A robust approach for on-line and off-line threat detection based on event tree similarity analysis