ietf-asrg
[Top] [All Lists]

Re: [Asrg] DNS-based Email Sender Authentication Mechanisms: a Critical Review

2009-05-25 06:15:58

Amir should send it to the list before sending it to be published by Science Direct. I'm not sure, but it seems to me that even he, he can't distribute a copy of the paper, now. Unfortunately.

I have a copy of it (but I haven't yet read it), as our library subscribes to that service, but, as long as I know, I can't either redistribute it.

Cheers,



Steve Atkins wrote:

On May 24, 2009, at 12:58 AM, Amir Herzberg wrote:

Hi guys, I wrote a `critical review' of SPF, DKIM and Sender-ID Framework (SIDF); it's in process of publication at `computer & security`, you can see it at http://dx.doi.org/10.1016/j.cose.2009.05.002 (pending editing, final changes etc.). Nothing much new, just an attempt to provide a fair-yet-critical survey, hopefully to help clarify this important subject. Comments will be most welcome. Abstract below.

I'm not going to pay $31.50 to review someone's work. Nor is anyone else, I suspect.

Cheers,
  Steve



Amir Herzberg

Title: DNS-based Email Sender Authentication Mechanisms: a Critical Review

Abstract

We describe and compare three predominant email sender authentication mechanisms based on DNS: SPF, DKIM and Sender-ID Framework (SIDF). These mechanisms are designed mainly to assist in filtering of undesirable email messages, in particular spam and phishing emails.We clarify the limitations of these mechanisms, identify risks, and make recommendations. In particular, we discuss potential abuse of these mechanisms to facilitate DNS poisoning, and suggest countermeasures.

--
Amir Herzberg
Associate Professor, Dept. of Computer Science
Bar Ilan University
http://AmirHerzberg.com
_______________________________________________
Asrg mailing list
Asrg(_at_)irtf(_dot_)org
http://www.irtf.org/mailman/listinfo/asrg

_______________________________________________
Asrg mailing list
Asrg(_at_)irtf(_dot_)org
http://www.irtf.org/mailman/listinfo/asrg



--
 ---------------------------------------------------------------
 Jose Marcio MARTINS DA CRUZ           http://j-chkmail.ensmp.fr
 Ecole des Mines de Paris
 60, bd Saint Michel                      75272 - PARIS CEDEX 06
 mailto:Jose-Marcio(_dot_)Martins(_at_)mines-paristech(_dot_)fr
_______________________________________________
Asrg mailing list
Asrg(_at_)irtf(_dot_)org
http://www.irtf.org/mailman/listinfo/asrg

<Prev in Thread] Current Thread [Next in Thread>