A Hybrid Wavelet-CUSUM Approach for Anomaly Detection in Denial of Service Attacks using Synthetic Network Traffic

Authors

  • Andi Muhammad Nur Hidayat Universitas Islam Negeri Alauddin Makassar
  • Antamil Universitas Islam Negeri Alauddin Makassar
  • Avilah Ramadhani Universitas Islam Negeri Alauddin Makassar

Keywords:

Denial of Service, Wavelet Transform, CUSUM, Intrusion Detection, Network Security

Abstract

Denial of Service (DoS) attacks pose a significant threat to network availability by overwhelming target systems with abnormal traffic volumes. This research proposes a hybrid detection method combining Discrete Wavelet Transform (DWT) and Cumulative Sum Control Chart (CUSUM) to detect multi-stage DoS attacks with improved sensitivity and reduced false alarm rates. Synthetic network traffic was generated using Poisson distribution to simulate normal conditions and three attack scenarios of varying intensity. The Haar wavelet decomposed the traffic signal, separating anomalous high-frequency components from normal patterns. CUSUM was then applied to the detail coefficients to detect cumulative shifts indicative of sustained attack activity. Results demonstrate that the standalone wavelet method with static thresholding achieved a detection rate of 39.64%, while CUSUM-enhanced detection reached 81.98%, representing a 106.8% improvement. The hybrid approach maintained a false alarm rate comparable to wavelet-only detection (30.63% vs 35.14%) while significantly improving sensitivity. Detection delay averaged 3 samples (44.67 seconds), enabling early attack identification suitable for real-time intrusion response systems. The proposed method offers a lightweight, training-free alternative to machine learning approaches, making it suitable for resource-constrained network environments

Downloads

Download data is not yet available.

References

[1] L. Ikhwanul Uzlah and R. Adi Saputra, "Deteksi Serangan Siber Pada Jaringan Komputer Menggunakan Metode Random Forest," J. Inform. dan Tek. Elektro Terap., vol. 12, no. 2, pp. 1–8, 2024.

[2] M. Antonakakis et al., "Understanding the Mirai Botnet," in Proc. USENIX Security Symp., 2017, pp. 1093–1110.

[3] N. Mishra, S. Pandya, C. Patel, et al., "Memcached: An experimental study of DDoS attacks for the wellbeing of IoT applications," in Proc. Int. Conf. IoT, 2023.

[4] F. Cendekiawan, B. Wicaksono, and I. M. Suartana, "Deteksi Serangan Denial of Service (DoS) pada Cloud Menggunakan SVM," SINTECH J., vol. 6, no. 1, pp. 45–54, 2023.

[5] A. Harris, A. Rahim, and S. Komputer, "Seleksi Fitur dengan Information Gain untuk Meningkatkan Deteksi Serangan DDoS," J. Teknol. Inf. dan Ilmu Komput., vol. 10, no. 3, pp. 1–10, 2023.

[6] F. Febriansyah, Z. A. Dwiyanti, D. Firdaus, and T. Informatika, "Deteksi Serangan Low Rate DDoS pada Jaringan Tradisional," J. Inform. dan Tek. Elektro Terap., vol. 12, no. 1, pp. 1–9, 2024.

[7] S. Munawarah and E. Arip Winanto, "Deteksi Serangan DDoS SYN Flood Pada Jaringan IoT Menggunakan Metode Deep Neural Network," J. Ilmu Komput. dan Sist. Inf., vol. 10, no. 2, pp. 120–128, 2023.

[8] S. M. Debbal and L. H. Ch, "Heart Sounds analysis using the Three Wavelet Transform Versions," Aditum J. Clin. Biomed. Res., vol. 3, no. 6, pp. 1–13, 2022.

[9] G. Lei, L. Ji, R. Ji, Y. Cao, W. Yang, and H. Wang, "Can Wavelet Transform Detect LDDoS Abnormal Traffic in Multipath Network?," Secur. Commun. Networks, vol. 2022, pp. 1–15, 2022.

[10] D. H. Jeong, B. K. Jeong, and S. Y. Ji, "Multi-Resolution Analysis with Visualization to Determine Network Attack Patterns," IEEE Access, vol. 10, pp. 48389–48404, 2022.

[11] B. Fachri and F. H. Harahap, "Simulasi Penggunaan Intrusion Detection System (IDS) Sebagai Keamanan Jaringan dan Komputer," J. Media Inform. Budidarma, vol. 5, no. 4, pp. 1264–1272, 2021.

[12] M. Zidane, "Klasifikasi Serangan Distributed Denial-of-Service (DDoS) menggunakan Metode Data Mining Naïve Bayes," J. Teknol. Inf. dan Ilmu Komput., vol. 10, no. 1, pp. 1–8, 2023.

[13] A. Prayogi, M. A. S. Pane, R. D. M. Siregar, R. A. Sugianto, and H. F. S. Simbolon, "Penggunaan Random Forest dan Algoritma untuk Deteksi DDoS," J. Sci. Soc. Res., vol. 6, no. 3, pp. 520–528, 2023.

[14] W. Wahyuni and P. Adytia, "Identifikasi Serangan Low-Rate DDoS Berbasis Deep Learning," Bul. Poltanesa, vol. 23, no. 2, pp. 1–8, 2022.

[15] P. V. Shalini, V. Radha, and S. G. Sanjeevi, "DDoS Attack Detection in SDN Using CUSUM," in Lect. Notes Data Eng. Commun. Technol., vol. 150, 2022, pp. 149–160.

Downloads

Published

2026-08-14

How to Cite

Nur Hidayat, A. M., Antamil , A., & Ramadhani , A. (2026). A Hybrid Wavelet-CUSUM Approach for Anomaly Detection in Denial of Service Attacks using Synthetic Network Traffic. System Information and Computer Technology (SYNCTECH), 2(2), 86–96. Retrieved from https://librarium.id/index.php/synctech/article/view/68

Issue

Section

Articles

Similar Articles

You may also start an advanced similarity search for this article.