Please use this identifier to cite or link to this item: doi:10.22028/D291-29343
Volltext verfügbar? / Dokumentlieferung
Title: Formally Reasoning about the Cost and Efficacy of Securing the Email Infrastructure
Author(s): Speicher, Patrick
Steinmetz, Marcel
Künnemann, Robert
Simeonovski, Milivoj
Pellegrino, Giancarlo
Hoffmann, Jörg
Backes, Michael
Language: English
Title: 3rd IEEE European Symposium on Security and Privacy : EUROS&P 2018 : proceedings : 24-26 April 2018, London, United Kingdom
Startpage: 77
Endpage: 91
Publisher/Platform: IEEE
Year of Publication: 2018
Title of the Conference: EUROS&P 2018
Place of the conference: London, United Kingdom
Publikation type: Conference Paper
Abstract: Security in the Internet has historically been added post-hoc, leaving services like email, which, after all, is used by 3.7 billion users, vulnerable to large-scale surveillance. For email alone, there is a multitude of proposals to mitigate known vulnerabilities, ranging from the introduction of completely new protocols to modifications of the communication paths used by big providers. Deciding which measures to deploy requires a deep understanding of the induced benefits, the cost and the resulting effects. This paper proposes the first automated methodology for making formal deployment assessments. Our planning algorithm analyses the impact and cost-efficiency of different known mitigation strategies against an attacker in a formal threat model. This novel formalisation of an infrastructure attacker includes routing, name resolution and application level weaknesses. We apply the methodology to a large-scale scan of the Internet, and assess how protocols like IPsec, DNSSEC, DANE, SMTP STS, SMTP over TLS and other mitigation techniques like server relocation can be combined to improve the confidentiality of email users in 45 combinations of attacker and defender countries and nine cost scenarios. This is the first deployment analysis for mitigation techniques at this scale.
DOI of the first publication: 10.1109/EuroSP.2018.00014
URL of the first publication: https://ieeexplore.ieee.org/document/8406592
Link to this record: hdl:20.500.11880/28340
http://dx.doi.org/10.22028/D291-29343
ISBN: 978-1-5386-4228-3
978-1-5386-4227-6
978-1-5386-4229-0
Date of registration: 21-Nov-2019
Third-party funds sponsorship: BMBF through funding for the Center for IT-Security, Privacy and Accountability (CISPA)
Sponsorship ID: BMBF 16KIS0656
Faculty: MI - Fakultät für Mathematik und Informatik
Department: MI - Informatik
Professorship: MI - Prof. Dr. Jörg Hoffmann
Collections:SciDok - Der Wissenschaftsserver der Universität des Saarlandes

Files for this record:
There are no files associated with this item.


Items in SciDok are protected by copyright, with all rights reserved, unless otherwise indicated.