Towards Understanding the Adoption of Anti-Spoofing Protocols in Email Systems

Towards Understanding the Adoption of Anti-Spoofing Protocols in Email Systems
复制标题

DOI:
10.1109/secdev.2018.00020
复制
发表时间:
2018-09
期刊:
2018 IEEE Cybersecurity Development (SecDev)
影响因子:
--
通讯作者:
Hang Hu;Peng Peng-Peng;G. Wang
Hang Hu;Peng Peng-Peng;G. Wang
中科院分区:
其他
文献类型:
--
作者:
Hang Hu;Peng Peng-Peng;G. Wang

文献摘要

被引文献

相似文献

电子邮件欺骗是网络钓鱼攻击的关键步骤,攻击者冒充受害者认识或信任的人。即使在今天,电子邮件提供商仍然面临着检测或防止欺骗的关键挑战,尽管多年来设计和开发了反欺骗协议(例如SPF, DKIM, DMARC)。关键问题是反欺骗协议没有被广泛采用,特别是新的DMARC协议(5.1%)。在本文中,我们试图了解反欺骗协议采用率低背后的原因。我们对来自不同机构的N=9名电子邮件管理员进行了用户研究,以了解他们对反欺骗协议的看法。我们的结果表明,电子邮件管理员意识到并关注SPF、DKIM和DMARC中的技术弱点,这些弱点很容易导致错误(例如,阻止合法电子邮件)。电子邮件管理员认为,由于协议存在缺陷、激励机制薄弱和实际部署方面的挑战,当前协议的采用还没有达到关键水平。基于这些结果,我们讨论了对协议设计者、电子邮件提供商和用户的关键影响,以及未来减轻电子邮件欺骗威胁的研究方向。
Email spoofing is a critical step in phishing attacks, where the attacker impersonates someone that the victim knows or trusts. Even today, email providers still face key challenges to detect or prevent spoofing, despite the years of efforts to design and develop anti-spoofing protocols (e.g., SPF, DKIM, DMARC). The key problem is that anti-spoofing protocols are not widely adopted, especially for the new DMARC protocol (5.1%). In this paper, we seek to understand the reasons behind the low adoption rates of anti-spoofing protocols. We conduct a user study with N=9 email administrators from different institutions to understand their perceptions towards anti-spoofing protocols. Our result suggests that email administrators are aware of and concerned about the technical weaknesses in SPF, DKIM, and DMARC that can easily cause errors (e.g., blocking legitimate emails). Email administrators believe the current protocol adoption lacks the crucial mass due to the protocol defects, weak incentives, and practical deployment challenges. Based on these results, we discuss the key implications to protocol designers, email providers and users, and future research directions to mitigate the email spoofing threats.