网络与信息安全学报 ›› 2020, Vol. 6 ›› Issue (6): 69-79.doi: 10.11959/j.issn.2096-109x.2020083

• 专栏:网络应用与防护技术 • 上一篇    下一篇

电子邮件安全扩展协议应用分析

尚菁菁1,2,3,朱宇佳2,3(),刘庆云2,3   

  1. 1 中国科学院大学网络空间安全学院,北京 100093
    2 信息内容安全技术国家工程实验室,北京 100093
    3 中国科学院信息工程研究所,北京 100093
  • 修回日期:2020-07-03 出版日期:2020-12-15 发布日期:2020-12-16
  • 作者简介:尚菁菁(1995- ),女,北京人,中国科学院大学硕士生,主要研究方向为网络空间安全|朱宇佳(1984- ),女,江苏无锡人,博士,中国科学院信息工程研究所高级工程师,主要研究方向为网络空间测绘、安全态势感知技术|刘庆云(1980- ),男,河北人,博士,中国科学院信息工程研究所高级工程师,主要研究方向为网络空间测绘、网络空间安全
  • 基金资助:
    中国科学院战略性先导科技专项(XDC02030000);国家重点研发计划(2016YFB0801300)

Analysis of security extension protocol in e-mail system

Jingjing SHANG1,2,3,Yujia ZHU2,3(),Qingyun LIU2,3   

  1. 1 School of Cyber Security,University of Chinese Academy of Sciences,Beijing 100093,China
    2 National Engineering Laboratory for Information Security Technologies,Beijing 100093,China
    3 Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100093,China
  • Revised:2020-07-03 Online:2020-12-15 Published:2020-12-16
  • Supported by:
    Chinese Academy of Sciences Strategic Pilot Project(XDC02030000);National Key R & D Program(2016YFB0801300)

摘要:

电子邮件是黑客发起网络攻击的主要入口,其中身份仿冒是电子邮件欺诈重要手段。基于邮件身份验证机制,构建属性图以测量政府机构电子邮件安全扩展协议全球采用率。从邮件内容仿冒、域仿冒、信头仿冒 3 个维度研究安全扩展协议部署效果。结果表明,各国政府机构邮件系统中部署 SPF 协议的约占70%,部署DMARC协议的不足30%,电子邮件身份检测采用率较低。当欺诈邮件进入收件人邮箱后,邮件服务提供商针对仿冒邮件警告机制有待完善。

关键词: 电子邮件, 安全扩展协议, 域名密钥识别邮件标准, 发件人策略框架, 基于域的邮件验证、报告和一致性

Abstract:

E-mail is the main entry point for hackers to launch network attacks.Impersonating a trusted entity is an important means of e-mail forged.An attribute graph based on the e-mail authentication mechanism was built to measure the global adoption rate of e-mail security extension protocols for government agencies.Research on the deployment effect of security extension protocol was from three dimensions:e-mail content phishing,domain phishing,and letterhead phishing.The results show that about 70% of the SPF protocols are deployed in the mail systems of government agencies in various countries,and less than 30% of the DMARC protocol is deployed.The adoption rate of email identity detection is low.When forged e-mail gets in,the e-mail providers' warning mechanism for counterfeit emails need to be improved.

Key words: e-mail, security extension protocol, DKIM, SPF, DMARC

中图分类号: 

No Suggested Reading articles found!