Electronic mails (emails) have become an indispensable part of most people’s daily routines. However, they were not designed for deployment in an adversarial environment, which explains why there have been so many incidents such as spamming and phishing. Malicious impostor emails sent by sophisticated attackers are perhaps even more damaging, because their contents, except the attachments, may look perfectly legitimate while silently targeting certain critical information such as cryptographic keys and passwords. In this paper, we explore a mechanism for blocking malicious impostor emails called ContAining Malicious Emails Locally (CAMEL), which aims at blocking compromised victim user machines from further infecting others.
Erhan J. Kartaltepe, Shouhuai Xu