TL;DR: Fixed-rule monitoring is no longer enough for global traffic because static thresholds cannot keep pace with shifting user behaviour and low-and-slow bot activity, according to Arkose Labs. Smart Traffic Anomaly Detection learns normal traffic patterns from six weeks of history, builds 100+ hourly thresholds per country, and in one deployment found 100,000+ suspicious sessions in three weeks while cutting false positives by more than half.
Editorial analysis by NHI Mgmt Group, based on content published by Arkose Labs: “Stop Chasing False Alarms: How AI-Powered Traffic Monitoring Cuts Alert Fatigue”.
Key questions
Q: What breaks when traffic monitoring relies on fixed thresholds?
A: Fixed thresholds break when legitimate traffic changes by geography, time of day, or seasonality faster than the rule set is updated.
Q: Why do adaptive baselines reduce false positives in traffic detection?
A: Adaptive baselines reduce false positives because they compare current activity with the expected pattern for that region and time window, not with a universal limit.
Q: How do security teams know whether traffic anomaly detection is working?
A: It is working when it identifies abnormal spikes early enough for the team to intervene before customer sessions fail or origin capacity is exhausted.
Practitioner guidance
- Replace global threshold rules with regional baselines Build separate anomaly logic for countries, time zones, and business hours so legitimate local traffic is not treated as suspicious by default.
- Use historical windows long enough to capture seasonality Train detection models on sufficient prior activity to reflect weekday, weekend, and market-specific usage patterns before tuning enforcement.
- Connect anomaly detection to an enforcement decision Route suspicious sessions into challenge or blocking workflows so the monitoring layer can trigger containment instead of producing more triage work.
Bottom line: Fixed traffic thresholds fail because they cannot keep pace with local business rhythms and slow attacker behaviour.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Static thresholds are a governance problem, not just a tuning problem. Fixed rules turn traffic monitoring into a maintenance exercise that cannot keep up with changing legitimate behaviour. When business activity varies by country, hour, and day, the control starts measuring compliance with the rule, not risk in the traffic. Practitioners should treat threshold design as a living governance process, not a one-time configuration choice.
A question worth separating out:
Q: What should teams do when suspicious sessions are detected but not yet confirmed?
A: They should send those sessions into a second-stage response path, such as challenge, step-up verification, or enforcement review, before the session is allowed to continue. Anomaly detection is only useful when it leads to an operational decision instead of another dashboard indicator.
👉 Read our full editorial: AI traffic anomaly detection reduces alert fatigue without fixed thresholds