Advantages and vulnerabilities of pull-based email-delivery

Natascha Chrobok, Andrew Trotman, Richard A. O’Keefe · 2010

Over the last decade spam has become a serious prob-lem to email-users all over the world. Most of the daily email-traffic consists of this unwanted spam. There are various methods that have been proposed to fight spam, from IP-based blocking to filtering in-coming email-messages. However it seems that it is impossible to overcome this problem as the number of email-messages that are considered spam is increas-ing. But maybe these techniques target the problem at the wrong side: it is the email-delivery protocol it-self that fosters the existence of spam. What once was created to make internet-mail communication as easy and as reliable as possible became abused by mod-ern day spammers. This paper proposes a different approach: instead of accepting all messages unques-tioned it introduces a way to empower the receiver by giving him the control to decide if he wants to receive a message or not. By extending SMTP to pull mes-sages instead of receiving them an attempt to stem the flood of spam is made. The pull-based approach works without involvement of the end-users. How-ever this new system does not come without a price: it opens the possibility of a distributed denial of ser-vice (DDOS)-attacks against legitimate mail-transfer agents. This vulnerability and possible ways to over-come it are also discussed in this paper.

Read the paper · More papers on PaperTik