A Stateful and Flow-Based Intrusion Prevention System for Email Applications

碩士 === 國立中正大學 === 電機工程所 === 95 === Recently years, an email has become more important communication for most users over Internet. As this popularity for emails, there are many email attackers who abuse emails to launch SMTP attacks and Spam mails to receivers.Although some technical countermeasures...

Full description

Bibliographic Details
Main Authors: Chih-Di Chen, 陳智迪
Other Authors: Yuan-Sun Chu
Format: Others
Language:zh-TW
Published: 2006
Online Access:http://ndltd.ncl.edu.tw/handle/34303100233263168494
id ndltd-TW-095CCU05442014
record_format oai_dc
spelling ndltd-TW-095CCU054420142015-10-13T10:45:18Z http://ndltd.ncl.edu.tw/handle/34303100233263168494 A Stateful and Flow-Based Intrusion Prevention System for Email Applications 結合全狀態與流量檢驗技術之郵件入侵防禦系統 Chih-Di Chen 陳智迪 碩士 國立中正大學 電機工程所 95 Recently years, an email has become more important communication for most users over Internet. As this popularity for emails, there are many email attackers who abuse emails to launch SMTP attacks and Spam mails to receivers.Although some technical countermeasures against SMTP attacks and Spam mails are proposed respectively, there is not an approach to prevent Spam mails as well as SMTP attack effectively. These proposed security technologies usually aim at signal threat so that it lack for an integral security technology to defend these problems. In order to prevent both Spam mails and SMTP attacks more effectively, in this thesis, we propose an integral approach which bases on the concept of PAD (Protocol Anomaly Detection) , adopting this concept implemented by finite state machine to inspect statefully whether email flows deviate from the normal behavior. We integrated the porposed approach with Snort to make it possess not only positive approach but also negative approach. Finally, we would hope the study that it can be a soulution for researchers who strong Snort more and more. Yuan-Sun Chu 朱元三 2006 學位論文 ; thesis 93 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 國立中正大學 === 電機工程所 === 95 === Recently years, an email has become more important communication for most users over Internet. As this popularity for emails, there are many email attackers who abuse emails to launch SMTP attacks and Spam mails to receivers.Although some technical countermeasures against SMTP attacks and Spam mails are proposed respectively, there is not an approach to prevent Spam mails as well as SMTP attack effectively. These proposed security technologies usually aim at signal threat so that it lack for an integral security technology to defend these problems. In order to prevent both Spam mails and SMTP attacks more effectively, in this thesis, we propose an integral approach which bases on the concept of PAD (Protocol Anomaly Detection) , adopting this concept implemented by finite state machine to inspect statefully whether email flows deviate from the normal behavior. We integrated the porposed approach with Snort to make it possess not only positive approach but also negative approach. Finally, we would hope the study that it can be a soulution for researchers who strong Snort more and more.
author2 Yuan-Sun Chu
author_facet Yuan-Sun Chu
Chih-Di Chen
陳智迪
author Chih-Di Chen
陳智迪
spellingShingle Chih-Di Chen
陳智迪
A Stateful and Flow-Based Intrusion Prevention System for Email Applications
author_sort Chih-Di Chen
title A Stateful and Flow-Based Intrusion Prevention System for Email Applications
title_short A Stateful and Flow-Based Intrusion Prevention System for Email Applications
title_full A Stateful and Flow-Based Intrusion Prevention System for Email Applications
title_fullStr A Stateful and Flow-Based Intrusion Prevention System for Email Applications
title_full_unstemmed A Stateful and Flow-Based Intrusion Prevention System for Email Applications
title_sort stateful and flow-based intrusion prevention system for email applications
publishDate 2006
url http://ndltd.ncl.edu.tw/handle/34303100233263168494
work_keys_str_mv AT chihdichen astatefulandflowbasedintrusionpreventionsystemforemailapplications
AT chénzhìdí astatefulandflowbasedintrusionpreventionsystemforemailapplications
AT chihdichen jiéhéquánzhuàngtàiyǔliúliàngjiǎnyànjìshùzhīyóujiànrùqīnfángyùxìtǒng
AT chénzhìdí jiéhéquánzhuàngtàiyǔliúliàngjiǎnyànjìshùzhīyóujiànrùqīnfángyùxìtǒng
AT chihdichen statefulandflowbasedintrusionpreventionsystemforemailapplications
AT chénzhìdí statefulandflowbasedintrusionpreventionsystemforemailapplications
_version_ 1716833280753401856