• DocumentCode
    3531384
  • Title

    Fibonacci sequence and EWMA for intrusion forecasting system

  • Author

    Pontes, Elvis ; Zucchi, Wagner L.

  • Author_Institution
    Technol. Res. Inst. of Sao, São Paulo, Brazil
  • fYear
    2010
  • fDate
    5-8 July 2010
  • Firstpage
    404
  • Lastpage
    411
  • Abstract
    Availability and reliability from information systems have been threatened by intrusions and Unwanted Internet Traffic (UIT). To protect systems from UIT, it is desirable developing techniques that detect and forecast UIT. Intending to improve intrusion detection, in our earlier work we proposed an approach to cope with UIT in a proactive manner, using forecasting techniques combined with Return on Security Investment (ROSI). In this paper we examine the applicability of a cooperative architecture regarding forecasts of UIT on a more complex set-up, with hosts associated with sites geographically divided. The aim of this paper is to detail the employment of EWMA and Fibonacci forecasting techniques covering three major gaps of current prediction techniques concerning UIT: sensors employment, the use of just one prediction technique and forecasts´ sharing. A proof of concept of such architecture is presented, which allows concluding about the improvement in forecasts for IDS to deal with UIT.
  • Keywords
    Fibonacci sequences; Internet; security of data; EWMA; Fibonacci sequence; Return on Security Investment; cooperative architecture; forecast sharing; information system availability; information system reliability; intrusion detection; intrusion forecasting system; intrusion threat; prediction technique; sensor employment; system protection; unwanted Internet traffic; Employment; Forecasting; Internet; Prototypes; Random access memory; Security; Sensors;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Digital Information Management (ICDIM), 2010 Fifth International Conference on
  • Conference_Location
    Thunder Bay, ON
  • Print_ISBN
    978-1-4244-7572-8
  • Type

    conf

  • DOI
    10.1109/ICDIM.2010.5664238
  • Filename
    5664238