Composition Kills: A Case Study of Email Sender Authentication
Jianjun Chen, Vern Paxson, Jian Jiang
摘要
Component-based software design has been widely adopted as a way to manage complexity and improve reusability. The approach divides complex systems into smaller modules that can be independently created and reused in different systems. One then combines these components together to achieve desired functionality. Modern software systems are commonly built using components made by different developers who work independently. While having wide-ranging benefits, the security research community has recognized that this practice also introduces security concerns. In particular, when faced with crafted adversarial inputs, different components can have inconsistent interpretations when operating on the input in sequence. Attackers can exploit such inconsistencies to bypass security policies and subvert the system's operation. In this work we provide a case study of such composition issues in the context of email (SMTP) sender authentication. We present 18 attacks for widely used email services to bypass their sender authentication checks by misusing combinations of SPF, DKIM and DMARC, which are crucial defenses against email phishing and spear-phishing attacks. Leveraging these attack techniques, an attacker can impersonate arbitrary senders without breaking email authentication, and even forge DKIM-signed emails with a legitimate site's signature. Email spoofing, commonly used in phishing attacks, poses a serious threat to both individuals and organizations. Over the past years, a number of attacks used email spoofing or phishing attacks to breach enterprise networks [5] or government officials' accounts [10] . To address this problem, modern email services and websites employ authentication protocols-SPF, DKIM, and DMARC-to prevent email forgery. These protocols authenticate different aspects of email delivery, such as the sender's IP address (SPF), content integrity (DKIM), and correctness of the domains used for these checks (DMARC). Our research in USENIX Security 2020 [3] identified a set of practical exploits to show the fragility of these protocols as implemented in practice. The key problem is that different components in the email processing chain employ a wide range of inconsistent interpretation regarding precisely how to interpret the different email elements they secure. Figure 1 illustrates one of our spoofing attacks to impersonating facebook.com by exploiting the inconsistency between the DKIM and DNS components. Gmail attests that the email was indeed from
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper23
- Assessing Browser-level Defense against IDN-based PhishingHang Hu, Steve T. K. Jan, Yang Wang, Gang WangUSENIX Security 2021 · 被引用 22 次
- Break the Wall from Bottom: Automated Discovery of Protocol-Level Evasion Vulnerabilities in Web Application FirewallsQi Wang, Jianjun Chen, Zheyu Jiang, Run Guo 等S&P 2024 · 被引用 11 次
- Revisiting Email Forwarding Security under the Authenticated Received Chain ProtocolChenkai Wang, Gang WangWWW 2022 · 被引用 10 次
- FakeBehalf: Imperceptible Email Spoofing Attacks against the Delegation Mechanism in Email SystemsJinrui Ma, Lutong Chen, Kaiping Xue, Bo Luo 等USENIX Security 2024 · 被引用 7 次
- VeriSMS: A Message Verification System for Inclusive Patient Outreach against Phishing AttacksChenkai Wang, Zhuofan Jia, Hadjer Benkraouda, Cody Zevnik 等CHI 2024 · 被引用 5 次
它引用的顶会 Paper1
相关 Paper
- Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing AttacksKaiwen Shen, Chuhan Wang, Minglei Guo, Xiaofeng Zheng 等USENIX Security 2021 · 被引用 49 次
- Email Spoofing with SMTP Smuggling: How the Shared Email Infrastructures Magnify this VulnerabilityChuhan Wang, Chenkai Wang, Songyi Yang, Sophia Liu 等USENIX Security 2025
- You've Got Report: Measurement and Security Implications of DMARC ReportingMd. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong ChungUSENIX Security 2023
- BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the InternetChuhan Wang, Yasuhiro Kuranaga, Yihang Wang, Mingming Zhang 等NDSS 2024
- One Email, Many Faces: A Deep Dive into Identity Confusion in Email AliasesMengying Wu, Geng Hong, Jiatao Chen, Baojun Liu 等NDSS 2026
