Research Article

Network Intrusion Detection with Threat Agent Profiling

Table 8

Representatives of individual clusters, -means and PAM with 7 clusters.

Cl. Nr. Perc. Scan. DDoS Durat. MaxI MinI ISP Targ.

1402888.9622018137834195017
2410.91504625341471022
31753.86280582947212115893827
4871.92250595354225164671025
5741.632 01306601559022
6731.612907708494034894261029
7501.1013018039085781232659

Notes. The second and third columns report the number and percentage of threat agents in a specific cluster, respectively. The last seven columns correspond to the following characteristics: Recon.Scanning, Availability.DDoS, duration, max. idleness, min. idleness, a number of ISP, and a number of unique targets.