Mid Sweden University

miun.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
TunnelVision: En undersökning kring hotbilden som TunnelVision utgörmot kommersiella VPN-tjänster
Mid Sweden University, Faculty of Science, Technology and Media, Department of Computer and Electrical Engineering (2023-).
2024 (Swedish)Independent thesis Basic level (university diploma), 10 credits / 15 HE creditsStudent thesis
Abstract [sv]

Den sjätte maj publicerade Leviathan Security ett blogginlägg om en VPN-baserad sårbarhet som de har valt att kalla TunnelVision. Denna sårbarhet tycks påverka all routing-baserad VPN-teknik och kan användas av illvilliga aktörer mot användare på ett lokalt nätverk för att avlyssna deras VPN-trafik okrypterat. Syftet med studien är att utvärdera hotet som TunnelVision utgör mot kommersiella VPN-tjänster. 19 olika VPN-tjänster har testats, och en simulerad TunnelVision-attack har genomförts mot dessa tjänster. Resultaten visar att ingen av tjänsterna är helt säker mot TunnelVision, och nära hälften av de testade tjänsterna är helt sårbara. Utöver detta har VPN-tjänsteleverantöres respons på TunnelVision uppmärksammats. Endast en fjärdedel av de utvärderade tjänsteleverantörer informerar om sårbarheten. I diskussionen redogörs olika säkerhetsåtgärder emot TunnelVision som förhindrar att en sådan attack kan utföras. Slutsatsen är att TunnelVision är en sårbarhet som påverkar all routing-baserad VPN-teknik, men det påverkar inte alla VPN-tjänster likvärdigt.

Abstract [en]

On the sixth of May, Leviathan Security published a blog post about a VPN-based vulnerability which they have choosen to call TunnelVision. This vulnerability seemingly affects all VPN-technology and can be used by malicious actors against users on a local network to snoop on their VPN-traffic unencrypted. The purpose of this study is to evaluate the threat that TunnelVision poses to commercial VPN services. 19 different VPN services have been tested, and a simulated TunnelVision attack has been conducted against these services. The results show that none of the services are completely secure against TunnelVision, and nearly half of the tested services are completely vulnerable. In addition, VPN service providers’ response to TunnelVision has been noted. Only a quarter of the evaluated service providers inform about the vulnerability. The discussion describes various security measures against TunnelVision that prevent such an attack from being carried out. The conclusion is that TunnelVision is a vulnerability that affects all routing-based VPN technologies, but it does not affect all VPN services equally.

Place, publisher, year, edition, pages
2024. , p. 43
Keywords [en]
TunnelVision, VPN
Keywords [sv]
TunnelVision, VPN
National Category
Computer Engineering
Identifiers
URN: urn:nbn:se:miun:diva-52841Local ID: DT-V24-G2-047OAI: oai:DiVA.org:miun-52841DiVA, id: diva2:1905468
Subject / course
Computer Engineering DT1
Educational program
Network Management TNÄTG 120 higher education credits
Supervisors
Examiners
Available from: 2024-10-14 Created: 2024-10-14 Last updated: 2025-09-25Bibliographically approved

Open Access in DiVA

fulltext(1298 kB)42 downloads
File information
File name FULLTEXT01.pdfFile size 1298 kBChecksum SHA-512
8cc756fa4ab8b21ee08959405854acca68dbcc453717cc67f15d89f97cee77afa42a99f5e1292ab9d5e6f16f34603f1fb617b5c55f8ed7f52a81a110c642c6e0
Type fulltextMimetype application/pdf

Search in DiVA

By author/editor
Högild, Jonatan
By organisation
Department of Computer and Electrical Engineering (2023-)
Computer Engineering

Search outside of DiVA

GoogleGoogle Scholar
Total: 45 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 93 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf