EWMA Based Threshold Algorithm for Intrusion Detection

keywords: Intrusion detection, EWMA, threshold algorithm, optimization, network traffic, autocorrelation
Intrusion detection is used to monitor and capture intrusions into computer and network systems which attempt to compromise their security. Many intrusions manifest in dramatic changes in the intensity of events occuring in computer networks. Because of the ability of exponentially weighted moving average control charts to monitor the rate of occurrences of events based on their intensity, this technique is appropriate for implementation in threshold based algorithms.
mathematics subject classification 2000: 94A13, 94C12, 68M15, 68W99, 62B15
reference: Vol. 29, 2010, No. 6+, pp. 1089–1101