Efficient Extraction of Network Event Types from NetFlows

Statistical comparison of the new method (red) with Camnep (blue) over selected malicious classes for the number of identified events. Due to the immense difference of frequency of occurence between some of the event types, the total number of events (Camnep + new method) is normalized to 100% for every class.

