I think, a naive aproach will be to test 3 to 5 threshold values in simulation and pick the one that gives you the optimum results, such as good detection accuracy with high throughput.
This depends on the approach you use for detecting attacks. A general problem with a threshold value, is that it may be valid only for a limited period of time if the attack pattern changes, which it typically will do both over time as well as possibly in different physical locations.