Lune

USENIX Security2020Top-tier venue

Composition Kills: A Case Study of Email Sender Authentication

Jianjun Chen, Vern Paxson, Jian Jiang

2020Year
23Top-tier citations

Abstract

Component-based software design has been widely adopted as a way to manage complexity and improve reusability. The approach divides complex systems into smaller modules that can be independently created and reused in different systems. One then combines these components together to achieve desired functionality. Modern software systems are commonly built using components made by different developers who work independently. While having wide-ranging benefits, the security research community has recognized that this practice also introduces security concerns. In particular, when faced with crafted adversarial inputs, different components can have inconsistent interpretations when operating on the input in sequence. Attackers can exploit such inconsistencies to bypass security policies and subvert the system's operation. In this work we provide a case study of such composition issues in the context of email (SMTP) sender authentication. We present 18 attacks for widely used email services to bypass their sender authentication checks by misusing combinations of SPF, DKIM and DMARC, which are crucial defenses against email phishing and spear-phishing attacks. Leveraging these attack techniques, an attacker can impersonate arbitrary senders without breaking email authentication, and even forge DKIM-signed emails with a legitimate site's signature. Email spoofing, commonly used in phishing attacks, poses a serious threat to both individuals and organizations. Over the past years, a number of attacks used email spoofing or phishing attacks to breach enterprise networks [5] or government officials' accounts [10] . To address this problem, modern email services and websites employ authentication protocols-SPF, DKIM, and DMARC-to prevent email forgery. These protocols authenticate different aspects of email delivery, such as the sender's IP address (SPF), content integrity (DKIM), and correctness of the domains used for these checks (DMARC). Our research in USENIX Security 2020 [3] identified a set of practical exploits to show the fragility of these protocols as implemented in practice. The key problem is that different components in the email processing chain employ a wide range of inconsistent interpretation regarding precisely how to interpret the different email elements they secure. Figure 1 illustrates one of our spoofing attacks to impersonating facebook.com by exploiting the inconsistency between the DKIM and DNS components. Gmail attests that the email was indeed from

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 1dabb339-bd94-4bdd-9fcd-0e5749e6ff7e

Cited by top-tier papers23

Ask how each one uses it

Builds on1

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines