Email bombing attack detection and mitigation using machine learning

Sanjeev Shukla,Manoj Misra,Gaurav Varshney
DOI: https://doi.org/10.1007/s10207-024-00871-7
2024-06-15
International Journal of Information Security
Abstract:Email bombing, a growingly prevalent and destructive cyber attack, involves inundating a target's email inbox with subscription confirmation messages from legitimate services. This type of attack, particularly challenging for conventional spam filters, is not easily detected as the emails often appear benign. In our research, we introduce an innovative real-time technique to identify and mitigate email bombing. Our method leverages a unique time gap threshold for attack detection, proving effective across various bombing types, including mass mailing and subscription bombing. Upon detecting an attack, we utilize a novel mechanism of nine features extracted from email headers to build a machine learning model. This model distinguishes between genuine and bombing emails with approximately 97% accuracy. Our study not only explores email bombing attacks but also offers a comprehensive solution, combining attack detection and a machine learning-based approach to accurately classify emails, thereby effectively mitigating such cyber threats.
computer science, information systems, theory & methods, software engineering
What problem does this paper attempt to address?