FINDING · DEFENSE
Per-jurisdiction user counts are modeled as a Poisson process; the detector infers the 99.99th-percentile credible interval for the underlying rate λ from the observed count via a Gamma-Poisson approximation rather than a Gaussian assumption, correctly treating small-jurisdiction zero-user days as non-anomalous.
From 2011-danezis-anomaly-based — An anomaly-based censorship-detection system for Tor · §3–§4 · 2011 · The Tor Project
Implications
- Apply Poisson/Gamma credible intervals rather than Gaussian confidence intervals when monitoring low-traffic jurisdictions to avoid spurious censorship alerts from natural count variation.
- Use jurisdiction-size-aware statistical models so high false-alarm rates in small-user regions do not crowd out real blocking events in alerting pipelines.
Tags
Extracted by claude-sonnet-4-6 — review before relying.