With the shift to working remotely after the COVID-19 pandemic, the use of Virtual Private Networks (VPNs) around the world has nearly doubled. Therefore, measuring the traffic and security aspects of the VPN ecosystem is more important now than ever. It is, however, challenging to detect and characterize VPN traffic since some VPN protocols use the same port number as web traffic and port-based traffic classification will not help. VPN users are also concerned about the vulnerabilities of their VPN connections due to privacy issues. In this paper, we aim at detecting and characterizing VPN servers in the wild, which facilitates detecting the VPN traffic. To this end, we perform Internet-wide active measurements to find VPN servers in the wild, and characterize them based on their vulnerabilities, certificates, locations, and fingerprinting. We find 9.8M VPN servers distributed around the world using OpenVPN, SSTP, PPTP, and IPsec, and analyze their vulnerability. We find SSTP to be the most vulnerable protocol with more than 90% of detected servers being vulnerable to TLS downgrade attacks. Of all the servers that respond to our VPN probes, 2% also respond to HTTP probes and therefore are classified as Web servers. We apply our list of VPN servers to the traffic from a large European ISP and observe that 2.6% of all traffic is related to these VPN servers.
翻译:随着新冠疫情后远程办公模式的转变,全球虚拟专用网络(VPN)的使用量几乎翻了一番。因此,如今对VPN生态系统的流量和安全特性进行测量比以往任何时候都更加重要。然而,由于某些VPN协议使用与网络流量相同的端口号,基于端口的流量分类无法有效识别,这使得检测和表征VPN流量面临挑战。同时,出于隐私考虑,VPN用户也对其连接存在的漏洞感到担忧。本文致力于检测和表征现实环境中的VPN服务器,以协助识别VPN流量。为此,我们通过互联网范围的主动测量发现现实环境中的VPN服务器,并根据其漏洞、证书、地理位置和指纹特征对其进行分类。我们使用OpenVPN、SSTP、PPTP和IPsec协议在全球范围内发现了980万个VPN服务器,并分析了其漏洞。研究发现SSTP是最易受攻击的协议,超过90%的检测服务器面临TLS降级攻击风险。在所有响应VPN探测的服务器中,有2%同时响应HTTP探测,因此被归类为Web服务器。我们将VPN服务器列表应用于一家欧洲大型ISP的流量数据,观察到其总流量的2.6%与这些VPN服务器相关。