The Unintended Consequences of Email Spam Prevention

The Unintended Consequences of Email Spam Prevention
复制标题

垃圾邮件预防的意外后果

DOI:
--
复制
发表时间:
2018
期刊:
Passive and Active Network Measurement Conference
影响因子:
--
通讯作者:
S. Goldberg
S. Goldberg
中科院分区:
--
文献类型:
--
作者:
Sarah Scheffler;Sean W. Smith;Y. Gilad;S. Goldberg

文献摘要

被引文献

相似文献

为了对抗域名系统(DNS)缓存中毒攻击和利用DNS作为拒绝服务(DoS)攻击的放大器,许多递归DNS解析器被配置为“关闭”,并拒绝回答其组织外部的主机发出的查询。在这项工作中,我们提出了一种技术,以诱导DNS查询在一个组织内,使用该组织的电子邮件服务和DNS策略框架(SPF)的垃圾邮件检查机制。我们使用我们的技术来研究封闭解析器。我们的研究表明,大多数封闭的DNS解析器都部署了常见的DNS中毒防御技术,例如源端口和事务ID随机化。然而,我们还发现SPF通常以一种允许外部攻击者通过向组织域内的任何地址发送单个电子邮件来导致组织的解析器向受害者IP地址发出大量DNS查询的方式部署,从而提供潜在的DoS向量。
To combat Domain Name System (DNS) cache poisoning attacks and exploitation of the DNS as amplifier in denial of service (DoS) attacks, many recursive DNS resolvers are configured as “closed” and refuse to answer queries made by hosts outside of their organization. In this work, we present a technique to induce DNS queries within an organization, using the organization’s email service and the Sender Policy Framework (SPF) spam-checking mechanism. We use our technique to study closed resolvers. Our study reveals that most closed DNS resolvers have deployed common DNS poisoning defense techniques such as source port and transaction ID randomization. However, we also find that SPF is often deployed in a way that allows an external attacker to cause the organization’s resolver to issue numerous DNS queries to a victim IP address by sending a single email to any address within the organization’s domain, thereby providing a potential DoS vector.