Skip to content

CONCEPT Cited by 1 source

Dual-threshold session anomaly

A dual-threshold session anomaly is a behavioral signal that requires both (1) an unusual change relative to the subject's own recent behavior and (2) enough absolute magnitude to be operationally material. It avoids the two common failures of one-dimensional spend or usage alerting: a global threshold misses a 10× change by a small but normally stable agent, while a personal percentage threshold pages on an inconsequential increase from a few cents.

Two distributions, two questions

Threshold Question answered Cloudflare User Insights example
Relative, per subject Is this session abnormal for this person or agent? Cost greater than 2× the account's rolling 30-day p95 session cost.
Absolute, organisation-wide Is the session large enough to warrant attention? Cost greater than the account-level p99 session-cost ceiling.

A qualifying signal lies in the intersection of both conditions. In Cloudflare's illustrative chart, the top-right quadrant alerts; a relative spike below the p99 floor and a normally expensive heavy-user session both remain outside the alert set.

Why sessions are the unit

A session retains the behavioral shape of a task. A recurring ticket-summary agent produces a tight cost and time distribution; a person working through a difficult problem has irregular timing and longer sessions. Scoring single requests would fragment both patterns and confuse normal multi-request work with anomalous behavior.

Rolling baseline and drift

The relative threshold uses a rolling window, so the p95 baseline follows durable behavioral change rather than preserving a stale one-time profile. The absolute threshold remains necessary because an adaptive personal baseline alone can still turn a trivial monetary blip into an alert. Operators should separately consider minimum-history and sudden-drift safeguards; the Cloudflare source does not disclose them.

Relationship to incidents and enforcement

A dual-threshold anomaly is a prioritization signal, not evidence of malicious intent or an automatic enforcement decision. It feeds an investigation queue, where it can be promoted to an incident only after user impact or security evidence is confirmed. This makes it complementary to anomaly versus incident separation.

Seen in

Last updated · 622 distilled / 1,953 read