Hybrid model for detecting Denial of Wallet attacks in serverless architectures
Abstract Serverless architectures enable application execution in environments where computational resources are allocated dynamically. Unlike traditional models, functions are invoked based on discrete events, offering scalability and reduced operational overhead. However, the ephemeral and distributed nature of these environments introduces significant monitoring challenges, rendering them vulnerable to exploitation. A Denial of Wallet (DoW) attack represents a specific threat in cloud-native ecosystems, where an attacker deliberately exhausts a target’s financial resources by forcing consumption beyond budget thresholds. Such attacks exploit the pay-per-use billing model, leading to substantial financial liabilities. This study introduces a hybrid detection model for DoW attacks that combines traditional statistical methods with advanced AI techniques to reduce computational costs while maintaining detection efficacy. The proposed framework operates in two sequential phases. First, time-series entropy is derived from the distribution of function invocation types and execution-duration buckets, generating a temporal sequence reflecting system behavior. Second, a supervised anomaly detection algorithm is applied to this sequence to identify deviations indicative of a DoW attack. This entropy-driven approach aims to enhance accuracy while minimizing false positives. By quantifying the randomness and predictability of serverless workloads, the model provides an effective mechanism for early threat identification, enabling proactive identification of financial risks associated with Denial of Wallet attacks in offline and batch evaluation settings. This dual-phase strategy ensures the effectiveness of previously developed methods while significantly improving computational efficiency in serverless deployments.
Authors
- Francisco José Mora Gimeno (ORCID: https://orcid.org/0000-0002-2712-3233)
- Higinio Mora (ORCID: https://orcid.org/0000-0002-8591-0710)
- José Manuel Ortega Candel (ORCID: https://orcid.org/0009-0003-9998-6120)
Institutions
- University of Alicante (ES)
Publication Details
- Journal
- Cybersecurity
- Published
- 2026-09-24
- DOI
- https://doi.org/10.1186/s42400-026-00663-7
- Primary Topic
- Software System Performance and Reliability
- Type
- article
- Field-Weighted Citation Impact
- 0.00