Research Article

Network Intrusion Detection with Threat Agent Profiling

Table 7

Representatives of individual clusters without outliers, PAM with 7 clusters.

Cl. Nr. Perc. Scan. Durat. MaxI MinI ISP Targ.

1369284,782146610011
21844,23551957666134534
3170,391845249746678312718
4872,00107473253549022
52545,832460474908308159824
6430,9922567254735378251722
7781,797574608392āˆ’1035

Notes. The second and third columns report the number and percentage of threat agents in a specific cluster, respectively. The last six columns correspond to the following characteristics: Recon.Scanning, duration, max. idleness, min. idleness, a number of ISP, and a number of unique targets.