首页> 外文会议>IFIP International Conference on Network and Parallel Computing(NPC 2007); 20070918-21; Dalian(CN) >SIPS: A Stateful and Flow-Based Intrusion Prevention System for Email Applications
【24h】

SIPS: A Stateful and Flow-Based Intrusion Prevention System for Email Applications

机译:SIPS:用于电子邮件应用程序的基于状态和基于流的入侵防御系统

获取原文
获取原文并翻译 | 示例

摘要

In the fast-growing internet applications, email becomes more and more important in communication. SMTP attacks and spam have become one of the most serious problems. Particularly, the SMTP attacks and spam varies on email, for example spoofing address, illegal characters, sending in bulk, too many SMTP commands and so on. A single security technique is not enough to protect the system from these attacks and spam. In this paper, we propose a SMTP Intrusion Prevention System (SIPS) which bases on the concept of Stateful Protocol Anomaly Detection and Flow-based Inspection. SIPS is implemented by a finite state machine to inspect all coming email flows. It is according to the media type of email flow and their characteristics. On the test of a real email environment, our approach can prevent attacks on SMTP attack (mail bomb) average about 95.4% and spam average about 91.1%.
机译:在快速增长的Internet应用程序中,电子邮件在通信中变得越来越重要。 SMTP攻击和垃圾邮件已成为最严重的问题之一。特别是,SMTP攻击和垃圾邮件在电子邮件上会有所不同,例如欺骗地址,非法字符,批量发送,太多SMTP命令等等。单一的安全技术不足以保护系统免受这些攻击和垃圾邮件的侵害。在本文中,我们提出了一种基于状态协议异常检测和基于流检查的概念的SMTP入侵防御系统(SIPS)。 SIPS由有限状态机实现,以检查所有即将来临的电子邮件流。它取决于电子邮件流的媒体类型及其特征。在真实电子邮件环境的测试中,我们的方法可以防止对SMTP攻击(邮件炸弹)的攻击平均约为95.4%,垃圾邮件的平均攻击约为91.1%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号