Text this: How to distribute the detection load among virtual machines to maximize the detection of distributed attacks in the cloud?