Received 13.02.2026, Revised 29.05.2026, Accepted 25.06.2026 Published 03.08.2026

Software implementation of a network traffic monitoring system based on cluster analysis

Samira Budzhelida*, Valeriy Dubrovin , Larysa Deineha

budzhelida.samira@gmail.com



The growth in the volume and heterogeneity of network traffic complicates the timely detection of attacks, whereas signature-based approaches do not cover new or modified threats. Interpretable and reproducible methods for analysing data flows are needed, and they must be suitable for integration into monitoring systems. The purpose of the study was to develop and implement a monitoring system that separates normal connections from anomalous ones without prior data labelling and provides transparent decision-making criteria. The research methodology was based on the standardisation of network traffic features and the use of the unsupervised k-means clustering algorithm, followed by anomaly detection through deviations from centroids. On a synthetic set of events with a small proportion of violations, the system consistently formed two compact clusters corresponding to typical and atypical behaviour. The centroid of normal traffic was characterised by lower values for the volumes of transmitted and received data and lower connection activity; the centroid of anomalous traffic had substantially higher values across all features. The combined post-clustering rule reduced false positives that arise during legitimate large transfers, for example, backups, while maintaining a high proportion of correctly detected rare events. Comparative experiments demonstrated comparable or higher precision and recall than classical outlier detection approaches, along with a stable millisecond-level processing time for one thousand records. The sensitivity analysis confirmed robustness to the choice of distance threshold and preprocessing parameters. The experimental sample contained 1,000 records, of which 980 corresponded to normal network traffic and 20 corresponded to anomalous events (2%). Clustering formed two clusters, with the smaller cluster grouping 20 records that corresponded to atypical network behaviour. The proposed approach does not require reference labels, scales easily, provides transparent explanations through centroids and distances, is suitable for batch and stream processing, and can serve as a basic component in production anomaly detection pipelines

anomalous connection detection; feature standardisation; centroid models; thresholding by distance to centroid; silhouette coefficient; comparison with outlier detection methods; stream data processing
24-34
Budzhelida, S., Dubrovin , V., & Deineha , L. (2026). Software implementation of a network traffic monitoring system based on cluster analysis. Information Technologies and Computer Engineering, 23(2), 24-34. https://doi.org/10.31649/vitce/2.2026.24

References

  1. Ahmad, Z., Khan, A.S., Shiang, C.W., Abdullah, J., & Ahmad, F. (2020). Network intrusion detection system: A systematic study of machine learning and deep learning approaches. Transactions on Emerging Telecommunications Technologies, 32, article number e4150. doi: 10.1002/ett.4150.
  2. Chalapathy, R., & Chawla, S. (2019). Deep learning for anomaly detection: A survey. arXiv. doi: 10.48550/arxiv.1901.03407.
  3. Chandola, V., Banerjee, A., & Kumar, V. (2009). Anomaly detection. ACM Computing Surveys, 41(3), 1-58. doi: 10.1145/1541880.1541882.
  4. Chen, J., Zhang, C., Cai, S., Zhang, Z., Liu, L., & Huang, L. (2022). Malware recognition approach based on self‐similarity and an improved clustering algorithm. IET Software, 16(5), 527-541. doi: 10.1049/sfw2.12067.
  5. Dasgupta, D., Akhtar, Z., & Sen, S. (2020). Machine learning in cybersecurity: A comprehensive survey. The Journal of Defense Modeling and Simulation Applications Methodology Technology, 19(1), 57-106. doi: 10.1177/1548512920951275.
  6. Ferrag, M.A., Maglaras, L., Moschoyiannis, S., & Janicke, H. (2019). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications, 50, article number 102419. doi: 10.1016/j.jisa.2019.102419.
  7. Hodge, V., & Austin, J. (2004). A survey of outlier detection methodologies. Artificial Intelligence Review, 22, 85-126. doi: 10.1023/b:aire.0000045502.10941.a9.
  8. Jafarian, T., Masdari, M., Ghaffari, A., & Majidzadeh, K. (2020a). A survey and classification of the security anomaly detection mechanisms in software defined networks. Cluster Computing, 24(2), 1235-1253. doi: 10.1007/s10586-020-03184-1.
  9. Jafarian, T., Masdari, M., Ghaffari, A., & Majidzadeh, K. (2020b). Security anomaly detection in software‐defined networking based on a prediction technique. International Journal of Communication Systems, 33, article number e4524. doi: 10.1002/dac.4524.
  10. MacQueen, J. (1967). Some methods for classification and analysis of multivariate observations. In Proceedings of the fifth Berkeley symposium on mathematical statistics and probability (Vol. 1; pp. 281-297). California: The Regents of the University of California.
  11. Miraftabzadeh, S.M., Colombo, C.G., Longo, M., & Foiadelli, F. (2023). K-Means and alternative clustering methods in modern power systems. IEEE Access, 11, 119596-119633. doi: 10.1109/access.2023.3327640.
  12. Molina-Coronado, B., Mori, U., Mendiburu, A., & Miguel-Alonso, J. (2020). Survey of network intrusion detection methods from the perspective of the knowledge discovery in databases process. IEEE Transactions on Network and Service Management, 17(4), 2451-2479. doi: 10.1109/tnsm.2020.3016246.
  13. Münz, G., Li, S., & Carle, G. (2007). Traffic anomaly detection using k-means clustering. In Proceedings of the GI/ITG workshop MMBnet (pp. 116-123). Hamburg: Gesellschaft für Informatik, Informationstechnische Gesellschaft.
  14. Nafea, A.A., Alameri, S.A., Majeed, R.R., Khalaf, M.A., & Al-Ani, M.M. (2024). A short review on supervised machine learning and deep learning techniques in computer vision. Babylonian Journal of Machine Learning, 2024, 48-55. doi: 10.58496/bjml/2024/004.
  15. Nassif, A.B., Talib, M.A., Nasir, Q., & Dakalbab, F.M. (2021). Machine learning for anomaly detection: A systematic review. IEEE Access, 9, 78658-78700. doi: 10.1109/access.2021.3083060.
  16. Sarker, I.H. (2021). CyberLearning: Effectiveness analysis of machine learning security modeling to detect cyber-anomalies and multi-attacks. Internet of Things, 14, article number 100393. doi: 10.1016/j.iot.2021.100393.
  17. Wang, S., Balarezo, J.F., Kandeepan, S., Al-Hourani, A., Chavez, K.G., & Rubinstein, B. (2021). Machine learning in network anomaly detection: A survey. IEEE Access, 9, 152379-152396. doi: 10.1109/access.2021.3126834.
  18. Yaseen, A. (2023). The role of machine learning in network anomaly detection for cybersecurity. Sage Science Review of Applied Machine Learning, 6(8), 16-34.
  19. Yuan, Y., & Li, Y. (2022). A modified hybrid method based on PSO, GA, and K-Means for network anomaly detection. Mathematical Problems in Engineering, 2022, 1-10. doi: 10.1155/2022/5985426.
  20. Zhang, C., Wang, N., Hou, Y.T., & Lou, W. (2025). Machine learning-based intrusion detection systems: Capabilities, methodologies, and open research challenges. TechRxiv. doi: 10.36227/techrxiv.173627464.48290242/v1.