论文标题

身份验证链中的薄弱环节:电子邮件发送者欺骗攻击的大规模分析

Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing Attacks

论文作者

Shen, Kaiwen, Wang, Chuhan, Guo, Minglei, Zheng, Xiaofeng, Lu, Chaoyi, Liu, Baojun, Zhao, Yuxuan, Hao, Shuang, Duan, Haixin, Pan, Qingfeng, Yang, Min

论文摘要

作为基本的交流服务,电子邮件在个人和公司沟通中都发挥着重要作用,这也使其成为最频繁的攻击向量之一。电子邮件的真实性是基于涉及多个协议,角色和服务的身份验证链,而不一致会造成安全威胁。因此,这取决于链的最弱环节,因为任何失败的部分都可以打破基于链条的防御。本文系统地分析了电子邮件的传输,并确定了一系列能够绕过SPF,DKIM,DMARC和用户界面保护的新攻击。特别是,通过进行“鸡尾酒”联合攻击,可以伪造更现实的电子邮件来渗透诸如Gmail和Outlook之类的著名电子邮件服务。我们对30个受欢迎的电子邮件服务和23个电子邮件客户进行了大规模实验,发现所有这些都容易受到某些类型的新攻击的影响。我们已经适当地向相关的电子邮件服务提供商报告了确定的漏洞,并收到了其中11个的积极回复,包括Gmail,Yahoo,iCloud和Alibaba。此外,我们提出了重要的减轻措施来防御新攻击。因此,这项工作对于确定欺骗攻击并改善电子邮件生态系统的整体安全性具有很高的价值。

As a fundamental communicative service, email is playing an important role in both individual and corporate communications, which also makes it one of the most frequently attack vectors. An email's authenticity is based on an authentication chain involving multiple protocols, roles and services, the inconsistency among which creates security threats. Thus, it depends on the weakest link of the chain, as any failed part can break the whole chain-based defense. This paper systematically analyzes the transmission of an email and identifies a series of new attacks capable of bypassing SPF, DKIM, DMARC and user-interface protections. In particular, by conducting a "cocktail" joint attack, more realistic emails can be forged to penetrate the celebrated email services, such as Gmail and Outlook. We conduct a large-scale experiment on 30 popular email services and 23 email clients, and find that all of them are vulnerable to certain types of new attacks. We have duly reported the identified vulnerabilities to the related email service providers, and received positive responses from 11 of them, including Gmail, Yahoo, iCloud and Alibaba. Furthermore, we propose key mitigating measures to defend against the new attacks. Therefore, this work is of great value for identifying email spoofing attacks and improving the email ecosystem's overall security.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源