Evaluating Susceptibility of VPN Implementations to DoS Attacks Using Adversarial Testing
Fabio Streun, Joel Wanner, Adrian Perrig
摘要
Many systems today rely heavily on virtual private network (VPN) technology to connect networks and protect their services on the Internet. While prior studies compare the performance of different implementations, they do not consider adversarial settings. To address this gap, we evaluate the resilience of VPN implementations to flooding-based denial-of-service (DoS) attacks. We focus on a class of stateless flooding attacks, which are particularly threatening to real connections, as they can be carried out by an off-path attacker using spoofed IP addresses. We have implemented various attacks to evaluate DoS resilience for three major open-source VPN solutions, with surprising results: On high-performance hardware with a interface, data transfer over established WireGuard connections can be fully denied with of attack traffic. For strongSwan (IPsec), an adversary can block any legitimate connections from being established using only of attack traffic. OpenVPN can be overwhelmed with of flood traffic denying data transfer through the VPN connection as well as connection establishment completely. Further analysis has revealed implementation bugs and major inefficiencies in the implementations related to concurrency aspects. These findings demonstrate a need for more adversarial testing of VPN implementations with respect to DoS resilience.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Bypassing Tunnels: Leaking VPN Client Traffic by Abusing Routing TablesNian Xue, Yashaswi Malla, Zihang Xia, Christina Pöpper 等USENIX Security 2023
- Onions Got Puzzled: On the Challenges of Mitigating Denial-of-Service Problems in Tor Onion ServicesJinseo Lee, Hobin Kim, Min Suk KangUSENIX Security 2025
它引用的顶会 Paper2
相关 Paper
- Blind In/On-Path Attacks and Applications to VPNsWilliam J. Tolley, Beau Kujath, Mohammad Taha Khan, Narseo Vallina-Rodriguez 等USENIX Security 2021 · 被引用 19 次
- Invisible Adversaries: A Systematic Study of Session Manipulation Attacks on VPNsYuxiang Yang, Ao Wang, Xuewei Feng, Qi Li 等INFOCOM 2026 · 被引用 1 次
- FRAGJAM: DoS Attacks Using IP Reassembly CongestionYepeng Pan, Christian RossowUSENIX Security 2026
- A Unified Symbolic Analysis of WireGuardPascal Lafourcade, Dhekra Mahmoud, Sylvain RuhaultNDSS 2024
- Point Break: A Study of Bandwidth Denial-of-Service Attacks against TorRob Jansen, Tavish Vaidya, Micah SherrUSENIX Security 2019 · 被引用 49 次
