A New Approach for Detecting SMTPFA Based on Entropy Measurement

Abstract : In this paper, we propose a new approach of detecting a kind of Simple Mail Transfer Protocol Flooding Attack (SMTPFA for short) based on entropy measurement. We will calculate the entropy values from the received packets flow. Further checking its entropy value compared with the values of abnormal entropy, we then use it to detect this server whether is suffered some attacks from hacker. The scheme can easily detect SMTPFA, and monitor the real-time status of SMTP server.
Type de document :
Communication dans un congrès
James J. Park; Albert Zomaya; Sang-Soo Yeo; Sartaj Sahni. 9th International Conference on Network and Parallel Computing (NPC), Sep 2012, Gwangju, South Korea. Springer, Lecture Notes in Computer Science, LNCS-7513, pp.349-359, 2012, Network and Parallel Computing. 〈10.1007/978-3-642-35606-3_41〉
Liste complète des métadonnées

Littérature citée [7 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01551369
Contributeur : Hal Ifip <>
Soumis le : vendredi 30 juin 2017 - 10:36:16
Dernière modification le : vendredi 1 décembre 2017 - 01:09:55
Document(s) archivé(s) le : lundi 22 janvier 2018 - 21:56:24

Fichier

978-3-642-35606-3_41_Chapter.p...
Fichiers produits par l'(les) auteur(s)

Licence


Distributed under a Creative Commons Paternité 4.0 International License

Identifiants

Citation

Hsing-Chung Chen, Jai-Zong Sun, Shian-Shyong Tseng, Chien-Erh Weng. A New Approach for Detecting SMTPFA Based on Entropy Measurement. James J. Park; Albert Zomaya; Sang-Soo Yeo; Sartaj Sahni. 9th International Conference on Network and Parallel Computing (NPC), Sep 2012, Gwangju, South Korea. Springer, Lecture Notes in Computer Science, LNCS-7513, pp.349-359, 2012, Network and Parallel Computing. 〈10.1007/978-3-642-35606-3_41〉. 〈hal-01551369〉

Partager

Métriques

Consultations de la notice

47

Téléchargements de fichiers

13