Quote
The program can distinguish between regular server process behavior and viruses to detect an attack. "A rogue process such as a worm or virus tends to be making the same type of connection at a much more frequent pace," Redmond said. "If a process probes a particular socket on 1,000 systems a minute, what can you conclude? It's probably not a user or (a legitimate) server process."