An Approach for Detecting a Flooding Attack Based on Entropy Measurement of Multiple E-Mail Protocols
Hsing‐Chung Chen, Chuan-Hsien Mao, Shian‐Shyong Tseng · Journal of Applied Science and Engineering · 2015
In recent years, there have been many approaches proposed by many researchers to detect RTT (round-trip time) and RTO (retransmission timeout) message traffic accessing email and trying to determine whether these belong to dangerous traffic. The aim of this study is to protect an electronic mail (email) server system based on the integrated entropy calculations of the multiple protocols of RTT and RTO in order to detect flooding attacks. Entropy is an approach in the mathematical theory of communication. It can be used to measure the uncertainty or randomness in a random variable. A normal email server usually supports four protocols consisting of simple mail transfer protocol (SMTP), post office protocol version 3 (POP3), Internet Message Access Protocol version 4 (IMAP4), and HTTPS being used by a remote web-based email. However, in the internet, there are many flooding attacks that attempt to paralyze an email server system. Therefore, we propose a new approach for detecting flooding attacks based on the integrated entropy measurements for an email server. Our approach can reduce the misjudged rate compared to conventional approaches.