A system for detecting network intrusions and other conditions in a network is described. The system includes a plurality of collector devices that are disposed to collect data and statistical information on packets that are sent between nodes on a network. An aggregator device is disposed to receive...http://www.google.de/patents/US20060173992?utm_source=gb-gplus-sharePatent US20060173992 - Event detection/anomaly correlation heuristics