The present invention is a "floating" intrusion detection system that can
use any computer on the network as an intrusion detection platform. A
software agent program called a "socket" is installed on each computer
that is to be available to be an intrusion detection platform. A central
server contains intrusion detection software as well as a database
containing knowledge based rules and profiles for detecting intrusions.
The central server can contact any computer that has a socket installed
and direct that computer to become an intrusion detection platform. The
selected computer then downloads, installs, and runs the intrusion
detection software thus becoming an intrusion detection platform. Once
the need has passed the central server can direct some of the platforms
to stop running the software and return to their normal state.