-
This paper reveals the vulnerabilities of OpenVPN, including commercial obfuscated services, to DPI-based fingerprinting attacks by adversarial ISPs. It details a detection framework capable of identifying VPN traffic effectively, proposes defenses, and highlights the need for ongoing development of robust obfuscation methods.
Main Points- Growing VPN AdoptionVPNs are increasingly adopted due to concerns over privacy and censorship, motivating ISPs and governments to track or block VPN traffic.
- OpenVPN's Vulnerability to FingerprintingOpenVPN, the most popular protocol for commercial VPN services, is explored for its vulnerability to fingerprinting by adversarial ISPs.
- Detection FrameworkA detection framework inspired by the Great Firewall uses a two-phase process (Filter and Prober components) to identify OpenVPN traffic effectively.
- Obfuscated VPN Services VulnerabilityObfuscated VPN services, while marketed as superior in evading detection, share many vulnerabilities with vanilla OpenVPN, making them detectable.
- Proposed Defenses and Future WorkThe research proposes short-term defenses against fingerprinting attacks and highlights the need for long-term, robust obfuscation strategies.
122004763