case studies

Stolen VPN Login Case Study: Rules Learned From Two Weeks of Traffic Stop 136 of 144 Attempts

Many company VPNs are flat. Once a login is accepted, the VPN hands its owner the whole office network: every server, on every port. Staff like it that way because nothing ever gets in their way. Whoever steals a login likes it too, and stolen VPN logins are one of the commonest ways into a company today.

The fix is old advice. Give each person the systems they use and nothing else. Few companies do it, because few have a list of who uses what, and one written by hand is out of date the day it’s done. Scope, the second VPN Works engine, writes that list from the traffic itself.

In the Scope demo, a made-up office of 30 people in five teams uses 12 internal systems for two weeks. Scope learns from those two weeks. Then, on Thursday, September 24 at 21:47 UTC, someone logs in as Alice from finance with her stolen password and tries every system on 12 common ports. That’s 144 attempts. On the flat VPN, all 144 get through, to all 12 systems. Under the rules Scope learned, 8 get through, to the 6 systems Alice uses for her work, on the ports she uses. The other 136 stop at the gateway.

Step 5 of the Scope demo, under the learned rules: of 144 attempts by the stolen login, 8 reach a system, 6 of the 12 systems are reached, and 136 are refused at the gateway. dns, mail, intranet, files, erp and payroll are reached on the ports Alice uses; git, ci, staging-db, crm, helpdesk and backup refuse every attempt.

What Scope Learned

Scope read 20,232 connections from the two weeks: who connected, to which address and port, and on which days. It kept no content. Its rules are simple enough to check by hand:

  • A destination becomes a team rule when every active member of the team used it on two days or more.
  • What only some people used becomes a personal rule for each of them, if they used it on two days or more.
  • Anything used on a single day goes under review, and stays blocked until a person decides.

The draft came out as 39 team rules for the five teams, 11 personal rules and 3 destinations under review. Every rule carries its evidence as a note, such as “all 5 active members, 10 days, 484 connections”. On the flat VPN, 360 pairs of person and system were open. The draft opens 168 of them, and only on the ports people actually used.

The three under review were one-off visits: Jonas from engineering looked at the CRM once, Quinn from sales opened the ERP on one day, and Zoe from IT connected to payroll on one day. A person at the company decides about those. Scope only flags them.

The Week After

Before anyone enforces a draft, Scope replays the following week against it, as if it had been in force. The week had 10,387 connections. The draft allowed 10,375 of them and would have blocked 12, and both causes are worth knowing about. Farid, an engineer, started work on the staging database that week, 9 connections. Quinn went back to the ERP, 3 more. Either the rules get a line each, or someone asks why.

Hana joined the sales team that week. She had no history to learn from, so she got her team’s rules, and all 358 of her connections went through.

Is Any of It Real?

The office and its traffic are generated from a fixed seed, so the same numbers come out every time. Scope’s code is real. The demo page runs it, compiled for the browser.

The rules are real too. In Scope’s tests, the 144 stolen-login attempts were made as real connections through a Linux gateway, first with no rules and then with Scope’s rules loaded into the kernel’s firewall. The kernel let through exactly the 8 the replay predicted. Across three tests on two offices, the larger with 2,000 people and 288 systems, 45,809 connections were checked that way, and the kernel and Scope never disagreed once.

What It Doesn’t Fix

The 8 attempts that got through still reach payroll and the ERP, because Alice uses them. Narrow access limits how far a stolen login gets. It doesn’t replace second factors, or someone noticing a finance login late on a Thursday evening.

Scope 0.1.0 is also an Alpha. It has run on one Linux machine against made-up offices, not on a real company VPN yet. It needs a people file that says who is behind each VPN address. And a job that runs once a quarter can be missing from two weeks of traffic. Watch mode, the review list and a longer window reduce that risk without removing it.

The demo runs in the browser on the Scope page, with nothing to install.