A method of network surveillance includes receiving network packets
handled by a network entity and building at least one long-term and a
least one short-term statistical profile from a measure of the network
packets that monitors data transfers, errors, or network connections. A
comparison of the statistical profiles is used to determine whether the
difference between the statistical profiles indicates suspicious network
activity.