Antamil Antamil
Universitas Islam Negeri Alauddin Makassar

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

A Hybrid Wavelet-CUSUM Approach for Anomaly Detection in Denial of Service Attacks Andi Muhammad Nur Hidayat; Antamil Antamil; Avilah Ramadhani
System Information and Computer Technology (SYNCTECH) Vol. 2 No. 2 (2026): July
Publisher : Subaltern Inti Media

Show Abstract | Download Original | Original Source | Check in Google Scholar

Abstract

Denial of Service (DoS) attacks pose a significant threat to network availability by overwhelming target systems with abnormal traffic volumes. This research proposes a hybrid detection method combining Discrete Wavelet Transform (DWT) and Cumulative Sum Control Chart (CUSUM) to detect multi-stage DoS attacks with improved sensitivity and reduced false alarm rates. Synthetic network traffic was generated using Poisson distribution to simulate normal conditions and three attack scenarios of varying intensity. The Haar wavelet decomposed the traffic signal, separating anomalous high-frequency components from normal patterns. CUSUM was then applied to the detail coefficients to detect cumulative shifts indicative of sustained attack activity. Results demonstrate that the standalone wavelet method with static thresholding achieved a detection rate of 39.64%, while CUSUM-enhanced detection reached 81.98%, representing a 106.8% improvement. The hybrid approach maintained a false alarm rate comparable to wavelet-only detection (30.63% vs 35.14%) while significantly improving sensitivity. Detection delay averaged 3 samples (44.67 seconds), enabling early attack identification suitable for real-time intrusion response systems. The proposed method offers a lightweight, training-free alternative to machine learning approaches, making it suitable for resource-constrained network environments