A Stateful and Flow-Based Intrusion Prevention System for Email Applications
碩士 === 國立中正大學 === 電機工程所 === 95 === Recently years, an email has become more important communication for most users over Internet. As this popularity for emails, there are many email attackers who abuse emails to launch SMTP attacks and Spam mails to receivers.Although some technical countermeasures...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2006
|
Online Access: | http://ndltd.ncl.edu.tw/handle/34303100233263168494 |
id |
ndltd-TW-095CCU05442014 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-095CCU054420142015-10-13T10:45:18Z http://ndltd.ncl.edu.tw/handle/34303100233263168494 A Stateful and Flow-Based Intrusion Prevention System for Email Applications 結合全狀態與流量檢驗技術之郵件入侵防禦系統 Chih-Di Chen 陳智迪 碩士 國立中正大學 電機工程所 95 Recently years, an email has become more important communication for most users over Internet. As this popularity for emails, there are many email attackers who abuse emails to launch SMTP attacks and Spam mails to receivers.Although some technical countermeasures against SMTP attacks and Spam mails are proposed respectively, there is not an approach to prevent Spam mails as well as SMTP attack effectively. These proposed security technologies usually aim at signal threat so that it lack for an integral security technology to defend these problems. In order to prevent both Spam mails and SMTP attacks more effectively, in this thesis, we propose an integral approach which bases on the concept of PAD (Protocol Anomaly Detection) , adopting this concept implemented by finite state machine to inspect statefully whether email flows deviate from the normal behavior. We integrated the porposed approach with Snort to make it possess not only positive approach but also negative approach. Finally, we would hope the study that it can be a soulution for researchers who strong Snort more and more. Yuan-Sun Chu 朱元三 2006 學位論文 ; thesis 93 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立中正大學 === 電機工程所 === 95 === Recently years, an email has become more important communication for most users over Internet. As this popularity for emails, there are many email attackers who abuse emails to launch SMTP attacks and Spam mails to receivers.Although some technical countermeasures against SMTP attacks and Spam mails are proposed respectively, there is not an approach to prevent Spam mails as well as SMTP attack effectively. These proposed security technologies usually aim at signal threat so that it lack for an integral security technology to defend these problems.
In order to prevent both Spam mails and SMTP attacks more effectively, in this thesis, we propose an integral approach which bases on the concept of PAD (Protocol Anomaly Detection) , adopting this concept implemented by finite state machine to inspect statefully whether email flows deviate from the normal behavior. We integrated the porposed approach with Snort to make it possess not only positive approach but also negative approach. Finally, we would hope the study that it can be a soulution for researchers who strong Snort more and more.
|
author2 |
Yuan-Sun Chu |
author_facet |
Yuan-Sun Chu Chih-Di Chen 陳智迪 |
author |
Chih-Di Chen 陳智迪 |
spellingShingle |
Chih-Di Chen 陳智迪 A Stateful and Flow-Based Intrusion Prevention System for Email Applications |
author_sort |
Chih-Di Chen |
title |
A Stateful and Flow-Based Intrusion Prevention System for Email Applications |
title_short |
A Stateful and Flow-Based Intrusion Prevention System for Email Applications |
title_full |
A Stateful and Flow-Based Intrusion Prevention System for Email Applications |
title_fullStr |
A Stateful and Flow-Based Intrusion Prevention System for Email Applications |
title_full_unstemmed |
A Stateful and Flow-Based Intrusion Prevention System for Email Applications |
title_sort |
stateful and flow-based intrusion prevention system for email applications |
publishDate |
2006 |
url |
http://ndltd.ncl.edu.tw/handle/34303100233263168494 |
work_keys_str_mv |
AT chihdichen astatefulandflowbasedintrusionpreventionsystemforemailapplications AT chénzhìdí astatefulandflowbasedintrusionpreventionsystemforemailapplications AT chihdichen jiéhéquánzhuàngtàiyǔliúliàngjiǎnyànjìshùzhīyóujiànrùqīnfángyùxìtǒng AT chénzhìdí jiéhéquánzhuàngtàiyǔliúliàngjiǎnyànjìshùzhīyóujiànrùqīnfángyùxìtǒng AT chihdichen statefulandflowbasedintrusionpreventionsystemforemailapplications AT chénzhìdí statefulandflowbasedintrusionpreventionsystemforemailapplications |
_version_ |
1716833280753401856 |