The internet can be quite dynamic and too complicated for a parametric estimation, so we use sequential testing which requires much less computation
Two aspects of detection:
1) False alarm time: the time without attacks between unique false alarms
2) Detection time: the detection delay after the attack starts.
The goal is to minimize the second and maximize the first. However, the conflict and require trade offs