TY - GEN
T1 - Advanced Analysis of Email Sender Spoofing Attack and Related Security Problems
AU - Yu, Beiyuan
AU - Li, Pan
AU - Liu, Jianwei
AU - Zhou, Ziyu
AU - Han, Yiran
AU - Li, Zongxiao
N1 - Publisher Copyright:
© 2022 IEEE.
PY - 2022
Y1 - 2022
N2 - A mail spoofing attack is a harmful activity that modifies the source of the mail and trick users into believing that the message originated from a trusted sender whereas the actual sender is the attacker. Based on the previous work, this paper analyzes the transmission process of an email. Our work identifies new attacks suitable for bypassing SPF, DMARC, and Mail User Agent's protection mechanisms. We can forge much more realistic emails to penetrate the famous mail service provider like Tencent by conducting the attack. By completing a large-scale experiment on these well-known mail service providers, we find some of them are affected by the related vulnerabilities. Some of the bypass methods are different from previous work. Our work found that this potential security problem can only be effectively protected when all email service providers have a standard view of security and can configure appropriate security policies for each email delivery node. In addition, we also propose a mitigate method to defend against these attacks. We hope our work can draw the attention of email service providers and users and effectively reduce the potential risk of phishing email attacks on them.
AB - A mail spoofing attack is a harmful activity that modifies the source of the mail and trick users into believing that the message originated from a trusted sender whereas the actual sender is the attacker. Based on the previous work, this paper analyzes the transmission process of an email. Our work identifies new attacks suitable for bypassing SPF, DMARC, and Mail User Agent's protection mechanisms. We can forge much more realistic emails to penetrate the famous mail service provider like Tencent by conducting the attack. By completing a large-scale experiment on these well-known mail service providers, we find some of them are affected by the related vulnerabilities. Some of the bypass methods are different from previous work. Our work found that this potential security problem can only be effectively protected when all email service providers have a standard view of security and can configure appropriate security policies for each email delivery node. In addition, we also propose a mitigate method to defend against these attacks. We hope our work can draw the attention of email service providers and users and effectively reduce the potential risk of phishing email attacks on them.
KW - Anti-Spam
KW - Email ecosystem
KW - Mail spoofing attack
KW - Mail spoofing detection method
KW - Sender source security check
KW - Social engineering attack
UR - https://www.scopus.com/pages/publications/85137020891
U2 - 10.1109/CSCloud-EdgeCom54986.2022.00023
DO - 10.1109/CSCloud-EdgeCom54986.2022.00023
M3 - 会议稿件
AN - SCOPUS:85137020891
T3 - Proceedings - 2022 IEEE 9th International Conference on Cyber Security and Cloud Computing and 2022 IEEE 8th International Conference on Edge Computing and Scalable Cloud, CSCloud-EdgeCom 2022
SP - 80
EP - 85
BT - Proceedings - 2022 IEEE 9th International Conference on Cyber Security and Cloud Computing and 2022 IEEE 8th International Conference on Edge Computing and Scalable Cloud, CSCloud-EdgeCom 2022
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 9th IEEE International Conference on Cyber Security and Cloud Computing and 8th IEEE International Conference on Edge Computing and Scalable Cloud, CSCloud-EdgeCom 2022
Y2 - 25 June 2022 through 27 June 2022
ER -