VPN Detection
This page provides information on the VPN Detection in Netify's Network Intelligence Engine. To learn more about our full suite of intelligence drivers, see our intelligence capabilities page.
Risk Overview
While VPN technology is a staple for secure remote access, its ability to encapsulate and encrypt traffic makes it a primary vector for stealthy data exfiltration. By tunneling sensitive information through an encrypted VPN session, an insider or malicious actor can move data off-site without triggering traditional firewall alerts.
Indicator Drivers
Business VPN Application Driver
Much like consumer VPN services, business VPNs like Zscaler and ZeroTier play an essential role in protecting enterprise networks. However, these VPNs can still create compliance and control issues if this traffic is not managed properly.
The Business VPN indicator driver is triggered when a business VPN application is detected on the network.
- Tag
- vpn_application_business
- Score
- Medium Risk - 45
- Version
- 1.2.9
Consumer VPN Application Driver
Consumer VPNs like ExpressVPN and Mullvad VPN play an essential role in protecting users' privacy. On the other hand, businesses need to protect their networks to maintain security, compliance, and control over their environments.
The Consumer VPN indicator driver is triggered when a consumer VPN application is detected on the network. You can find a list of supported VPNs on our VPN Resources page.
- Tag
- vpn_application_consumer
- Score
- High Risk - 70
- Version
- 1.2.9
VPN Protocol Driver
The VPN Protocol indicator driver is triggered when a supported VPN protocol is detected by the Netify DPI engine.
WiFi Calling is a popular feature that allows mobile phones to use local WiFi for mobile connectivity. This application uses the IPsec VPN protocol, so you may want to make an exception in the configuration for this type of traffic.
- Tag
- vpn_protocol
- Score
- High Risk - 60
- Version
- 1.2.9
Consumer VPN Server Driver
The Consumer VPN Server indicator driver activates when a connection is made to any of thousands of known VPN servers across the Internet. It complements the Consumer VPN Application indicator driver by broadening detection to include more obfuscated and less easily identifiable VPN services.
- Tag
- vpn_server_consumer
- Score
- High Risk - 70
- Version
- 1.2.9