Presentation 2010-07-01
On the use and misuse of E-mail sender authentication mechanisms
Tatsuya MORI,
PDF Download Page PDF download Page Link
Abstract(in Japanese) (See Japanese page)
Abstract(in English) E-mail sender authentication is a promising way of verifying the sources of e-mail messages. Since today's primary e-mail sender authentication mechanisms are designed as fully decentralized architecture, it is crucial for e-mail operators to know how other organizations are using and misusing them. This paper aims to address the question "How is the DNS Sender Policy Framework (SPF), which is the most popular e-mail sender authentication mechanism, used and misused in the wild?" To the best of our knowledge, this is the first extensive study addressing the fundamental question. This work targets both legitimate and spamming domain names and correlates them with multiple data sets, including the e-mail delivery logs collected from medium-scale enterprise networks and various IP reputation lists. We first present the adoption and usage of DNS SPF from both global and local viewpoints. Next, we present empirically why and how spammers leverage the SPF mechanism in an attempt to pass a simple SPF authentication test. We also present that non-negligible volume of legitimate messages originating from legitimate senders will be rejected or marked as potential spam with the SPF policy set by owners of legitimate domains. Our findings will help provide (1) e-mail operators with useful insights for setting adequate sender or receiver policies and (2) researchers with the detailed measurement data for understanding the feasibility, fundamental limitations, and potential extensions to e-mail sender authentication mechanisms.
Keyword(in Japanese) (See Japanese page)
Keyword(in English) spam / sender authentication / SPF / measurement
Paper # ISEC2010-22,SITE2010-18,ICSS2010-28
Date of Issue

Conference Information
Committee ISEC
Conference Date 2010/6/24(1days)
Place (in Japanese) (See Japanese page)
Place (in English)
Topics (in Japanese) (See Japanese page)
Topics (in English)
Chair
Vice Chair
Secretary
Assistant

Paper Information
Registration To Information Security (ISEC)
Language ENG
Title (in Japanese) (See Japanese page)
Sub Title (in Japanese) (See Japanese page)
Title (in English) On the use and misuse of E-mail sender authentication mechanisms
Sub Title (in English)
Keyword(1) spam
Keyword(2) sender authentication
Keyword(3) SPF
Keyword(4) measurement
1st Author's Name Tatsuya MORI
1st Author's Affiliation NTT Service Integration Laboratories()
Date 2010-07-01
Paper # ISEC2010-22,SITE2010-18,ICSS2010-28
Volume (vol) vol.110
Number (no) 113
Page pp.pp.-
#Pages 6
Date of Issue