Automatic generation method, sending method and detection method of security test mail

Through the method of automatically generating and automatically sending detection emails, the problem of low degree of automation of email gateway verification is solved, and the full-link mail status verification and stable transmission is realized, meeting the enterprise's efficient, continuous and accurate verification needs.

CN120281574AActive Publication Date: 2025-07-08BEIJING ZHIQIAN TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510748572.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-07-08
Estimated Expiration
2045-06-06

AI Technical Summary

Technical Problem

The validity verification method of existing mail gateways is low in automation, and the full link verification of email status cannot be verified. There is a lack of customized testing strategies, which is difficult to meet the enterprise's efficient, continuous and accurate verification needs.

Method used

Provides a security test email automatic generation method, generates custom emails by parsing and modifying EML files, constructs email headers and body text, adds attachments, supports DKIM signatures, and verifies the transmission and reception status of emails through automated sending and detection methods.

Benefits of technology

It improves the efficiency of email construction, supports batch generation, reduces the probability of email being intercepted or classified as spam, ensures the stable operation of the mail system in different mail service provider environments, and realizes automatic verification of the full link.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281574A_ABST
    Figure CN120281574A_ABST
Patent Text Reader

Abstract

The invention provides an automatic generation method, a sending method and a detection method of a security test mail, and belongs to the technical field of security validity verification. According to the automatic generation method for the security test mail, manual operation is reduced, an automatic system can quickly generate the mail according to the template, manual modification of an EML file is avoided, and the mail construction efficiency is improved; in addition, batch mail generation is supported, a large number of mails can be constructed at a time, and the method is suitable for large-scale mail testing or marketing activities; moreover, a flexible mail construction mode supports two modes of EML file replacement and standardized construction, and different mail security test service requirements can be met. According to the method provided by the invention, when the mail is sent anonymously, the probability that the mail is intercepted or classified as a junk mail is reduced by querying the MX record of the mail receiving server and selecting the locally adaptive SMTP server as the mail sending server, and the successful delivery rate of the mail is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security and effectiveness verification, and in particular to an automatic generation method, a sending method and a detection method for security test emails. Background Art

[0002] As the core communication security device of enterprises and organizations, the Email Gateway is responsible for the management of email sending and receiving, content filtering, anti-spam, virus scanning, and policy control. With the increase in network security threats and the continuous evolution of email transmission protocols, the security, stability, and reliability of the email gateway have become an important guarantee for enterprise IT infrastructure. However, the current method for validating the effectiveness of the email gateway mainly relies on passive monitoring or manual testing, lacking a systematic automatic verification mechanism and being difficult to meet the enterprise's requirements for efficient, continuous, and accurate verification.

[0003] Currently, the transmission of emails mainly relies on protocols such as SMTP (Simple Mail Transfer Protocol), IMAP (Internet Message Access Protocol), and POP3 (Post Office Protocol version 3). To enhance email security, common email security technologies include: TLS (Transport Layer Security) encryption: used to protect the security of SMTP, IMAP, and POP3 communications; SPF (Sender Policy Framework), DKIM (Domain Keys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting & Conformance): used to verify the identity of email senders and prevent forged email attacks.

[0004] Anti-spam technology: intercepts spam emails based on methods such as blacklists, content analysis, and Bayesian filtering.

[0005] Currently, the methods for validating the effectiveness of the email gateway mainly include: Manual testing: Operations and maintenance personnel manually construct test emails, send them to a specified email box, and manually check whether the emails are successfully delivered. This method is inefficient, difficult to promote on a large scale, and unable to continuously monitor.

[0006] Log analysis: By analyzing the logs of the mail gateway, it is determined whether the mail has been successfully delivered. However, log analysis can only reflect the processing situation of the mail and cannot verify the final status of the mail in the target mailbox.

[0007] Regular script testing: Some enterprises adopt customized scripts to simulate mail sending and receiving. However, due to the high cost of script maintenance and poor scalability, it is difficult to adapt to the configuration and rule changes of different mail gateways.

[0008] Currently, there are some mail automation testing tools on the market, such as: MailTester: Used to detect whether the configuration of the mail server is correct, but only supports single testing and cannot perform long-term monitoring.

[0009] Gmail API / Outlook API: Allows developers to automate mail sending and receiving through the API, but depends on specific mail service providers and is difficult to apply to the comprehensive verification of enterprise internal mail gateways.

[0010] Selenium + Webmail: Can simulate user login to the Web mailbox for mail sending and receiving tests, but this method has poor compatibility with different Webmail systems and is easily affected by UI changes.

[0011] Although the above methods can verify the functions of the mail gateway to a certain extent, the following problems exist in actual applications: 1. Low degree of automation: Traditional testing methods rely on manual operations or customized scripts and are difficult to meet the needs of normalization and automation.

[0012] 2. Unable to verify the entire link: Most of the existing methods focus on the mail transmission process and lack the ability to automatically verify the status of the mail in the target mailbox.

[0013] 3. Lack of customized test strategies: Enterprise users cannot flexibly define different test scenarios, such as specific attachments, different mail protocols, special character encodings, etc. Summary of the Invention

[0014] The purpose of the present invention is to overcome the above technical deficiencies and provide an automatic generation method, sending method and detection method for security test mails to solve the problem of low automation degree of test behaviors for network penetration by means of mails in related technologies.

[0015] To achieve the above technical objectives, the present invention adopts the following technical solutions: According to the first aspect of the present invention, an automatic generation method for security test mails is provided, including: Generating non-standard customized mails by parsing and modifying existing EML files; Generate a standardized EML file by initializing an email constructor, constructing an email header, generating an email body, and adding attachments.

[0016] Preferably, generating a non-standardized custom email by parsing and modifying an existing EML file includes: Read the existing EML file, parse the EML file through the email module of Python, and obtain email metadata from it: email header, body, and / or attachments; Parse the email header and modify the content of the email header to conform to a preset standard; Parse the body and modify the content of the body according to test requirements; If the parsed email metadata contains attachments, keep the attachments unchanged or replace some attachments according to test requirements; Rebuild the EML file according to the modified email header, body, and / or attachments; According to test requirements, if DKIM signature is enabled, insert the DKIM signature into the header field of the rebuilt EML file to generate the final custom email.

[0017] Preferably, parsing the email header and modifying the content of the email header to conform to a preset standard includes: Parse the email header and extract at least the following fields from it: sender address, recipient address, sending time, email subject; When the email subject contains non-ASCII characters, perform Base64 encoding conversion on it to ensure that the email header conforms to the SMTP protocol specification and avoid the email being rejected by the server or parsed abnormally due to character encoding problems; Check whether the unique identifier Message-ID in the email header is repeated. If so, modify the unique identifier Message-ID to ensure its uniqueness to avoid being recognized as a duplicate email by the server and rejected or discarded.

[0018] Preferably, parsing the body and modifying the content of the body according to test requirements includes one or more of the following methods: Replace the plain text content marked with text modification identifiers in the body according to test requirements; Replace the embedded pictures or QR codes in the body according to test requirements, and update the reference relationship between the content identifier CID and the replaced embedded pictures or QR codes.

[0019] Preferably, generating a standardized EML file by initializing an email constructor, constructing an email header, generating an email body, and adding attachments includes: Initialize the email constructor to create an empty email structure; Set the email header information: fill in the sender, recipient, and subject; Generate a unique identifier id_hash of a fixed length by hashing the Message-ID to uniquely identify the email; Insert the DKIM signature into the header field of the email header; Generate the email body in plain text format and / or HTML format according to the test requirements; Add attachments according to the test requirements and selectively encrypt the attachments; Combine the constructed email header, email body, and attachments according to the MIME protocol, calculate the byte length of the email body and / or the byte length of the attachments, and insert the calculated byte length into the corresponding field of the email header for the email recipient to verify.

[0020] According to the second aspect of the present invention, there is provided a method for automatically sending a security test email, including: Establish a communication connection with the recipient server; Execute the MAIL FROM command to set the sender address used between servers during the email transmission; execute the RCPT TO command to set the email address where the email is actually to be delivered; Execute the DATA command to send the automatically generated security test email to the recipient server; Receive the status code returned by the recipient server to determine whether the sending is successful or failed; if the email sending fails, record the reason for failure, switch to the backup SMTP server and retry; perform up to N retries, if still failed, then terminate and record the error, N≥3.

[0021] Preferably, the establishing a communication connection with the recipient server includes: Read the configuration to obtain the server address, port number, and protocol scheme of the recipient server; According to the test requirements, check whether to use the anonymous sending mode. If so, query the MX record of the recipient server and select the locally adapted SMTP server as the sender server; if not, directly use the pre-configured SMTP server as the sender server and perform identity verification through the account and password; Execute the EHLO or HELO command to start the email transmission; When it is confirmed that both sides support TLS with the recipient server through the EHLO or HELO command, upgrade the originally plaintext-transmitted SMTP connection to an encrypted channel through the STARTTLS command.

[0022] According to a third aspect of the present invention, a method for automatically detecting security test emails, applicable to a receiving server, includes: Initialize the email client: Obtain the necessary information required for the operation of the receiving server from a configuration file, user input, or environment variables, including: the address, port, account, and password of the sending server; According to the protocol type configured by the user, dynamically select the corresponding protocol implementation class and initialize an object of this class, so as to perform protocol-related operations through this object subsequently, including: connecting to the sending server and sending and receiving emails; Retrieve the metadata of emails from the sending server or local storage to form an email list, including: if the folder protocol is not supported, traverse the emails and filter them by receiving time; if the folder protocol is supported, scan the emails by folder classification; Parse the email headers of each email, extract the unique email identifier, receiving time, email storage, and log record; record the email scanning log, including successful, failed, and abnormal email information; downgrade and store the emails with parsing failures to ensure data integrity.

[0023] Preferably, the email client at least includes: The base class of the email client (MailClient), the POP3 protocol client (POPMailClient), the IMAP protocol client (IMAPMailClient), and the EWS protocol client (EWSMailClient).

[0024] According to a fourth aspect of the present invention, a method for testing vulnerabilities of an email gateway includes: The above-mentioned method for automatically generating security test emails; The above-mentioned method for automatically sending security test emails; The above-mentioned method for automatically detecting security test emails.

[0025] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects: The method for automatically generating security test emails provided by the present invention reduces manual operations: The automated system can quickly generate emails according to templates, avoiding manual modification of EML files by humans and improving the email construction efficiency; in addition, it supports batch email generation: a large number of emails can be constructed at one time, which is suitable for large-scale email testing or marketing activities; furthermore, the flexible email construction method: supports two modes of replacing EML files and standardized construction, which can meet different email security test business requirements.

[0026] This method for automatically sending security test emails provided by the present invention executes the command sequence in the standard process specified by the protocol. The retry mechanism and the logic of link reuse have more advantages for sending a large number of emails in a short period of time. When it comes to the anonymous sending rate of emails, by querying the MX record of the recipient server and selecting a locally adapted SMTP server as the sender server, the probability of emails being intercepted or classified as spam is reduced, and the successful delivery rate of emails is increased. In addition, this method for automatically sending security test emails provided by the present invention records the detailed logs of email sending, receiving, and parsing, which is convenient for problem location and optimization.

[0027] This method for automatically detecting security test emails provided by the present invention dynamically selects the corresponding protocol implementation class according to the protocol type configured by the user and initializes an object of this class, so as to perform protocol-related operations through this object subsequently, including: connecting to the sender server and sending and receiving emails, enabling the email reception to be compatible with multiple SMTP servers, and ensuring that the email system can operate stably in different email service provider (such as Gmail, Outlook, enterprise email) environments.

[0028] In summary, the present invention determines whether the mail gateway has corresponding recognition and processing behaviors through the automatic login matching of the automatic generation of security test emails in the first step, the automatic sending of security test emails in the second step, and the automatic detection of security test emails in the third step, so as to verify the security of the mail gateway. Brief Description of the Drawings

[0029] Figure 1 is a flowchart of a method for automatically generating security test emails shown according to an exemplary embodiment; Figure 2 is a flowchart of a method for automatically sending security test emails shown according to an exemplary embodiment; Figure 3 is a flowchart of a method for automatically detecting security test emails shown according to an exemplary embodiment. Detailed Description of the Embodiment

[0030] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present application.

[0031] Embodiment 1 Figure 1It is a flowchart of a method for automatically generating a security test email shown according to an exemplary embodiment. Refer to Figure 1 , the method includes: Step S11: Generate a non-standardized custom email by parsing and modifying an existing EML file; Step S12: Generate a standardized EML file by initializing an email constructor, constructing an email header, generating an email body, and adding attachments.

[0032] It should be noted that the standardized EML file mentioned in this embodiment refers to an email that complies with the MIME protocol. The MIME protocol, Multipurpose Internet Mail Extensions, is a multi-purpose Internet mail extension protocol. A non-standardized custom email refers to an email that does not strictly comply with the MIME protocol.

[0033] It can be understood that this method for automatically generating a security test email provided in this embodiment reduces manual operations: the automated system can quickly generate emails according to templates, avoiding manual modification of EML files and improving the email construction efficiency; in addition, it supports batch email generation: a large number of emails can be constructed at one time, which is suitable for large-scale email testing or marketing activities; furthermore, a flexible email construction method: it supports two modes of replacing EML files and standardized construction, which can meet different email security test business requirements.

[0034] In specific practice, generating a non-standardized custom email by parsing and modifying an existing EML file in step S11 includes: Step S111: Read the existing EML file, parse the EML file through the email module of Python, and obtain email metadata from it: email headers, body, and / or attachments.

[0035] It should be noted that the email module of Python is used to process emails, including parsing, generating, and sending emails. The EML file is usually the email format saved by an email client, containing information such as email headers, body, and attachments.

[0036] Headers (email headers): Email headers contain email metadata, such as the sender, recipient, subject, timestamp, etc. Common header fields include: From (sender address), To (recipient address), Subject (email subject), Date (sending time), Message-ID (a globally unique identifier to prevent duplicate email delivery), etc.

[0037] Body (email body): The email body is the main content of the email, which can be in plain text or HTML format.

[0038] Attachments: Attachments are additional files sent with emails, such as documents, pictures, etc.

[0039] Step S112: parsing the email header and modifying the email header content to make it conform to a preset standard, including: Parsing the email header, extracting at least the following fields: sender address, recipient address, sending time, and email subject; When the email subject contains non-ASCII characters (such as Chinese, Japanese, special symbols, etc.), it is converted to Base64 encoding to ensure that the email header complies with the SMTP protocol specification and avoid email rejection or parsing abnormality due to character encoding problems; Check whether the unique identifier Message-ID in the email header is repeated. If so, modify the unique identifier Message-ID to ensure its uniqueness to avoid being identified as a duplicate email by the server and rejected or discarded.

[0040] Step S113: parsing the text and modifying the text content according to the test requirements, including one or more of the following methods: According to the test requirements, replace the plain text content marked with a text modification mark in the body (for example, to generate a security test email with a phishing file script, put a text modification mark in the name of the email body, and pass in the name you want to replace when generating it, such as replacing Zhang San with Li Si, so that you can generate security test emails in batches); According to the test requirements, the embedded image or QR code in the text is replaced, and the reference relationship between the content identifier CID and the replaced embedded image or QR code is updated.

[0041] Step S114: If the parsed email metadata contains attachments, keep the attachments unchanged or replace some of the attachments according to the test requirements; Step S115, reconstructing the EML file according to the modified email header, body, and / or attachment; Step S116: According to the test requirements, if the DKIM signature is enabled, the DKIM signature is inserted into the header field of the reconstructed EML file to generate the final customized email.

[0042] It should be noted that during the email transmission process, Message-ID is a globally unique identifier for emails, which is used to prevent duplicate delivery, track the source of emails, and ensure compliance with email protocols. The following are typical scenarios and reasons for modifying Message-ID: (1) A unique Message-ID must be generated each time a new email is sent When automated tools send test emails (such as verification code emails, marketing emails) in batches, each email must have a unique Message-ID.

[0043] If the same Message-ID is reused, mail servers (such as Gmail, Outlook) will recognize it as a duplicate email and directly reject or discard it. This is to prevent email clients (such as Outlook, Foxmail) from having abnormal email displays (such as duplicate counting, sorting chaos) due to ID conflicts.

[0044] (2) The Message-ID needs to be updated after the email content or metadata is changed. After modifying keywords such as the email body, attachments, sender address (From), recipient address (To), etc.

[0045] The Message-ID is usually generated based on the hash value of the email content. Content changes will cause the hash value to change, and the ID needs to be updated. If the old ID is forcibly retained, it may cause the mail server to reject the email due to inconsistent content.

[0046] The full name of CID: Content-ID, is an identifier used to uniquely identify embedded resources in the email MIME protocol. In an email, CID association is a mechanism used to identify and reference embedded resources (such as pictures, QR codes, etc.). When the email content contains embedded pictures or QR codes, the CID is required to ensure the correct loading of the resources, otherwise the pictures may not be displayed.

[0047] DKIM (DomainKeys Identified Mail) is an email verification technology used for: Verifying the sender's identity: Confirming that the email actually comes from the claimed domain.

[0048] Preventing email tampering: Detecting whether the email has been modified during transmission.

[0049] Enhancing the credibility of emails: Reducing the risk of spam / phishing emails.

[0050] In specific practices, in step S12, a standardized EML file is generated by initializing the email constructor, constructing the email header, generating the email body, and adding attachments, including: Step S121, initializing the email constructor to create an empty email structure; Step S122, setting the email header information: filling in the sender, recipient, and subject to ensure that the format complies with the RFC 5322 standard; Step S123: Generate a unique identifier id_hash of a fixed length by performing a hash calculation on the Message-ID to uniquely identify the email. Step S124: Insert a DKIM signature into the header field of the email header. Step S125: Generate a plain text email body and / or an HTML email body according to the test requirements, including: if the email body enables the QR code function, generate a QR code image and insert it into the HTML content; if the email body includes images or hyperlinks, ensure that the content identifier CID is correctly matched. Step S126: Add attachments according to the test requirements and selectively encrypt the attachments. Step S127: Combine the constructed email header, email body, and attachments according to the MIME protocol, calculate the byte length of the email body and / or the byte length of the attachments, and insert the calculated byte length into the corresponding field of the email header for verification by the email recipient.

[0051] It should be noted that an email constructor is a tool or code module used to create emails that conform to the standard format. Its core function is to assemble email content (such as the body, attachments, recipient information, etc.) according to protocol specifications (such as SMTP, MIME), and finally generate a directly sendable email data packet. The email constructor is the core component of the email system and is responsible for converting the user's intention into email data that conforms to the protocol. Whether it is a simple text email or a complex rich media marketing email, a standardized data packet needs to be generated through the email constructor.

[0052] The workflow of the email constructor includes: Initialize the email object: Create an empty email structure.

[0053] Set the email header: Populate information such as the sender, recipient, and subject.

[0054] Construct the body: Add plain text or HTML content. If there are attachments or multi-part content, use the multipart structure to combine them.

[0055] Encoding processing: Encode non-ASCII characters (such as UTF-8 with quoted-printable).

[0056] Perform Base64 or binary encoding on the attachments.

[0057] Generate email data: Serialize the email object into a string or byte stream that conforms to the SMTP / MIME protocol.

[0058] It can be understood that the automatic security test email generation method provided in this embodiment supports the automatic generation of email bodies in plain text or HTML format, supports image embedding and QR code generation, making the email content richer; allows manual setting of email headers and can flexibly control the field information of the email; by performing a hash calculation on the Message-ID, a unique identifier id_hash with a fixed length is generated to uniquely identify the email, prevent duplicate delivery, and at the same time track the email transfer process; by inserting a DKIM signature into the header field of the email header, the email is prevented from being tampered with, improving the credibility of the email and reducing the probability that the automatically generated security test email is classified as spam by the recipient server. In addition, the technical solution provided in this embodiment supports attachment encryption and integrity verification: ensuring the security of sensitive information and preventing malicious tampering or interception.

[0059] Embodiment 2 Figure 2 is a flowchart of an automatic security test email sending method shown according to an exemplary embodiment. Refer to Figure 2 , the method includes: Step S21, establish a communication connection with the recipient server; Step S22, execute the MAIL FROM command to set the sender address used between servers during the email transmission process; execute the RCPT TO command to set the email address where the email is actually to be delivered; Step S23, execute the DATA command to send the automatically generated security test email to the recipient server; Step S24, receive the status code returned by the recipient server to determine whether the sending is successful or failed; if the email sending fails, record the reason for failure, switch to the backup SMTP server and retry; perform up to N retries. If it still fails, terminate and record the error, where N≥3.

[0060] It should be noted that the technical solution provided in this embodiment is applied to the sender server.

[0061] The MAIL FROM command, RCPT TO command, and DATA command all belong to SMTP commands.

[0062] 1. MAIL FROM command: Specify the envelope sender of the email, that is, the sender address used between servers during the email transmission process.

[0063] 2. RCPT TO command: Specify the envelope recipient of the email, that is, the email address where the email is actually to be delivered.

[0064] 3. DATA Command: Start transmitting the actual content of the email (including the email header and body). The server enters the data reception mode and waits for the client to send the complete email content. The email content must conform to the MIME protocol format and include headers (such as Subject, From, To) and the body (which may include attachments).

[0065] In specific practice, establishing a communication connection with the recipient server in step S21 includes: Read the configuration to obtain the server address, port number, and protocol scheme of the recipient server; According to the test requirements, check whether to use the anonymous sending mode. If so, query the MX record of the recipient server and select a locally adapted SMTP server as the sender server; if not, directly use the pre-configured SMTP server as the sender server and perform authentication through the account and password. Execute the EHLO or HELO command to start the email transmission; When it is confirmed through the EHLO or HELO command that both the local and recipient servers support TLS, upgrade the originally plaintext SMTP connection to an encrypted channel through the STARTTLS command.

[0066] It should be noted that the MX record (Mail eXchanger Record) is a type of resource record in the DNS (Domain Name System) used to specify the email server address responsible for receiving emails for a certain domain name. When someone sends an email to a certain domain name, the sender's email server will query the MX record of that domain name to determine which email server the email should be routed to.

[0067] Characteristics of the email anonymous sending mode: The sender hides their true identity (such as forging the From address, not using the real IP or SPF / DKIM signature). In this case, the receiving server will check whether the sender's domain name has a valid MX record: If there is an MX record: The email may be marked as legitimate (but further verification of SPF / DKIM is required).

[0068] If there is no MX record: The email may be directly rejected or marked as suspicious (for example, the sender claims to be from example.com, but that domain name has no MX record).

[0069] That is: When sending a normal email, the role of the MX record is to ensure that the email is routed to the correct recipient server (such as mail.example.com). When sending an anonymous email, the role of the MX record is to help the recipient verify the legitimacy of the sender's domain name and reduce the risk of spam.

[0070] EHLO and HELO are commands used to initiate a mail transfer session in SMTP (Simple Mail Transfer Protocol). Their core function is to announce the client's identity to the mail server and negotiate transfer capabilities. HELO is the basic command of the SMTP protocol, used by the client to identify itself to the server (usually the IP or domain name of the sender's domain) and initiate the mail transfer process. EHLO is an enhanced version of HELO, used to request the server to provide support for more extended functions (such as STARTTLS, DKIM, etc.).

[0071] The automatic security test mail sending method provided in this embodiment also has error handling and log management functions, including: Recording errors that occur during the sending process; Handling SMTP exceptions (such as rejecting the sender, recipient rejecting the letter, data errors, etc.); Recording detailed logs of successful or failed mail sending.

[0072] It can be understood that in the case of the anonymous mail sending rate of the automatic security test mail sending method provided in this embodiment, by querying the MX record of the recipient server and selecting a locally adapted SMTP server as the sender server, the probability of the mail being intercepted or classified as spam is reduced, and the successful delivery rate of the mail is increased. In addition, the automatic security test mail sending method provided in this embodiment records detailed logs of mail sending, receiving, and parsing, which is convenient for problem location and optimization.

[0073] Embodiment Three Figure 3 is a flowchart of an automatic security test mail detection method shown according to an exemplary embodiment. Refer to Figure 3 , and this method includes: Step S31, Initialize the mail client: Obtain the necessary information required for the recipient server to run from the configuration file, user input, or environment variables, including: the sender server address, port, account, password (these parameters define how the mail client establishes a connection with the sender server, authenticates its identity, and performs operations such as sending and receiving mails); Step S32, Dynamically select the corresponding protocol implementation class according to the protocol type configured by the user (such as IMAP, POP3, SMTP), and initialize an object of this class, so as to perform protocol-related operations through this object later, including: connecting to the sender server and sending and receiving mails; Step S33: Retrieve the metadata of emails from the sender server or local storage to form an email list, including: if the folder protocol is not supported (the folder protocol usually refers to the protocol that supports folder management on the email server side. For example, IMAP allows users to store, manage, and retrieve emails by folder. In contrast, the "protocol that does not support folders" (such as POP3) can only filter emails by reception time and cannot classify emails by folder), traverse the emails and filter them by reception time; if the folder protocol is supported, scan the emails by folder classification; Step S34: Parse the email headers of each email to extract the unique email identifier, reception time, email storage, and log record; record the email scanning log, including successful, failed, and abnormal email information; store the emails with parsing failures in a degraded manner to ensure data integrity (in an email processing system, storing emails with parsing failures in a degraded manner is a fault tolerance mechanism. Its core purpose is to maximize the retention of data during parsing exceptions, avoid information loss, and provide the possibility for subsequent repair or manual intervention).

[0074] It should be noted that the technical solution provided in this embodiment is applied to the recipient server. The email client is loaded and runs on the recipient server.

[0075] Preferably, the email client at least includes: MailClient (the base class of the email client), POPMailClient (the POP3 protocol client), IMAPMailClient (the IMAP protocol client), and EWSMailClient (the EWS protocol client).

[0076] It should be noted that: 1. MailClient (the base class of the email client) supports the following functions: Unify the management of email connection configurations, such as server address, port, user credentials, etc.; Provide a logging function, support multiple loggers, and set the log timeout; Parse the email header information to obtain the email reception time, and support the check of the unique email identifier; Maintain the email server connection and provide a server refresh mechanism.

[0077] 2. POPMailClient (the POP3 protocol client) supports the following functions: Implement email retrieval based on the POP3 protocol; Support sorting emails by reception time and filtering out emails within a specific time range; Adopt a mechanism of multiple attempts to connect to improve the stability of the server connection; Parse the email header information to obtain the email subject, receiving time, etc.; Implement email traversal through the scan_inbox method, and support resuming scanning from the breakpoint.

[0078] 3. IMAP protocol client (IMAPMailClient), supporting the following functions: Obtain the email list based on the IMAP protocol, and support multi-folder scanning; Parse the email header information to obtain the email unique identifier and time; Use regular expressions to match the folder information returned by the IMAP server; Traverse emails through the scan_folder method, and support retrying to obtain abnormal emails.

[0079] 4. EWS protocol client (EWSMailClient), supporting the following functions: Obtain the email list based on the EWS protocol, and support multi-folder scanning; Parse the email header information to obtain the email unique identifier and time; Use regular expressions to match the folder information returned by the Exchange server; Traverse emails through the scan_folder method, and support retrying to obtain abnormal emails.

[0080] This automatic security test email detection method provided in this embodiment also has an intelligent log management function: adopt multiple loggers, and support the log timeout cleaning mechanism; Record key events during the email scanning process, such as server connection failure, email parsing error, etc.; provide the add_logger method to support dynamically adding loggers; This automatic security test email detection method provided in this embodiment also has an email exception handling function: Adopt an exception capture mechanism to handle exceptions during the email acquisition and parsing process; When the server connection fails, automatically attempt to reconnect, and support the maximum number of retries; For emails that fail to be parsed, provide a fallback processing solution, such as storing the original email data for subsequent analysis.

[0081] It can be understood that for the automatic detection method of security test emails provided in this embodiment, according to the protocol type configured by the user, the corresponding protocol implementation class is dynamically selected, and an object of this class is initialized, so as to perform protocol-related operations through this object subsequently, including: connecting to the sender server, sending and receiving emails, enabling the email reception to be compatible with multiple SMTP servers, and ensuring that the email system can operate stably in different email service provider (such as Gmail, Outlook, enterprise email) environments.

[0082] Embodiment 4 A method for testing vulnerabilities of an email gateway shown according to an exemplary embodiment includes: The above-mentioned automatic generation method of security test emails; The above-mentioned automatic sending method of security test emails; The above-mentioned automatic detection method of security test emails.

[0083] It can be understood that for the automatic generation method of security test emails in this embodiment, manual operations are reduced: the automated system can quickly generate emails according to templates, avoiding manual modification of EML files and improving the email construction efficiency; in addition, batch email generation is supported: a large number of emails can be constructed at one time, which is suitable for large-scale email tests or marketing activities; furthermore, flexible email construction methods: support two modes of replacing EML files and standardized construction, which can meet different email security test business requirements.

[0084] For the automatic sending method of security test emails in this embodiment, when the email anonymous sending rate is concerned, by querying the MX record of the recipient server and selecting a locally adapted SMTP server as the sender server, the probability of the email being intercepted or classified as spam is reduced, and the email successful delivery rate is improved. In addition, for the automatic sending method of security test emails in this embodiment, detailed logs of email sending, receiving, and parsing are recorded, which is convenient for problem location and optimization.

[0085] For the automatic detection method of security test emails in this embodiment, according to the protocol type configured by the user, the corresponding protocol implementation class is dynamically selected, and an object of this class is initialized, so as to perform protocol-related operations through this object subsequently, including: connecting to the sender server, sending and receiving emails, enabling the email reception to be compatible with multiple SMTP servers, and ensuring that the email system can operate stably in different email service provider (such as Gmail, Outlook, enterprise email) environments.

[0086] The above-mentioned serial numbers of the embodiments of this application are only for description and do not represent the advantages or disadvantages of the embodiments.

[0087] If the integrated units in the above embodiments are implemented in the form of software functional units and sold or used as independent products, they can be stored in the above computer-readable storage media. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing one or more computer devices (which can be personal computers, servers, or network devices, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application.

[0088] In the above embodiments of this application, the descriptions of the various embodiments have their own emphases. For the parts not elaborated in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0089] In the several embodiments provided by this application, it should be understood that the disclosed client can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the units or modules can be in electrical or other forms.

[0090] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0091] In addition, the functional units in the various embodiments of this application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0092] The above is only the preferred embodiment of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can still be made, and these improvements and refinements should also be regarded as the protection scope of this application.

Claims

1. A method for automatically generating security test emails, characterized in that, Including: Generating a non-standard custom email by parsing and modifying an existing EML file; Generating a standardized EML file by initializing an email constructor, constructing an email header, generating an email body, and adding attachments.

2. The method according to claim 1, wherein The generating a non-standard custom email by parsing and modifying an existing EML file includes: Reading an existing EML file, parsing the EML file through the email module of Python, and obtaining email metadata therefrom: email header, body, and / or attachments; Parsing the email header and modifying the content of the email header to conform to a preset standard; Parsing the body and modifying the body content according to test requirements; If the parsed email metadata includes attachments, keeping the attachments unchanged or replacing some of the attachments according to test requirements; Reconstructing an EML file based on the modified email header, body, and / or attachments; According to test requirements, if DKIM signature is enabled, inserting the DKIM signature into the header field of the reconstructed EML file to generate the final custom email.

3. The method according to claim 2, wherein The parsing the email header and modifying the content of the email header to conform to a preset standard includes: Parsing the email header and extracting at least the following fields therefrom: sender address, recipient address, sending time, email subject; When the email subject contains non-ASCII characters, performing Base64 encoding conversion on it to ensure that the email header conforms to the SMTP protocol specification and avoid the email being rejected or abnormally parsed by the server due to character encoding problems; Checking whether the unique identifier Message-ID in the email header is repeated. If so, modifying the unique identifier Message-ID to ensure its uniqueness to avoid being recognized as a duplicate email by the server and being rejected or discarded.

4. The method according to claim 2, wherein The parsing the body and modifying the body content according to test requirements includes one or more of the following methods: Replacing the plain text content marked with text modification identifiers in the body according to test requirements; Replacing the embedded images or QR codes in the body according to test requirements and updating the reference relationship between the content identifier CID and the replaced embedded images or QR codes.

5. The method according to claim 1, characterized in that, The generating a standardized EML file by initializing an email constructor, constructing an email header, generating an email body, and adding attachments includes: Initializing an email constructor to create an empty email structure; Setting email header information: filling in the sender, recipient, and subject; Generating a unique identifier id_hash with a fixed length by performing a hash calculation on Message-ID to uniquely identify the email; Inserting the DKIM signature into the header field of the email header; Generating a plain text format email body and / or an HTML format email body according to test requirements; Adding attachments according to test requirements and selectively encrypting the attachments; Combining the constructed email header, email body, and attachments according to the MIME protocol, calculating the byte length of the email body and / or the byte length of the attachments, and inserting the calculated byte length into the corresponding field of the email header for verification by the email recipient.

6. A method for automatically sending security test emails, applicable to a sender server, characterized in that, Including: Establish a communication connection with the recipient server; Execute the MAIL FROM command to set the sender address used between servers during email transmission; Execute the RCPT TO command to set the email address where the email is actually to be delivered; Execute the DATA command to send an automatically generated security test email to the recipient server; Receive the status code returned by the recipient server to determine whether the sending is successful or failed; if the email sending fails, record the reason for failure, switch to the backup SMTP server and retry; perform up to N retries, if still failed, then terminate and record the error, N≥3.

7. The method according to claim 6, wherein The establishment of the communication connection with the recipient server includes: Read the configuration to obtain the server address, port number, and protocol scheme of the recipient server; According to the test requirements, check whether to use the anonymous sending mode. If so, query the MX record of the recipient server and select the locally adapted SMTP server as the sender server; if not, directly use the pre-configured SMTP server as the sender server and perform authentication through the account and password; Execute the EHLO or HELO command to start email transmission; When it is confirmed through the EHLO or HELO command that both the local and recipient servers support TLS, upgrade the originally plaintext SMTP connection to an encrypted channel through the STARTTLS command.

8. A method for automatically detecting security test emails, applicable to the receiving server, characterized in that Include: Initialize the email client: Obtain the necessary information required for the operation of the recipient server from the configuration file, user input, or environment variables, including: sender server address, port, account, password; Dynamically select the corresponding protocol implementation class according to the protocol type configured by the user, and initialize an object of this class for subsequent execution of protocol-related operations through this object, including: connecting to the sender server, sending and receiving emails; Retrieve the metadata of emails from the sender server or local storage to form an email list, including: if the folder protocol is not supported, traverse the emails and filter by the receiving time; if the folder protocol is supported, scan the emails by folder classification; Parse the email headers of each email to extract the unique email identifier, receiving time, email storage, and log record; record the email scanning log, including successful, failed, and abnormal email information; store the emails with parsing failures in a degraded manner to ensure data integrity.

9. The method according to claim 8, wherein The email client at least includes: Email client base class, POP3 protocol client, IMAP protocol client, EWS protocol client.

10. A method for testing vulnerabilities of an email gateway, characterized in that, Include: The method for automatically generating a security test email according to any one of claims 1-5; The method for automatically sending a security test email according to any one of claims 6-7; The method for automatically detecting a security test email according to any one of claims 8-9.

Citation Information

Patent Citations

  • Method and system for monitoring automatic transmission of mails, computer device and storage medium

    CN109245988A

  • Method and equipment for analyzing mail with missing content

    CN119597941A

  • Mail sending method, mail control method, sending end, and receiving end

    WO2018113707A1