Network World – When we think of the victim in a phishing attack, we think of the unfortunate email recipient that has fallen for a ruse and
has given away their sensitive information or downloaded malware to their computer. But there’s often another victim in a
phishing attack: the company whose brand has been usurped for the purpose of delivering a convincing message, albeit an illegitimate
one.
Think of the PayPals, the UPSs and the Citibanks of the world — the companies whose reputations suffer every time some cybercriminal
spoofs a message so that it appears to come from them, businesses the recipient knows and trusts. According to the Anti-Phishing
Working Group, an average of 418 companies had their good names besmirched as part of a phishing attempt each month in the
last quarter of 2012. Perhaps your own company was among them.
[ FAQ: Phishing tactics and how attackers get away with it
BACKGROUND: Google, Microsoft and others putting kibosh on phishing emails ]
Now there is a technical specification that builds on other email standards to help reduce the potential for email-based abuse
of a brand. The specification is called DMARC, which stands for Domain-based Message Authentication, Reporting and Conformance.
To explain the purpose of DMARC, we have to go back in time before email authentications standards existed.
Suppose you receive an email message that appears to come from your Local Bank, whose domain is LocalBank.com. With the original
email standards anyone could say they were sending email from LocalBank.com, so someone who knows you have a relationship
with Local Bank could tell you that you need to reset your password and then send you a link to a fraudulent website to capture
your password, account information or other sensitive information.
In this context, the fundamental challenge the messaging industry wanted to solve is message authentication. As the recipient
of the email, you need to have confidence that a message that purports to be from LocalBank.com really was issued by Local
Bank and not by some entity pretending to be the bank.
There are two standards for email authentication. One is SPF, which stands for Sender Policy Framework, and the other is DKIM,
or DomainKeys Identified Mail.
SPF is basically an IP-based path-based authentication mechanism. It allows Local Bank to tell receivers such as Comcast,
Gmail and Yahoo, “These are the IP addresses or the third parties that are allowed to send mail on my behalf and these are
the IP addresses that they are sending from. If you see something that is not coming from any of these IP addresses, then
it doesn’t pass SPF and the mail can be rejected.” The intention is that spoofed email will never get past the ISPs to the
targeted recipient.
DKIM is a signature-based authentication. When a message is sent out, certain parts of that message are signed so when the
ISP receives it, they can validate to ensure the pieces of the message that were signed did not change during the transmission
of the message. This means the person who receives the message can be sure the content of the email is exactly the same as
what was sent.
Linda Musthaler is a principal analyst with Essential Solutions Corporation.
