An Approach for Detecting Flooding Attack Based on Integrated Entropy Measurement in E-Mail Server

The aim of this study is to protect an electronic mail (email) server system based on an integrated Entropy calculation via detecting flooding attacks. Lots of approaches have been proposed by many researchers to detect packets accessing email whether are

  • PDF / 2,015,944 Bytes
  • 12 Pages / 439.37 x 666.142 pts Page_size
  • 87 Downloads / 170 Views

DOWNLOAD

REPORT


Abstract The aim of this study is to protect an electronic mail (email) server system based on an integrated Entropy calculation via detecting flooding attacks. Lots of approaches have been proposed by many researchers to detect packets accessing email whether are belonging to the normal or abnormal packets. Entropy is an approach of the mathematical theory of Communication; it can be used to measure the uncertainty or randomness in a random variable. A normal email server usually supports the four protocols consists of Simple Mail Transfer Protocol (SMTP), Post Office Protocol version 3 (POP3), Internet Message Access Protocol version 4 (IMAP4), and HTTPS being used by remote web-based email. However, in Internet, there are many flooding attacks will try to paralyze email server system. Therefore, we propose a new approach for detecting flooding attack based on Integrated Entropy Measurement in email server. Our approach can reduce the misjudge rate compared to conventional approaches. Keywords Entropy

 Flooding attack  Email server

H.-C. Chen (&)  S.-S. Tseng  C.-H. Mao  C.-C. Lee  R. Churniawan Department of Computer Science and Information Engineering, Asia University, Taichung 41354, Taiwan, Republic of China e-mail: [email protected]; [email protected] S.-S. Tseng e-mail: [email protected] C.-H. Mao e-mail: [email protected] C.-C. Lee e-mail: [email protected] R. Churniawan e-mail: [email protected]

Y.-M. Huang et al. (eds.), Advanced Technologies, Embedded and Multimedia for Human-centric Computing, Lecture Notes in Electrical Engineering 260, DOI: 10.1007/978-94-007-7262-5_107, Ó Springer Science+Business Media Dordrecht 2014

941

942

H.-C. Chen et al.

Introduction In recent year, the rapid development of technologies helps people to communicate any information and sharing information via Internet. Email has become one of necessary communication services for Internet users. The using of Electronic Mail (email) is a method of exchanging digital messages from one person to one or more recipients, via connecting internet or computer network. There are many kind purposes of using email services, from private purposes to business purposes. Email Service Provider (ESP) is an organization which provides email server to send, receive and store emails for personal and or organization necessity. Some ESP who may provide the services to general public to personal email are Gmail, Yahoo! Mail, Hotmail and many others. Each email server is able to support many kind of protocol. In 1982, the early stage of email development, the Simple Mail Transfer Protocol (SMTP, for short) which is formulated in RFC (Request for Comments) 821 [1, 2]. SMTP is a protocol for a mail sender communicates with a mail receiver. On certain types of smaller nodes in the Internet it is often impractical to maintain a message transport system [3]. For example, a workstation may not have sufficient resources (cycles, disk space) in order to permit a SMTP server [RFC821] [3]. To solve this problem, The Post Of