Anomaly Detection: This module also runs in background
so it will continue working. It devises a set of statistical metrics
which model the behavior of an entity, usually a user, user
groups or a host computer. The profile of a user entity for
instance, may include information such as web pages visited,
files transferred, the amount of bytes transmitted in both
directions, the chat logs made by the chat tools, the time of day
or the terminals he usually login from, etc. The profile of a host
computer may include the average CPU utilization, the total
flow passed, the number of login users, and so on. The anomaly
detection module monitors the behavior of a computer, and
constantly compares the policies made. In case it detects a
deviation from the normal behavior it makes the appropriate
measures according with the policies such as signals an alarm
to the system security officer, blocks the abnormal behavior.