FINDING · EVALUATION
The deployed system uses 7-day intervals and a baseline built from the 50 largest Tor jurisdictions; a jurisdiction's user-count ratio is flagged when it falls outside the 99.99th percentile of the fitted Normal distribution N(m,v), yielding an expected false-alarm rate of approximately 1 in 10,000 per jurisdiction-week.
From 2011-danezis-anomaly-based — An anomaly-based censorship-detection system for Tor · §5 · 2011 · The Tor Project
Implications
- Calibrate censorship early-warning detectors to a 99.99th-percentile threshold to limit noise while retaining sensitivity to major blocking events.
- Use weekly rather than daily observation windows when per-jurisdiction usage exhibits day-of-week periodicity to avoid systematic false alarms.
Tags
Extracted by claude-sonnet-4-6 — review before relying.