摘要
研究并实现了一种基于协议分析的邮件安全监控系统,通过利用命令解码、会话重组、内容检查等协议分析技术,可以检测各种包含敏感信息的邮件以及针对邮件协议和邮件服务器的攻击。实际应用效果表明该系统部署方便、可扩展性强,具有很好的效率和准确率。
This article proposes an email security monitoring system which is based on protocol analysis technique. By using command decoding, session reassemble, content inspection and other protocol analysis methods, it can find those email sessions that include illegal information and attack data. According to application result, this system can be deployed easily and be extended greatly, and it has high-performance and high-accuracy.
出处
《计算机工程》
EI
CAS
CSCD
北大核心
2005年第1期65-67,91,共4页
Computer Engineering
基金
国家"863"高技术研究发展计划基金资助项目(2003AA144150)
关键词
协议分析
邮件安全监控
内容检查
会话重组
Protocol analysis
Email security monitoring
Content inspection
Session reassemble