A security system for scanning content within a computer, including a
network interface, housed within a computer, for receiving content from
the Internet on its destination to an Internet application running on the
computer, a database of rules corresponding to computer exploits, stored
within the computer, a rule-based content scanner that communicates with
said database of rules, for scanning content to recognize the presence of
potential exploits therewithin, a network traffic probe, operatively
coupled to the network interface and to the rule-based content scanner,
for selectively diverting content from its intended destination to the
rule-based content scanner, and a rule update manager that communicates
with said database of rules, for updating said database of rules
periodically to incorporate new rules that are made available. A method
and a computer readable storage medium are also described and claimed.