Research Article

Network Intrusion Detection with Threat Agent Profiling

Table 6

Representatives of individual clusters, -means with 2 clusters without outliers.

Cl. Nr. Perc. Scan. Durat. MaxI MinI ISP Targ.

1394590,5953482639861812
24109,4119747950010215768716

Notes. The second and third columns report the number and percentage of threat agents in a specific cluster, respectively. The last six columns correspond to the following characteristics: Recon.Scanning, duration, max. idleness, min. idleness, a number of ISP, and a number of unique targets.