Invisible Adversaries: A Systematic Study of Session Manipulation Attacks on VPNs
Yuxiang Yang, Ao Wang, Xuewei Feng, Qi Li, Ke Xu
Abstract
Virtual Private Networks (VPNs) are widely used for censorship evasion and traffic protection. VPN users expect to be provided with adequate security protection, and at the same time not be affected by other users connected to the same VPN server, which can be illustrated as the non-interference property. However, in this paper, we have identified several vulnerabilities that violate this property, specifically within the connection tracking frameworks of VPN servers, stemming from shared resource misuse and insufficient validation of session state transitions. We present three session manipulation attacks targeting TCP and UDP traffic tunneled through VPNs. The attacker who only connects to the same VPN server can launch denial-of-service attacks, hijack TCP connections of other clients, or inject forged DNS responses into their queries. We evaluate these attacks against five popular connection tracking frameworks across different OSes and nine major commercial VPN providers. Experimental results reveal that all frameworks and eight providers are vulnerable to at least one of the attacks. We have responsibly disclosed our findings with countermeasures, resulting in 19 assigned CVEs/CNVDs and acknowledgments from the communities and providers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e794971e-a59a-4dc4-a108-b5a26da38a93Builds on15
- Off-Path TCP Exploits: Global Rate Limit Considered DangerousYue Cao, Zhiyun Qian, Zhongjie Wang, Tuan Dao et al.USENIX Security 2016 · 74 citations
- DNS Cache Poisoning Attack Reloaded: Revolutions with Side ChannelsKeyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng et al.CCS 2020 · 62 citations
- The Dangers of Key Reuse: Practical Attacks on IPsec IKEDennis Felsch, Martin Grothe, Jörg Schwenk, Adam Czubak et al.USENIX Security 2018 · 41 citations
- Off-Path TCP Exploits of the Mixed IPID AssignmentXuewei Feng, Chuanpu Fu, Qi Li, Kun Sun et al.CCS 2020 · 39 citations
- Off-Path TCP Exploit: How Wireless Routers Can Jeopardize Your SecretsWeiteng Chen, Zhiyun QianUSENIX Security 2018 · 35 citations
Related papers
- Bypassing Tunnels: Leaking VPN Client Traffic by Abusing Routing TablesNian Xue, Yashaswi Malla, Zihang Xia, Christina Pöpper et al.USENIX Security 2023
- Blind In/On-Path Attacks and Applications to VPNsWilliam J. Tolley, Beau Kujath, Mohammad Taha Khan, Narseo Vallina-Rodriguez et al.USENIX Security 2021 · 19 citations
- Evaluating Susceptibility of VPN Implementations to DoS Attacks Using Adversarial TestingFabio Streun, Joel Wanner, Adrian PerrigNDSS 2022
- FRAGJAM: DoS Attacks Using IP Reassembly CongestionYepeng Pan, Christian RossowUSENIX Security 2026
- Forwarding-Loop Attacks in Content Delivery NetworksJianjun Chen, Xiaofeng Zheng, Hai-Xin Duan, Jinjin Liang et al.NDSS 2016 · 44 citations
