A Hybrid Wavelet-CUSUM Approach for Anomaly Detection in Denial of Service Attacks using Synthetic Network Traffic
Keywords:
Denial of Service, Wavelet Transform, CUSUM, Intrusion Detection, Network SecurityAbstract
Denial of Service (DoS) attacks pose a significant threat to network availability by overwhelming target systems with abnormal traffic volumes. This research proposes a hybrid detection method combining Discrete Wavelet Transform (DWT) and Cumulative Sum Control Chart (CUSUM) to detect multi-stage DoS attacks with improved sensitivity and reduced false alarm rates. Synthetic network traffic was generated using Poisson distribution to simulate normal conditions and three attack scenarios of varying intensity. The Haar wavelet decomposed the traffic signal, separating anomalous high-frequency components from normal patterns. CUSUM was then applied to the detail coefficients to detect cumulative shifts indicative of sustained attack activity. Results demonstrate that the standalone wavelet method with static thresholding achieved a detection rate of 39.64%, while CUSUM-enhanced detection reached 81.98%, representing a 106.8% improvement. The hybrid approach maintained a false alarm rate comparable to wavelet-only detection (30.63% vs 35.14%) while significantly improving sensitivity. Detection delay averaged 3 samples (44.67 seconds), enabling early attack identification suitable for real-time intrusion response systems. The proposed method offers a lightweight, training-free alternative to machine learning approaches, making it suitable for resource-constrained network environments
Downloads
References
[1] L. Ikhwanul Uzlah and R. Adi Saputra, "Deteksi Serangan Siber Pada Jaringan Komputer Menggunakan Metode Random Forest," J. Inform. dan Tek. Elektro Terap., vol. 12, no. 2, pp. 1–8, 2024.
[2] M. Antonakakis et al., "Understanding the Mirai Botnet," in Proc. USENIX Security Symp., 2017, pp. 1093–1110.
[3] N. Mishra, S. Pandya, C. Patel, et al., "Memcached: An experimental study of DDoS attacks for the wellbeing of IoT applications," in Proc. Int. Conf. IoT, 2023.
[4] F. Cendekiawan, B. Wicaksono, and I. M. Suartana, "Deteksi Serangan Denial of Service (DoS) pada Cloud Menggunakan SVM," SINTECH J., vol. 6, no. 1, pp. 45–54, 2023.
[5] A. Harris, A. Rahim, and S. Komputer, "Seleksi Fitur dengan Information Gain untuk Meningkatkan Deteksi Serangan DDoS," J. Teknol. Inf. dan Ilmu Komput., vol. 10, no. 3, pp. 1–10, 2023.
[6] F. Febriansyah, Z. A. Dwiyanti, D. Firdaus, and T. Informatika, "Deteksi Serangan Low Rate DDoS pada Jaringan Tradisional," J. Inform. dan Tek. Elektro Terap., vol. 12, no. 1, pp. 1–9, 2024.
[7] S. Munawarah and E. Arip Winanto, "Deteksi Serangan DDoS SYN Flood Pada Jaringan IoT Menggunakan Metode Deep Neural Network," J. Ilmu Komput. dan Sist. Inf., vol. 10, no. 2, pp. 120–128, 2023.
[8] S. M. Debbal and L. H. Ch, "Heart Sounds analysis using the Three Wavelet Transform Versions," Aditum J. Clin. Biomed. Res., vol. 3, no. 6, pp. 1–13, 2022.
[9] G. Lei, L. Ji, R. Ji, Y. Cao, W. Yang, and H. Wang, "Can Wavelet Transform Detect LDDoS Abnormal Traffic in Multipath Network?," Secur. Commun. Networks, vol. 2022, pp. 1–15, 2022.
[10] D. H. Jeong, B. K. Jeong, and S. Y. Ji, "Multi-Resolution Analysis with Visualization to Determine Network Attack Patterns," IEEE Access, vol. 10, pp. 48389–48404, 2022.
[11] B. Fachri and F. H. Harahap, "Simulasi Penggunaan Intrusion Detection System (IDS) Sebagai Keamanan Jaringan dan Komputer," J. Media Inform. Budidarma, vol. 5, no. 4, pp. 1264–1272, 2021.
[12] M. Zidane, "Klasifikasi Serangan Distributed Denial-of-Service (DDoS) menggunakan Metode Data Mining Naïve Bayes," J. Teknol. Inf. dan Ilmu Komput., vol. 10, no. 1, pp. 1–8, 2023.
[13] A. Prayogi, M. A. S. Pane, R. D. M. Siregar, R. A. Sugianto, and H. F. S. Simbolon, "Penggunaan Random Forest dan Algoritma untuk Deteksi DDoS," J. Sci. Soc. Res., vol. 6, no. 3, pp. 520–528, 2023.
[14] W. Wahyuni and P. Adytia, "Identifikasi Serangan Low-Rate DDoS Berbasis Deep Learning," Bul. Poltanesa, vol. 23, no. 2, pp. 1–8, 2022.
[15] P. V. Shalini, V. Radha, and S. G. Sanjeevi, "DDoS Attack Detection in SDN Using CUSUM," in Lect. Notes Data Eng. Commun. Technol., vol. 150, 2022, pp. 149–160.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Andi Muhammad Nur Hidayat, Antamil , Avilah Ramadhani

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
You are free to:
- Share — copy and redistribute the material in any medium or format for any purpose, even commercially.
- Adapt — remix, transform, and build upon the material for any purpose, even commercially.
- The licensor cannot revoke these freedoms as long as you follow the license terms.
Under the following terms:
- Attribution — You must give appropriate credit , provide a link to the license, and indicate if changes were made . You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use.
- ShareAlike — If you remix, transform, or build upon the material, you must distribute your contributions under the same license as the original.
- No additional restrictions — You may not apply legal terms or technological measures that legally restrict others from doing anything the license permits.
Notices:
You do not have to comply with the license for elements of the material in the public domain or where your use is permitted by an applicable exception or limitation .
No warranties are given. The license may not give you all of the permissions necessary for your intended use. For example, other rights such as publicity, privacy, or moral rights may limit how you use the material.
