This document describes how to create a message filter that compares the SMTP authenticated username to the header From: address.
Cisco recommends that you have knowledge of Cisco AsyncOS for Email version 15.0 and later.
The SMTP authentication function allows customers to use SMTP authentication for their email clients to connect to and send mail through the Cisco Email Security Appliance (ESA). Because the feature allows an authenticated session to relay outbound mail, a client can spoof the header From: address. To help prevent spoofing, Cisco AsyncOS for Email version 6.5 and later includes a message filter condition that compares the authenticated SMTP username to the header From: address and logs the username in an X-header.
The message filter condition allows an administrator to write a filter (for example, the rule in the next section) that compares messages relayed outbound during an SMTP authenticated session. If SMTP credentials are compromised, the sending client often generates multiple header From: addresses. This condition allows messages to be delivered only when the authenticated username matches the header From: address; otherwise, the message is treated as a spoofed header From: and the configured message filter action is applied. The message filter action can be any final action; the example rule uses a quarantine action. The filter condition has this syntax:
smtp-auth-id-matches("<target>" [, "<sieve-char>"])
The optional sieve-char parameter specifies a delimiter character (for example, +) used to ignore the portion of the comparison address after that character. This is commonly used for plus-addressing, as shown in the table.
The filter permits a comparison against one of these targets:
| SMTP AUTH ID | SIEVE CHAR | COMPARISON ADDRESS | MATCHES? |
|---|---|---|---|
| someuser | otheruser@example.com | No | |
| someuser | someuser@example.com | Yes | |
| someuser | someuser@face.localhost | Yes | |
| SomeUser | someuser@example.com | Yes | |
| someuser | someuser+folder@example.com | No | |
| someuser | + | someuser+folder@example.com | Yes |
| someUser@example.com | someuser@forged.com | No | |
| someUser@example.com | someuser@example.com | Yes | |
| someUser@example.com | someuser@example.com | Yes |
This variable substitution, $SMTPAuthID, allows inclusion of the authenticated username in message headers for messages relayed during an authenticated SMTP session.
Msg_Authentication: if (smtp-auth-id-matches("*Any"))
{
# Always include the original authentication credentials in a
# special header.
insert-header("X-SMTPAUTH", "$SMTPAuthID");
if (smtp-auth-id-matches("*FromAddress", "+") and
smtp-auth-id-matches("*EnvelopeFrom", "+"))
{
# Username matches. Verify the domain.
if (header('from') != "(?i)@example\.com" or mail-from != "(?i)@example\.com")
{
# User has specified a domain which cannot be authenticated.
quarantine("forged");
}
}
else
{
# User claims to be a completely different user.
quarantine("forged");
}
}
| Revision | Publish Date | Comments |
|---|---|---|
1.0 |
11-Jun-2014
|
Initial Release |