Skip to main content

SecWEM: A Security Solution for Web Based E-mail

  • Conference paper
Information Systems Security (ICISS 2011)

Part of the book series: Lecture Notes in Computer Science ((LNSC,volume 7093))

Included in the following conference series:

  • 917 Accesses

Abstract

Web based e-mail (Webmail) service is a popular mode of e-mail communication and is being widely used for personal and business purposes. Security of webmails carrying sensitive commercial or corporate information is an important requirement today. A comprehensive solution is expected to cover confidentiality and integrity requirements during transit as well as authentication of the origin of webmails. Although some e-mail security solutions such as PGP, S/MIME, SMS and solution from Freenigma are currently available, most of them are tailored for handling e-mail sent or received by mail clients such as the Outlook Express or Eudora and they cannot handle webmails sent or received by browsers. The Freenigma solution handles a few specific webmail services but does not provide a generic solution. The main challenge in developing a security solution for webmails lies in building a parser to extract e-mail header details and mail body from a HTTP message, that can work with all webmail services. To address this challenge, we propose SecWEM, a desktop level end-to-end security solution. The problems involved in development and how they have been solved are presented in this paper.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. Bishop, M., Cheung, S., Wee, C.: The Threat from the Net. IEEE SPECTRUM 34, 56–63 (1997)

    Article  Google Scholar 

  2. Mathew, A.R., Al Hajj, A., Al Ruqeishi, K.: Cyber crimes: Threats and Protection. In: International Conference on Networking and Information Technology, pp. 16–18 (2010)

    Google Scholar 

  3. Foster, I., Kesselman, C.: Simple Mail Transfer Protocol (SMTP).: RFC 5321 (2008)

    Google Scholar 

  4. Myers, J., Rose, M.: Post Office Protocol Version -3 (POP3).: RFC 1939 (1996)

    Google Scholar 

  5. Crispin, M.: Internet Message Access Protocol (IMAP),version 4rev1.: RFC 3501 (2003)

    Google Scholar 

  6. Fielding, R., Gettys, J., Mogul, J., Frystylc H., Masinter, L., Leach P., Berners-Lee T.: Hypertext Transfer Protocol -HTTP/1.1. : RFC 2616 (1999)

    Google Scholar 

  7. Entrust Secure Messaging Service, http://www.entrust.com

  8. Freenigma, http://www.freenigma.com

  9. Pretty Good Privacy (PGP), http://www.pgp.com

  10. Ransdell, B., Turner, S.: Secure/Multipurpose Internet Mail Extensions (S/MIME) version 3.2.: RFC 5751 (2010)

    Google Scholar 

  11. Open PGP, http://www.openpgp.org

  12. Dierks, T., Rescorla, E.: The Transport Layer Security (TLS) Protocol Version 1.2.: RFC 5246 (2008)

    Google Scholar 

  13. Stallings, W.: Network Security Essentials: Applications and Standards. Prentice Hall (2000)

    Google Scholar 

  14. Mohsen, T.: SMEmail - A New Protocol for the Secure e-mail in Mobile Environments. In: Australian Telecommunications Networks and Applications Conference, Adelaide, Australia, pp. 39–44 (2008)

    Google Scholar 

  15. Lux, K.D., May, M.J., Bhattad, N.L., Gunter, C.A.: WSEmail: Secure Internet Messaging Based on Web Services. In: IEEE International Conference on Web Services, Orlando Florida USA, pp. 75–82 (2005)

    Google Scholar 

  16. Jang, J., Nepal, S., Zic, J.: Trusted e-mail Protocol: Dealing with Privacy Concerns from Malicious e-mail Intermediaries. In: IEEE International Conference on Computer and Information Technology, Sydney NSW, pp. 402–407 (2008)

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2011 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Yadav, R.S., Likhar, P., Rao, M.K. (2011). SecWEM: A Security Solution for Web Based E-mail. In: Jajodia, S., Mazumdar, C. (eds) Information Systems Security. ICISS 2011. Lecture Notes in Computer Science, vol 7093. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-642-25560-1_21

Download citation

  • DOI: https://doi.org/10.1007/978-3-642-25560-1_21

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-642-25559-5

  • Online ISBN: 978-3-642-25560-1

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics