Evaluating Susceptibility of VPN Implementations to DoS Attacks Using Adversarial Testing

Fabio Streun, Joel Wanner, Adrian Perrig · 2022

Many systems today rely heavily on virtual private network (VPN) technology to connect networks and protect services on the Internet.While prior studies compare the performance of different implementations, they do not consider adversarial settings.To address this gap, we evaluate the resilience of VPN implementations to flooding-based denial-of-service (DoS) attacks.We focus on a class of stateless flooding attacks, which are particularly threatening because an attacker that operates stealthily by spoofing its IP addresses can perform them.We have implemented various attacks to evaluate the DoS resilience of four widely used VPN solutions and measured their impact on a highperformance server with a 40 Gb/s interface, which has revealed surprising results: An adversary can deny data transfer over an already established WireGuard connection with just 300 Mb/s of attack traffic.When using strongSwan (IPsec), 75 Mb/s of attack traffic is sufficient to block connection establishment.A 100 Mb/s flood overwhelms OpenVPN, denying data transfer through VPN connections and connection establishments.Cisco's AnyConnect VPN solution can be overwhelmed with even less attack traffic: When using IPsec, 50 Mb/s of attack traffic deny connection establishment.When using SSL, 50 Mb/s deny data transfer over already established connections.Furthermore, performance analysis of WireGuard revealed significant inefficiencies in the implementation related to multi-core synchronization.We also found vulnerabilities in the implementations of strongSwan and OpenVPN, which an attacker can easily exploit for highly effective DoS attacks.These findings demonstrate the need for adversarial testing of VPN implementations with respect to DoS resilience.Overall, we demonstrate that today's standard implementations are highly vulnerable to flooding attacks, even though mitigation mechanisms are in place.Hence, they cannot reliably provide the first layer of DoS protection.Furthermore, our results indicate a significant deficit of adversarial testing.This paper makes the following contributions:• We evaluate four state-of-the-art VPN solutions on highperformance hardware, providing quantitative measurements of their resilience under realistic adversarial conditions.• We analyze the VPN implementations, uncovering significant inefficiencies and multiple vulnerabilities in the implementations.All findings have been reported to the respective developers, resulting in CVE-2021-3568 and multiple patches.• We present a framework capable of launching flooding attacks in a high-performance testbed network.

Read the paper · More papers on PaperTik