OpenVPN is Open to VPN Fingerprinting
Diwen Xue, Reethika Ramesh, Arham Jain, Michalis Kallitsis, J. Alex Halderman, Jedidiah R. Crandall, Roya Ensafi
摘要
VPN adoption has seen steady growth over the past decade due to increased public awareness of privacy and surveillance threats. In response, certain governments are attempting to restrict VPN access by identifying connections using "dual use" DPI technology. To investigate the potential for VPN blocking, we develop mechanisms for accurately fingerprinting connections using OpenVPN, the most popular protocol for commercial VPN services. We identify three fingerprints based on protocol features such as byte pattern, packet size, and server response. Playing the role of an attacker who controls the network, we design a two-phase framework that performs passive fingerprinting and active probing in sequence. We evaluate our framework in partnership with a million-user ISP and find that we identify over 85% of OpenVPN flows with only negligible false positives, suggesting that OpenVPN-based services can be effectively blocked with little collateral damage. Although some commercial VPNs implement countermeasures to avoid detection, our framework successfully identified connections to 34 out of 41 "obfuscated" VPN configurations. We discuss the implications of the VPN fingerprintability for different threat models and propose short-term defenses. In the longer term, we urge commercial VPN providers to be more transparent about their obfuscation approaches and to adopt more principled detection countermeasures, such as those developed in censorship circumvention research.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- AppSniffer: Towards Robust Mobile App Fingerprinting Against VPNSanghak Oh, Minwook Lee, Hyunwoo Lee, Elisa Bertino 等WWW 2023 · 被引用 26 次
- Fingerprinting Obfuscated Proxy Traffic with Encapsulated TLS HandshakesDiwen Xue, Michalis Kallitsis, Amir Houmansadr, Roya EnsafiUSENIX Security 2024 · 被引用 24 次
- Bytes to Schlep? Use a FEP: Hiding Protocol Metadata with Fully Encrypted ProtocolsEllis Fenske, Aaron JohnsonCCS 2024 · 被引用 3 次
- CalcuLatency: Leveraging Cross-Layer Network Latency Measurements to Detect Proxy-Enabled AbuseReethika Ramesh, Philipp Winter, Sam Korman, Roya EnsafiUSENIX Security 2024 · 被引用 2 次
- MVPNalyzer: An Investigative Framework for Auditing the Security & Privacy of Mobile VPNsWayne Wang, Aaron Ortwein, Enrique Sobrados, Robert Stanley 等NDSS 2026 · 被引用 2 次
它引用的顶会 Paper4
- LZR: Identifying Unexpected Internet ServicesLiz Izhikevich, Renata Teixeira, Zakir DurumericUSENIX Security 2021 · 被引用 63 次
- Decentralized Control: A Case Study of RussiaReethika Ramesh, Ram Sundara Raman, Matthew Bernhard, Victor Ongkowijaya 等NDSS 2020
- Detecting Probe-resistant ProxiesSergey Frolov, Jack Wampler, Eric WustrowNDSS 2020
- Measuring the Deployment of Network Censorship Filters at Global ScaleRam Sundara Raman, Adrian Stoll, Jakub Dalek, Reethika Ramesh 等NDSS 2020
相关 Paper
- Practical VPN Fingerprinting using Coarse Inference of Field Specifications in Data ChannelsTaewook Kim, Jinhwan Kim, Sangmin Lee, Yeongpil ChoINFOCOM 2026
- The use of TLS in Censorship CircumventionSergey Frolov, Eric WustrowNDSS 2019 · 被引用 97 次
- Fingerprinting Deep Packet Inspection Devices by their AmbiguitiesDiwen Xue, Armin Huremagic, Wayne Wang, Ram Sundara Raman 等CCS 2025
- The Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy TrafficDiwen Xue, Robert Stanley, Piyush Kumar, Roya EnsafiNDSS 2025
- Invisible Adversaries: A Systematic Study of Session Manipulation Attacks on VPNsYuxiang Yang, Ao Wang, Xuewei Feng, Qi Li 等INFOCOM 2026 · 被引用 1 次
