Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing Attacks
Kaiwen Shen, Chuhan Wang, Minglei Guo, Xiaofeng Zheng, Chaoyi Lu, Baojun Liu, Yuxuan Zhao, Shuang Hao, Haixin Duan, Qingfeng Pan, Min Yang
摘要
As a fundamental communicative service, email is playing an important role in both individual and corporate communications, which also makes it one of the most frequently attack vectors. An email's authenticity is based on an authentication chain involving multiple protocols, roles and services, the inconsistency among which creates security threats. Thus, it depends on the weakest link of the chain, as any failed part can break the whole chain-based defense. This paper systematically analyzes the transmission of an email and identifies a series of new attacks capable of bypassing SPF, DKIM, DMARC and user-interface protections. In particular, by conducting a "cocktail" joint attack, more realistic emails can be forged to penetrate the celebrated email services, such as Gmail and Outlook. We conduct a large-scale experiment on 30 popular email services and 23 email clients, and find that all of them are vulnerable to certain types of new attacks. We have duly reported the identified vulnerabilities to the related email service providers, and received positive responses from 11 of them, including Gmail, Yahoo, iCloud and Alibaba. Furthermore, we propose key mitigating measures to defend against the new attacks. Therefore, this work is of great value for identifying email spoofing attacks and improving the email ecosystem's overall security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- FakeBehalf: Imperceptible Email Spoofing Attacks against the Delegation Mechanism in Email SystemsJinrui Ma, Lutong Chen, Kaiping Xue, Bo Luo 等USENIX Security 2024 · 被引用 7 次
- PiMRef: Deducing Ever-evolving Spear-phishing Emails with Knowledge Base InvariantsRuofan Liu, Yun Lin, Yuxin Wang, Xiwen Teoh 等CCS 2026 · 被引用 4 次
- Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick CheckingYuxiao Wu, Yunyi Zhang, Chaoyi Lu, Baojun LiuNDSS 2026 · 被引用 2 次
- Unfiltered: Measuring Cloud-based Email Filtering BypassesSumanth Rao, Enze Liu, Grant Ho, Geoffrey M. Voelker 等WWW 2024 · 被引用 1 次
- CoordMail: Exploiting SMTP Timeout and Command Interaction to Coordinate Email Middleware for Convergence Amplification AttackRuixuan Li, Chaoyi Lu, Baojun Liu, Yanzhong Lin 等NDSS 2026 · 被引用 1 次
它引用的顶会 Paper6
- Detecting Credential Spearphishing in Enterprise SettingsGrant Ho, Aashish Sharma, Mobin Javed, Vern Paxson 等USENIX Security 2017 · 被引用 94 次
- End-to-End Measurements of Email Spoofing AttacksHang Hu, Gang WangUSENIX Security 2018 · 被引用 94 次
- High Precision Detection of Business Email CompromiseAsaf Cidon, Lior Gavish, Itay Bleier, Nadia Korshun 等USENIX Security 2019 · 被引用 68 次
- Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration ChannelsDamian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising 等USENIX Security 2018 · 被引用 64 次
- Host of Troubles: Multiple Host Ambiguities in HTTP ImplementationsJianjun Chen, Jian Jiang, Hai-Xin Duan, Nicholas Weaver 等CCS 2016 · 被引用 49 次
相关 Paper
- Composition Kills: A Case Study of Email Sender AuthenticationJianjun Chen, Vern Paxson, Jian JiangUSENIX Security 2020
- Email Spoofing with SMTP Smuggling: How the Shared Email Infrastructures Magnify this VulnerabilityChuhan Wang, Chenkai Wang, Songyi Yang, Sophia Liu 等USENIX Security 2025
- Revisiting Email Forwarding Security under the Authenticated Received Chain ProtocolChenkai Wang, Gang WangWWW 2022 · 被引用 10 次
- BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the InternetChuhan Wang, Yasuhiro Kuranaga, Yihang Wang, Mingming Zhang 等NDSS 2024
- You've Got Report: Measurement and Security Implications of DMARC ReportingMd. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong ChungUSENIX Security 2023
