Research Article

Network Intrusion Detection with Threat Agent Profiling

Table 4

Representatives of individual clusters, -means with 2 clusters.

Cl. Nr. Perc. Scan. DDoS Durat. MaxI MinI ISP Targ.

1402888,9622018137834195017
250011,044023715654085222649722

Notes. The second and third columns report the number and percentage of threat agents in a specific cluster, respectively. The last seven columns correspond to the following characteristics: Recon.Scanning, Availability.DDoS, duration, max. idleness, min. idleness, a number of ISP, and a number of unique targets.