FakeBehalf: Imperceptible Email Spoofing Attacks against the Delegation Mechanism in Email Systems
Jinrui Ma, Lutong Chen, Kaiping Xue, Bo Luo, Xuanbo Huang, Mingrui Ai, Huanjie Zhang, David S. L. Wei, Yan Zhuang
摘要
Email has become an essential service for global communication. In email protocols, a Delegation Mechanism allows emails to be sent by other entities on behalf of the email author. Specifically, the Sender field indicates the agent for email delivery (i.e., the Delegate). Despite well-implemented security extensions (e.g., DKIM, DMARC) that validate the authenticity of email authors, vulnerabilities in the Delegation Mechanism can still be exploited to bypass these security measures with well-crafted spoofing emails. This paper systematically analyzes the security vulnerabilities within the Delegation Mechanism. Due to the absence of validation for the Sender field, adversaries can arbitrarily fabricate this field, thus spoofing the Delegate presented to email recipients. Our observations reveal that emails with a spoofed Sender field can pass authentications and reach the inboxes of all target providers. We also conduct a user study with 50 participants to assess the recipients' comprehension of spoofed Delegates, finding that 50% are susceptible to deceiving Delegate information. Furthermore, we propose novel email spoofing attacks where adversaries can impersonate arbitrary entities as email authors to craft highly deceptive emails while passing security extensions. We assess their impact across 16 service providers and 20 clients, observing that half of the providers and all clients are vulnerable to the discovered attacks. To mitigate the threats within the Delegation Mechanism, we propose a validation scheme to verify the authenticity of the Sender field, along with design suggestions to enhance the security of email clients.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- One Email, Many Faces: A Deep Dive into Identity Confusion in Email AliasesMengying Wu, Geng Hong, Jiatao Chen, Baojun Liu 等NDSS 2026
- Automatic Insecurity: Exploring Email Auto-configuration in the WildShushang Wen, Yiming Zhang, Yuxiang Shen, Bingyu Li 等NDSS 2025
它引用的顶会 Paper15
- End-to-End Measurements of Email Spoofing AttacksHang Hu, Gang WangUSENIX Security 2018 · 被引用 94 次
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 被引用 92 次
- Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration ChannelsDamian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising 等USENIX Security 2018 · 被引用 64 次
- Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing AttacksKaiwen Shen, Chuhan Wang, Minglei Guo, Xiaofeng Zheng 等USENIX Security 2021 · 被引用 49 次
- "Johnny, you are fired!" - Spoofing OpenPGP and S/MIME Signatures in EmailsJens Müller, Marcus Brinkmann, Damian Poddebniak, Hanno Böck 等USENIX Security 2019 · 被引用 34 次
相关 Paper
- Composition Kills: A Case Study of Email Sender AuthenticationJianjun Chen, Vern Paxson, Jian JiangUSENIX Security 2020
- You've Got Report: Measurement and Security Implications of DMARC ReportingMd. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong ChungUSENIX Security 2023
- BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the InternetChuhan Wang, Yasuhiro Kuranaga, Yihang Wang, Mingming Zhang 等NDSS 2024
- Email Spoofing with SMTP Smuggling: How the Shared Email Infrastructures Magnify this VulnerabilityChuhan Wang, Chenkai Wang, Songyi Yang, Sophia Liu 等USENIX Security 2025
- Revisiting Email Forwarding Security under the Authenticated Received Chain ProtocolChenkai Wang, Gang WangWWW 2022 · 被引用 10 次
