EWMA Algorithm in Network Practice

Petar Cisar, Saša Bošnjak, Sanja Maravic Cisar


Intrusion detection is used to monitor and capture intrusions into computer and network systems which attempt to compromise their security. Many intrusions manifest in changes in the intensity of events occuring in computer networks. Because of the ability of exponentially weighted moving average (EWMA) control charts to monitor the rate of occurrences of events based on their intensity, this technique is appropriate for implementation in control limits based algorithms. The paper also gives a review of a possible optimization method. The validation check of results will be performed on authentic network samples.


intrusion detection, EWMA, control limits, optimization, autocorrelation

DOI: https://doi.org/10.15837/ijccc.2010.2.2471

Copyright (c) 2017 Petar Cisar, Saša Bošnjak, Sanja Maravic Cisar

