|
ABSTRACT
Exchange of private information content among a large number of users via E-mail List Services is becoming increasingly common. In this paper we address security requirements in that setting and develop a new protocol, SELS (a Secure E-mail List Service) that provides confidentiality, integrity, and authentication for e-mails exchanged via lists. In addition, SELS also protects against the use of lists for e-mail spamming. We have developed a prototype of SELS in Java, and integrated it with the Eudora e-mail client.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
 |
1
|
|
| |
2
|
M. Abadi, A. Birrell, M. Burrows, F. Dabek, and T. Wobber, "Bankable Postage for Network Services", in Proceedings of the 8th Asian Computing Science Conference, Mumbai, India, December 2003.
|
| |
3
|
J. Allen, The CERT Guide to System and Network Security Practices, Carnegie Mellon Software Engineering Institute, Addison Wesley, Indianapolis, 2001. ISBN 0-2-1-73723-X.
|
 |
4
|
Ion Androutsopoulos , John Koutsias , Konstantinos V. Chandrinos , Constantine D. Spyropoulos, An experimental comparison of naive Bayesian and keyword-based anti-spam filtering with personal e-mail messages, Proceedings of the 23rd annual international ACM SIGIR conference on Research and development in information retrieval, p.160-167, July 24-28, 2000, Athens, Greece
[doi> 10.1145/345508.345569]
|
| |
5
|
|
| |
6
|
M. Bellare, R. Canetti, and H. Krawczyk, "Message authentication using hash functions: The HMAC construction", RSA Laboratories' CryptoBytes, Vol. 2, No. 1, Spring 1996.
|
| |
7
|
M. Blaze, G. Bleumer, and M. Strauss, "Divertible protocols and atomic proxy cryptography", in Eurocrypt'98, LNCS 1403, Springer-Verlag, 1998.
|
| |
8
|
|
| |
9
|
D. Boneh, X. Ding, G. Tsudik and B. Wong, "Fast Revocation of Security Capabilities", in Proceedings of the Usenix Security Symposium, August 2001.
|
| |
10
|
|
| |
11
|
Catalist, the official catalog of LISTSERV lists, http://www.Isoft.com/catalist.html.
|
| |
12
|
|
 |
13
|
|
| |
14
|
X. Ding and G. Tsudik, "Simple Identity-Based Cryptography with Mediated RSA", in Proceedings of the RSA Conference, Cryptographer's Track, 2003.
|
| |
15
|
|
| |
16
|
C. Dwork, A. Goldberg, and M. Naor, "On Memory-Bound Functions for Fighting Spam", in advances of Cryptology (CRYPTO 2003,) August 2003.
|
| |
17
|
|
| |
18
|
T. E. Gamal, "A Public Key Cryptosystem and a Signature Scheme Based on the Discrete Logarithm", IEEE Transactions of Information Theory, pages 31(4): 469--472, 1985.
|
| |
19
|
The GNU Privacy Guard, http://gnupg.org.
|
| |
20
|
J. loannidis, "Fighting spam by encapsulating policy in email addresses", in Proceedings of the Symposium on Network and Distributed Systems Security, 2003.
|
| |
21
|
A. Ivan and Y. Dodis, "Proxy Cryptography Revisited", in Proceedings of the Network and Distributed System Security Symposium (NDSS), February 2003.
|
 |
22
|
|
| |
23
|
J. Linn, "Privacy Enhancement for Internet Electronic Mail: Part I: Message Encryption and Authentication Procedures", IETF PEM WG RFC 21, 1993.
|
| |
24
|
LISTSERV, http://www.Isoft.com.
|
 |
25
|
|
| |
26
|
Mailman, the GNU mailing list manager. http://www.list.org.
|
| |
27
|
Majordomo, http://www.greatcircle.com/majordomo.
|
| |
28
|
M. Mambo and E. Okamoto, "Proxy Cryptosystems: Delegation of the Power to Decrypt Ciphertexts", IEICE Transactions on Fundamentals, vol. E80-A, No. 1, 1997.
|
 |
29
|
Suvo Mittra, Iolus: a framework for scalable secure multicasting, Proceedings of the ACM SIGCOMM '97 conference on Applications, technologies, architectures, and protocols for computer communication, p.277-288, September 14-18, 1997, Cannes, France
|
| |
30
|
Ostermiller Java Utilities, http://ostermiller.org/utils.
|
| |
31
|
T. Tompkins and D. Handley, "Giving e-mail back to the users: Using digital signatures to solve the spam problem", First Monday, 8(9), September 2003.
|
| |
32
|
US Department of Energy Computer Incident Advisory, January 26 2000. http://ciac.llnl.gov/ciac/bulletins/k-020.shtml.
|
| |
33
|
|
| |
34
|
|
CITED BY 4
|
|
|
|
|
Rakesh Bobba , Serban Gavrila , Virgil Gligor , Himanshu Khurana , Radostina Koleva, Administering access control in dynamic coalitions, Proceedings of the 19th conference on Large Installation System Administration Conference, p.23-23, December 04-09, 2005, San Diego, CA
|
|
|
|
|
|
Himanshu Khurana , Jim Basney , Mehedi Bakht , Mike Freemon , Von Welch , Randy Butler, Palantir: a framework for collaborative incident response and investigation, Proceedings of the 8th Symposium on Identity and Trust on the Internet, April 14-16, 2009, Gaithersburg, Maryland
|
|