VPN or Vpwn? How Afraid Should You Be of VPN Traffic Identification?
An Empirical Analysis of VPN Traffic Fingerprinting in the Age of Censorship
Tanmay Rajore, Jithin S, Arnav Gupta, Keshav Gambhir, Anindya Prithvi, Dr. Sambuddho Chakravarty
IIIT Delhi�
Network Traffic Measurement and Analysis (TMA 2025)
1
VPN
2
Ideal Pathway
Image credit: sunteco
Protocols (in use today)
Older protocols (insecure/deprecated)
TLS
VPN Tunneling
3
Image credit: palo-alto-networks[link]
VPN Identification
4
Why This Matters
5
Research Questions
6
Threat Model
7
Methodology Overview
8
Logo rights belong to respective company , link1
Protocol Taxonomy
9
Open-Source VPNs
Proprietary VPNs
Freely available software with�modifiable code and�configurations.
Ex- OpenVPN, Wireguard
Vendor-specific extensions with�custom features and undocumented�protocols.
Ex- Lightway, Nordlynx, Chameleon
Commercial VPN connection
10
2 Step Process – client application ( after login using username /password)
1. Authentication with Authentication server to fetch the VPN gateway details. (API calls)
2. Connection to the VPN gateway
Authentication Server
Weakness: An Adversary can just block the Authentication step
OpenVPN
11
Vanilla – OpenVPN
OpenVPN
12
Wireguard
13
Wireguard
14
Image credits: [Link]
TLS and SSH-based VPNs
15
Image credits: [link]
TLS and SSH-based VPNs
16
Image credits: [link]
TLS and SSH-based VPNs
17
TLS and SSH-based VPNs
18
Evasion Techniques
19
Performance Results
20
Firewalls
Firewall tested : Fortinet 2601F ( FortiOS 7.6)
21
Firewalls
22
Static signatures try to keep up with the protocol changes
Firwalls
23
VPN Detection Table
24
Limitations
25
Our Proposed Fix
26
Conclusion
27