Thus, guard device 28 counts packets of types that deviate, in terms of port, protocol, or other parameters, from the established baseline profile for any given destination address in the monitored group as suspicious events. (The same packet may be counted as an anomaly for two or more of the monitored parameters.) Typically, the guard device updates the baseline profile continually based on the