providers' network security and uncovers prevalent misconfigurations and vulnerabilities.
Findings
Most VPN providers lack proper traffic filtering towards internal networks.
Many VPN endpoints inadvertently expose internal or other customers' networks.
Findings have been disclosed to providers with recommendations for improvement.
Abstract
Virtual Private Network (VPN) solutions are used to connect private networks securely over the Internet. Besides their benefits in corporate environments, VPNs are also marketed to privacy-minded users to preserve their privacy, and to bypass geolocation-based content blocking and censorship. This has created a market for turnkey VPN services offering a multitude of vantage points all over the world for a monthly price. While VPN providers are heavily using privacy and security benefits in their marketing, such claims are generally hard to measure and substantiate. While there exist some studies on the VPN ecosystem, all prior works omit a critical part in their analyses: (i) How well do the providers configure and secure their own network infrastructure? and (ii) How well are they protecting their customers from other customers? To answer these questions, we have developed an automated…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · IPv6, Mobility, Handover, Networks, Security · Network Security and Intrusion Detection
