...
首页> 外文期刊>電子情報通信学会技術研究報告. 情報通信システムセキュリティ >On the use and misuse of E-mail sender authentication mechanisms
【24h】

On the use and misuse of E-mail sender authentication mechanisms

机译:关于电子邮件发件人身份验证机制的使用和滥用

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

E-mail sender authentication is a promising way of verifying the sources of e-mail messages. Since today's primary e-mail sender authentication mechanisms are designed as fully decentralized architecture, it is crucial for e-mail operators to know how other organizations are using and misusing them. This paper aims to address the question "How is the DNS Sender Policy Framework (SPF), which is the most popular e-mail sender authentication mechanism, used and misused in the wild?" To the best of our knowledge, this is the first extensive study addressing the fundamental question. This work targets both legitimate and spamming domain names and correlates them with multiple data sets, including the e-mail delivery logs collected from medium-scale enterprise networks and various IP reputation lists. We first present the adoption and usage of DNS SPF from both global and local viewpoints. Next, we present empirically why and how spammers leverage the SPF mechanism in an attempt to pass a simple SPF authentication test. We also present that non-negligible volume of legitimate messages originating from legitimate senders will be rejected or marked as potential spam with the SPF policy set by owners of legitimate domains. Our findings will help provide (1) e-mail operators with useful insights for setting adequate sender or receiver policies and (2) researchers with the detailed measurement data for understanding the feasibility, fundamental limitations, and potential extensions to e-mail sender authentication mechanisms.
机译:电子邮件发件人身份验证是一种验证电子邮件来源的有前途的方法。由于当今的主要电子邮件发件人身份验证机制被设计为完全分散的体系结构,因此对于电子邮件运营商来说,了解其他组织如何使用和滥用它们至关重要。本文旨在解决以下问题:“ DNS发件人策略框架(SPF)是最流行的电子邮件发件人身份验证机制,在野外经常使用和滥用?”据我们所知,这是第一个针对基本问题的广泛研究。这项工作针对合法域名和垃圾邮件域名,并将它们与多个数据集相关联,包括从中型企业网络收集的电子邮件传递日志和各种IP信誉列表。我们首先从全球和本地角度介绍DNS SPF的采用和使用。接下来,我们将凭经验介绍垃圾邮件发送者为何以及如何利用SPF机制来尝试通过简单的SPF身份验证测试。我们还提出,合法域名所有者设置的SPF政策会拒绝来自合法发件人的合法邮件数量不可忽略或被标记为潜在垃圾邮件。我们的发现将为(1)电子邮件运营商提供有用的见解,以制定适当的发件人或收件人策略,以及(2)研究人员提供详细的测量数据,以了解电子邮件发件人身份验证机制的可行性,基本局限性和潜在扩展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号