A method, system and computer product for performing a system analysis of
a surveillance network containing a plurality of components. The method
comprises the steps of representing selected ones of the plurality of
components, providing a mapping between a plurality of observable events
and a plurality of causing events occurring in components, wherein the
observable events are at least associated with each of the at least one
components, and determining at least one likely causing event based on at
least one of the plurality of observable events by determining a measure
between each of a plurality of values associated with the plurality of
observable events and the plurality of causing events.