A cyber risk exists for everything that is transferred over the internet. This risk can be
mitigated or eliminated using software protection solutions. VPN - virtual private network - is
an example of such a solution.
Security risks and virtual private networks connecting a system to the internet requires
assuming security risks. As a technical point of view, when a system connects to an Internet
resource, a communication path is opened that crosses a number of network devices. Starting
with the initial system, continuing with the equipment on the route, and ending with the
destination system, each communication node can represent a security breach.
With VPN policies widely deployed, how to specify and configure them correctly is a critical
part of enforcing security requirements, especially among different administrative domains
across the internet in which routing dynamics may interfere with VPN policies, resulting in
unexpected conflicts due to a mismatch between the routing and VPN layers. As a solution to
these problems, we discuss VPN security requirements, policies, and their correctness