Skip to main content

Frequency / Rate

Atlas home · Research path · Operational families · Anomaly models · Visual index

Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.

Unusual event frequency per entity and unit of observed time.

Telemetry contract: Authentication, API, process or DNS events, with collection completeness and event deduplication.

Candidate method [unvalidated until tested]: Measure count, duration, source diversity and target breadth. Check dispersion and seasonality before choosing a Poisson model.

Benign alternatives and limits: Retries, outages, load tests and shared gateways can resemble an attack burst.

Frequency / rate anomaly. The same synthetic API client produces 3, 2, 3, 4, 3 and 24 requests in six equal one-minute intervals. The time denominator is explicit; the example does not prescribe an alert threshold. Retries, polling and releases can create bursts; sparse attacks may not.
Figure 8. Frequency / rate anomaly. The same synthetic API client produces 3, 2, 3, 4, 3 and 24 requests in six equal one-minute intervals. The time denominator is explicit; the example does not prescribe an alert threshold.SYNTHETIC ILLUSTRATION · USER-SUPPLIEDSources: NIST SP 800-94.
Text equivalent and full-size diagram

Retries, polling and releases can create bursts; sparse attacks may not.

M1: 3; M2: 2; M3: 3; M4: 4; M5: 3; M6: 24 requests per observed minute.

Deduplicate events and verify observation time. Retries, outages and load tests can create benign bursts.

Count occurrences and state the time denominator.

Open original full-size asset

Evidence tags: Identity and access · Network telemetry. Statistical forms: collective.

Browse articles and guides: Frequency / Rate.

Reported incidents and detection interpretations

HTTP/2 Rapid Reset DDoS campaign​

Period: August 2023. Evidence: campaign reported by the cited source.

Observed [source-reported]: The HTTP/2 campaign repeatedly opened and reset streams, letting relatively few connections generate exceptional request rates. Cloudflare: HTTP/2 Rapid Reset: deconstructing the record-breaking attack.

Anomaly interpretation [inferred]: Measure stream creation and cancellation per connection and per target, not just source-IP counts. Distribution shape complements aggregate rate.

Telemetry to validate: HTTP/2-aware edge telemetry, reset counters and time-aligned request rates.

Boundary / competing explanation: Ordinary access logs may not expose frame-level resets; encrypted packet metadata alone is insufficient for this feature.

ATT&CK [author-mapped behavior, not actor attribution]: T1499 — Endpoint Denial of Service

Midnight Blizzard compromise of Microsoft​

Period: Reported January 2024. Evidence: incident reported by the cited source.

Observed [source-reported]: Microsoft described low-count password attempts against selected accounts through distributed residential proxies. Microsoft: Midnight Blizzard: Guidance for responders on nation-state attack.

Anomaly interpretation [inferred]: This is an evasion case for simple rate thresholds. Aggregate repeated targeting across sources, retaining the affected identities and observation window.

Telemetry to validate: Identity sign-in results, account IDs, source networks and provider risk signals.

Boundary / competing explanation: Do not claim that every tenant-local detector must fail or that unrelated successful logins prove compromise.

ATT&CK [author-mapped behavior, not actor attribution]: T1110.003 — Brute Force: Password Spraying

Crosslinks: Volumetric · Geographic / ASN. Statistical foundation in the Anomaly Detection Atlas. Related research: From Threat Intelligence to Detection: A Practitioner’s Guide.

Illustrative scenarios (not additional incidents):

  • A single user account generates 45 failed VPN logins in 6 minutes, far above its normal authentication rate.

  • One API client that typically makes 2–3 requests per minute suddenly sends 1,200 token validation requests in 10 minutes.

  • A workstation that usually launches a browser a few times per hour suddenly starts 300 PowerShell processes in 15 minutes.

  • A host that normally performs low-volume name resolution suddenly issues hundreds of DNS queries per minute to many rare domains.

  • A service account that usually accesses one mailbox at a time suddenly performs repeated read operations across dozens of mailboxes in a short window.

Apply this analytical view​

These are curated conceptual links, not claims that a specific model detected the cited incidents.

Models: Repeated password guessing against an account · Low-volume failures distributed across many accounts · Repeated MFA prompts and denials · Repeated probing of public services · Internal network services or systems scanned.

Collection references: User Account Authentication · Network Connection Creation · Active Directory Credential Request. These describe data components, not equivalent connectors or guaranteed fields.

Technique workspaces​

Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.