A computer
system, method, or program includes receiving flow data associated with
web traffic from one or more requesters for a website, analyzing the flow data associated with the
web traffic for the website 510, determining whether the flow data associated with the
web traffic for the website indicates a likelihood of a malicious enumeration
attack, and alerting (450, fig.4) an administrator of the website of the likelihood of the malicious enumeration
attack. Flow data can be stored in a da tabase (420, fig.4). The likelihood of enumeration
attack can be calculated based on agent name 570, number or volume of requests in a time period 540, and threshold percentage of requests matching a
word list of common web pages 560, or on a weighted combination of these factors (fig.6). Analysis may be performed at predetermined intervals 580. Preferably the
system does not perform deep packet analysis, i.e. packet inspection, when determining if there is an enumeration attack. Instead relying on
metadata such as
IP address,
MAC address, host names,
web page names, packet headers and the like. Such a
system may protect internet-of-things (IoT) devices.