In this paper, a self-learning and self-perpetuating intrusion monitoring model is proposed, which can detect known and unknown abuses and anomalies. In the proposed model, the mobile agent will collect the data collected by each activity monitoring Agent to send to the event sequence generator. The event sequence generator submits the sequence of events generated thereby to the data mining engine for evidence discovery. The detection engine detects the discovered Evidence and the similarity between the existing rules are evaluated by the decision engine to make the final ruling, and accordingly maintain the rule base and each activity monitoring Agent issued a counter directive.