A method and system are disclosed for processing data from a computer network
to
determine an occurrence of and characterize a particular activity associated with
the computer network. In accordance with exemplary embodiments of the present invention,
a collection of data is managed that corresponds to events associated with the
computer network. At least one model is established to correlate an occurrence
of a predetermined set of events. At least one hypothesis is formed, using the
at least one model, that characterizes the particular activity associated with
the computer network. The at least one hypothesis is evaluated using the at least
one model. The steps of forming and evaluating are performed interactively with
the step of managing to iteratively update the collection of data.