Title :
Adaptive firewall model to detect email viruses
Author_Institution :
Dept. of Informatics, Pribourg Univ., Switzerland
Abstract :
This paper presents an adaptive approach to preventing the damage caused by viruses that travel via email. The approach protects intranet machines from outside infected machines by spreading email viruses. This directly addresses the two ways that viruses cause damage: less machines spreading the virus will reduce the number of machines infected and reduce the traffic generated by the virus. We present our firewall model and address how to detect email viruses based on protocol sanity, probabilistic estimation of maliciousness, and patterns recognition.
Keywords :
authorisation; computer viruses; electronic mail; intranets; pattern recognition; probability; protocols; adaptive firewall model; email virus detection; infected machines; intranet machines; patterns recognition; probabilistic maliciousness estimation; protocol sanity; Bayesian methods; Computer viruses; Decision trees; Engines; Informatics; Pattern recognition; Postal services; Protection; Protocols; Viruses (medical);
Conference_Titel :
Security Technology, 2004. 38th Annual 2004 International Carnahan Conference on
Print_ISBN :
0-7803-8506-3
DOI :
10.1109/CCST.2004.1405392