A system and method are disclosed for detecting and processing attacks on a computer
network. Data indicating an attack may be taking place is received. The data is
associated with an event. The data is placed in a selected one of a plurality of
queues of data to be processed. The data in the queue is processed. Each queue
is configured to store one or more sets of data, each set of data being associated
with an event to be processed. An administrative domain may be notified that an
attack may be taking place. The destination administrative domain may or may not
be associated with other than the sending administrative domain. The source of
an attack may be identified. Messages associated with an attack may be tracked
back to identify a point of attack at which messages associated with the attack
are entering a network.