Solicitation token authenticated mail protocol

Kurt Ackermann, Camille Gaspard, Ramana Rao Kompella, Cristina Nita-Rotaru · Annual Information Security Symposium · 2008

Email has grown into one of the dominant forms of communication in the 21st century. However, email systems were designed without security in mind, thus allowing attackers to abuse the system and send unsolicited email (or spam). Most current solutions to spam center on content-based filtering or domain blacklisting approaches, both of which are inaccurate and slow to adapt to the changing face of spam. Moreover, these schemes do not allow for the accountability of email address leakage, which would allow a user to know which untrustworthy parties divulged his address. We propose STAMP, the Solicitation Token Authenticated Mail Protocol, as a server-side solution to filter unsolicited mail from ever reaching the end-user's inbox, as well as allowing the user to revoke inbox access from solicited parties who prove to be untrustworthy with their email access. STAMP employs distributed access control, making use of transitive trust to reduce email solicitation overhead and allow the user's address book to grow organically through trusted entities. We implement a prototype of our scheme as an extensible mail filter plug-in for an industry standard mail server. We compare performance and server overhead of STAMP against a popular content-based filter and show that our scheme attains a 43% reduction in message delivery latency and achieves perfect message classification with a processing cost that is lower by more than 3 orders of magnitude.

Read the paper · More papers on PaperTik