End-to-End Measurements of Email Spoofing Attacks

End-to-End Measurements of Email Spoofing Attacks
复制标题

DOI:
--
复制
发表时间:
2018
期刊:
--
影响因子:
--
通讯作者:
Hang Hu;G. Wang
Hang Hu;G. Wang
中科院分区:
其他
文献类型:
--
作者:
Hang Hu;G. Wang

文献摘要

被引文献

相似文献

鱼叉式网络钓鱼一直是用户和组织面临的持续威胁,但电子邮件提供商仍然面临着验证传入电子邮件的关键挑战。因此,攻击者可以应用欺骗技术来冒充受信任的实体来进行高度欺骗性的网络钓鱼攻击。在这项工作中,我们研究了电子邮件欺骗,以回答三个关键问题:(1)电子邮件提供商如何检测和处理伪造电子邮件?(2)伪造邮件在什么条件下可以穿透防御到达用户收件箱?(3)一旦伪造邮件进入,邮件提供商如何提醒用户?这个警告真的有效吗?我们通过对35个流行的电子邮件提供商进行端到端测量,并通过真实的欺骗/网络钓鱼测试检查用户对欺骗的反应,来回答这些问题。我们的主要发现有三个方面。首先,我们观察到大多数电子邮件提供商都有必要的协议来检测欺骗,但仍然允许伪造的电子邮件到达用户的收件箱(例如,Yahoo Mail, iCloud, bgmail)。其次,一旦伪造的电子邮件进入,大多数电子邮件提供商都不会对用户发出警告,尤其是对移动电子邮件应用程序。一些提供商(例如bgmail Inbox)甚至具有误导性的ui,使伪造的电子邮件看起来是真实的。第三,少数电子邮件提供商(9/35)在未经验证的电子邮件上实施了视觉安全指示器。我们的网络钓鱼实验表明,安全指标对减少高风险用户行为有积极影响,但不能消除风险。我们的研究揭示了电子邮件提供商和最终用户之间的一个主要误解。需要在两端(服务器端协议和ui)进行改进,以弥合差距。
Spear phishing has been a persistent threat to users and organizations, and yet email providers still face key challenges to authenticate incoming emails. As a result, attackers can apply spoofing techniques to impersonate a trusted entity to conduct highly deceptive phishing attacks. In this work, we study email spoofing to answer three key questions: (1) How do email providers detect and handle forged emails? (2) Under what conditions can forged emails penetrate the defense to reach user inbox? (3) Once the forged email gets in, how email providers warn users? Is the warning truly effective? We answer these questions by conducting an end-toend measurement on 35 popular email providers and examining user reactions to spoofing through a real-world spoofing/phishing test. Our key findings are three folds. First, we observe that most email providers have the necessary protocols to detect spoofing, but still allow forged emails to reach the user inbox (e.g., Yahoo Mail, iCloud, Gmail). Second, once a forged email gets in, most email providers have no warning for users, particularly for mobile email apps. Some providers (e.g., Gmail Inbox) even have misleading UIs that make the forged email look authentic. Third, a few email providers (9/35) have implemented visual security indicators on unverified emails. Our phishing experiment shows that security indicators have a positive impact on reducing risky user actions, but cannot eliminate the risk. Our study reveals a major miscommunication between email providers and endusers. Improvements at both ends (server-side protocols and UIs) are needed to bridge the gap.