Improving Internet Security through Empirical and Qualitative Studies of Email and DNS Ecosystem

dc.contributor.authorAshiq Khan, Mohammad Ishtiaqen
dc.contributor.committeechairChung, Taejoong Tijayen
dc.contributor.committeememberFiebig, Tobiasen
dc.contributor.committeememberJi, Boen
dc.contributor.committeememberViswanath, Bimalen
dc.contributor.committeememberYao, Danfengen
dc.contributor.departmentComputer Science and#38; Applicationsen
dc.date.accessioned2025-12-12T09:00:32Zen
dc.date.available2025-12-12T09:00:32Zen
dc.date.issued2025-12-11en
dc.description.abstractEmail and the Domain Name System (DNS) remain foundational pillars of Internet communication, yet their security mechanisms continue to suffer from subtle design limitations, operational misconfigurations, and systemic fragility. This dissertation presents an empirical, measurement-driven exploration of the global email and DNS security landscape, identifying recurring patterns of misconfiguration, evaluating the real-world efficacy of recent protocol defenses, and proposing practical tools to enhance their resilience. First, we examine email sender authentication, focusing on the large-scale deployment and operational correctness of Sender Policy Framework (SPF) and Domain-based Message Authentication, Reporting, and Conformance (DMARC). Drawing from over 12 months of longitudinal data encompassing 176 million domains, our study exposes widespread evaluation inconsistencies and misconfigurations that undermine authentication integrity and email deliverability. We further uncover novel attack vectors, including exploitable DNS amplification pathways within major email providers and open-source SPF validators, emphasizing the systemic risk of these seemingly mature defenses. Next, we turn to email transport security, analyzing the adoption and robustness of the SMTP Mail Transfer Agent Strict Transport Security (MTA-STS) protocol introduced by major providers such as Google and Microsoft. Despite its reliance on the well-established web PKI ecosystem, we find that 28% of MTA-STS enabled domains exhibit configuration flaws that nullify the intended transport-layer protections, underscoring the practical challenges of achieving secure email delivery even under modern standards. Finally, we investigate DNS security through the lens of DNSSEC deployment. Leveraging over 1M diagnostic records from DNSViz, we systematically classify the most frequent DNSSEC configuration errors, explore their persistence over time, and trace their operational root causes. To address these challenges, we introduce DFixer, an automated offline repair tool that aggregates cascaded error codes into root causes and generates both high-level remediation guidance and corresponding BIND command sequences. Experimental evaluation with a purpose-built erroneous zone replicator demonstrates that DFixer can automatically repair 99.99% of observed DNSSEC errors within seconds. Together, these studies reveal the gap between the theoretical robustness of Internet security protocols and their practical deployment realities. By combining large-scale empirical measurement, vulnerability analysis, and automated remediation, this dissertation advances our understanding of Internet infrastructure security and provides actionable paths toward more reliable, verifiable, and self-healing email and DNS ecosystems.en
dc.description.abstractgeneralEmail and the Domain Name System (DNS) are essential to how the Internet works, but the security systems that protect them often fall short in practice. Even when standards exist, real-world mistakes, outdated setups, and overlooked weaknesses can leave users and organizations exposed to attacks. This dissertation takes a data-driven look at how well these security mechanisms actually work across the Internet. By studying hundreds of millions of domains over more than a year, it reveals that many email authentication systems that are meant to prevent spoofing and scams, are set up incorrectly or behave inconsistently. These problems not only weaken security but can also cause legitimate messages to be rejected. The research also uncovers new vulnerabilities in widely used tools that show how attackers could take advantage of these weaknesses. The work then examines a newer system designed to secure email as it travels between servers. Although this technology relies on the same security foundations used by modern websites, more than a quarter of the domains that enable it configure it incorrectly, leaving the protections ineffective. Finally, the dissertation studies DNSSEC, a protocol intended to prevent attackers from tampering with DNS responses. By analyzing over a million diagnostic records, it identifies the most common configuration errors and explains why they occur. To help fix these problems, the research introduces an automated tool that can diagnose the root causes of DNSSEC errors and generate step-by-step instructions to repair them. In testing, the tool successfully fixed nearly every observed error in just seconds. Overall, this work shows that the biggest threats to Internet security often come not from the protocols themselves, but from how they are deployed in practice. By combining large-scale measurement, vulnerability analysis, and automated repair techniques, this dissertation offers practical steps toward making Internet more reliable, secure, and resilient for everyone.en
dc.description.degreeDoctor of Philosophyen
dc.format.mediumETDen
dc.identifier.othervt_gsexam:44932en
dc.identifier.urihttps://hdl.handle.net/10919/139897en
dc.language.isoenen
dc.publisherVirginia Techen
dc.rightsCreative Commons Attribution 4.0 Internationalen
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/en
dc.subjectEmail Securityen
dc.subjectEmail Sender Authenticationen
dc.subjectEmail Transport Securityen
dc.subjectNetwork Measurementen
dc.subjectVulnerability Discoveryen
dc.subjectDNS Securityen
dc.titleImproving Internet Security through Empirical and Qualitative Studies of Email and DNS Ecosystemen
dc.typeDissertationen
thesis.degree.disciplineComputer Science & Applicationsen
thesis.degree.grantorVirginia Polytechnic Institute and State Universityen
thesis.degree.leveldoctoralen
thesis.degree.nameDoctor of Philosophyen

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Ashiq_Khan_M_D_2025.pdf
Size:
2.61 MB
Format:
Adobe Portable Document Format