Research Article

Network Intrusion Detection with Threat Agent Profiling

Table 9

Representatives of individual clusters without outliers, -means and PAM with 7 clusters.

Cl. Nr. Perc. Scan. Durat. MaxI MinI ISP Targ.

1394590,5953482639861812
2410,9442590325932022
31042,3922494445445112671922
4882,021948544908178186618
5761,7525595354225164671025
6430,9922567254735378251722
7581,3391008609776āˆ’726

Notes. The second and third columns report the number and percentage of threat agents in a specific cluster, respectively. The last six columns correspond to the following characteristics: Recon.Scanning, duration, max. idleness, min. idleness, a number of ISP, and a number of unique targets.