高级检索

一封邮件,多张面孔:深入探究电子邮件别名中的身份混淆问题

One Email, Many Faces: A Deep Dive into Identity Confusion in Email Aliases

  • 摘要: 电子邮件地址作为在线账户管理的通用标识符,其别名机制在电子邮件提供商和外部平台之间造成了显著的身份混淆。本文首次对电子邮件别名引起的不一致性进行了系统分析,分析发现,提供商将别名地址(例如,ALICE@example.com、alice+work@example.com)视为基础电子邮件(alice@example.com)的额外入口,而平台通常将其视为不同的身份。之后对28家电子邮件提供商和18个在线平台的别名机制进行实证评估,结果显示:1)电子邮件提供商中 仅Gmail对其别名规则进行了全面文档化,而11家提供商则隐式支持未文档化的别名行为;2) 由于缺乏别名机制的标准化文档和实施规范,平台要么无法区分别名地址,要么过于激进地排除所有包含特定符号的电子邮件。现实世界中的滥用案例表明,攻击者利用别名在npm中通过单个基础电子邮件创建多达139个账户,以进行垃圾邮件攻击。本文通过开展用户调研进一步揭示了别名机制的安全风险。调研结果显示:31.65%的具有别名知识的参与者误将钓鱼邮件地址视为合法电子邮件别名,问题的原因是电子邮件提供商别名机制实施不一致;那些自认为了解电子邮件别名机制的用户,尤其是受教育程度高、男性且具有技术背景的参与者,更容易遭受钓鱼邮件攻击。本文强调了使用者对电子邮件别名机制标准化文档和信息透明度的迫切需求,并贡献了OriginMail工具,以帮助平台解决别名混淆问题,并向受影响的利益相关者披露有关漏洞。

     

    Abstract: Email addresses serve as a universal identifier for online account management, however, their aliasing mechanisms introduce significant identity confusion between email providers and external platforms. This article presents the first systematic analysis of the inconsistencies arising from email aliasing, where providers view alias addresses (e.g., ALICE@example.com, alice+work@example.com) as additional entrances of the base email (alice@example.com), while platforms often treat them as distinct identities. Through empirical evaluations of the alias mechanisms of 28 email providers and 18 online platforms, we reveal critical gaps: 1) Only Gmail fully documents its aliasing rules, while 11 providers silently support undocumented alias behaviors; 2) Due to lack of standardization documentation and de facto implementation, platforms either fail to distinguish alias addresses or overly aggressively exclude all emails containing specific symbols. Real-world abuse cases demonstrate attackers exploiting aliases to create up to 139 accounts from a single base email in npm for spam campaigns. Our user study further highlights security risks, showing 31.65% of participants with alias knowledge mistake phishing emails as legitimate email alias due to inconsistent provider implementations. Users who believe they understand email aliasing, especially those highly educated, male, and technical participants, are more susceptible to being phished. Our findings underscore the urgent need for standardization and transparency in email aliasing. This article contributes the OriginMail tool to help platforms resolve alias confusion and disclose vulnerabilities to affected stakeholders.

     

/

返回文章
返回