Fuzzing E-mail filters with generative grammars and N-gram analysis

Sean Palka, Damon McCoy · 2015

Phishing attacks remain a common attack vector in to-day’s IT threat landscape, and one of the primary means of preventing phishing attacks is e-mail filtering. Most e-mail filtering is done according to a either a signature-based approach or using Bayesian models, so when spe-cific signatures are detected the e-mail is either quar-antined or moved to a Junk mailbox. Much like anti-virus, though, a signature-based approach is inadequate when it comes to detecting zero-day phishing e-mails, and can often be bypassed with slight variations in the e-mail contents. In this paper, we demonstrate an ap-proach to evaluating the effectiveness of e-mail filters using a fuzzing strategy. We present a system that uti-lizes generative grammars to create large sets of unique phishing e-mails, which can then be used for fuzzing in-put against e-mail filters. Rather than creating random text, our approach maintains a high degree of semantic quality in generated e-mails. We demonstrate how our system is able to adapt to existing filters and identify con-tents that are not detected, and show how this approach can be used to ensure the delivery of e-mails without the need to white-list. 1

Read the paper · More papers on PaperTik