USENIX Security2020Top-tier venue
Composition Kills: A Case Study of Email Sender Authentication
Jianjun Chen, Vern Paxson, Jian Jiang
Abstract
Component-based software design has been widely adopted as a way to manage complexity and improve reusability. The approach divides complex systems into smaller modules that can be independently created and reused in different systems. One then combines these components together to achieve desired functionality. Modern software systems are commonly built using components made by different developers who work independently. While having wide-ranging benefits, the security research community has recognized that this practice also introduces security concerns. In particular, when faced with crafted adversarial inputs, different components can have inconsistent interpretations when operating on the input in sequence. Attackers can exploit such inconsistencies to bypass security policies and subvert the system's operation. In this work we provide a case study of such composition issues in the context of email (SMTP) sender authentication. We present 18 attacks for widely used email services to bypass their sender authentication checks by misusing combinations of SPF, DKIM and DMARC, which are crucial defenses against email phishing and spear-phishing attacks. Leveraging these attack techniques, an attacker can impersonate arbitrary senders without breaking email authentication, and even forge DKIM-signed emails with a legitimate site's signature. Email spoofing, commonly used in phishing attacks, poses a serious threat to both individuals and organizations. Over the past years, a number of attacks used email spoofing or phishing attacks to breach enterprise networks [5] or government officials' accounts [10] . To address this problem, modern email services and websites employ authentication protocols-SPF, DKIM, and DMARC-to prevent email forgery. These protocols authenticate different aspects of email delivery, such as the sender's IP address (SPF), content integrity (DKIM), and correctness of the domains used for these checks (DMARC). Our research in USENIX Security 2020 [3] identified a set of practical exploits to show the fragility of these protocols as implemented in practice. The key problem is that different components in the email processing chain employ a wide range of inconsistent interpretation regarding precisely how to interpret the different email elements they secure. Figure 1 illustrates one of our spoofing attacks to impersonating facebook.com by exploiting the inconsistency between the DKIM and DNS components. Gmail attests that the email was indeed from
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1dabb339-bd94-4bdd-9fcd-0e5749e6ff7eCited by top-tier papers23
- Assessing Browser-level Defense against IDN-based PhishingHang Hu, Steve T. K. Jan, Yang Wang, Gang WangUSENIX Security 2021 · 22 citations
- Break the Wall from Bottom: Automated Discovery of Protocol-Level Evasion Vulnerabilities in Web Application FirewallsQi Wang, Jianjun Chen, Zheyu Jiang, Run Guo et al.S&P 2024 · 11 citations
- Revisiting Email Forwarding Security under the Authenticated Received Chain ProtocolChenkai Wang, Gang WangWWW 2022 · 10 citations
- FakeBehalf: Imperceptible Email Spoofing Attacks against the Delegation Mechanism in Email SystemsJinrui Ma, Lutong Chen, Kaiping Xue, Bo Luo et al.USENIX Security 2024 · 7 citations
- VeriSMS: A Message Verification System for Inclusive Patient Outreach against Phishing AttacksChenkai Wang, Zhuofan Jia, Hadjer Benkraouda, Cody Zevnik et al.CHI 2024 · 5 citations
Builds on1
Related papers
- Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing AttacksKaiwen Shen, Chuhan Wang, Minglei Guo, Xiaofeng Zheng et al.USENIX Security 2021 · 49 citations
- Email Spoofing with SMTP Smuggling: How the Shared Email Infrastructures Magnify this VulnerabilityChuhan Wang, Chenkai Wang, Songyi Yang, Sophia Liu et al.USENIX Security 2025
- You've Got Report: Measurement and Security Implications of DMARC ReportingMd. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong ChungUSENIX Security 2023
- BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the InternetChuhan Wang, Yasuhiro Kuranaga, Yihang Wang, Mingming Zhang et al.NDSS 2024
- One Email, Many Faces: A Deep Dive into Identity Confusion in Email AliasesMengying Wu, Geng Hong, Jiatao Chen, Baojun Liu et al.NDSS 2026
