k-mean clustering and its real use-case in the security domain : detecting a ddos attack on apache server live

What is a DDoS Attack? — DDoS Meaning

How a DDoS attack works

  • The response to requests will be much slower than normal.
  • Some — or all — users’ requests may be totally ignored

What our objective will be:

  • Pull the log file and put it to any centralized storage like aws s3
  • create, analyse and the put the code to the SCM tool like GitHub
  • further we can use automation tools like jenkins to pull the code and the log file and then find the vulnerable IPs which may cause D-DOS attack and take necessary actions like mailing, using the AWS API to further block the IP address by updating the firewall or any other research work
import pandas as pd
import matplotlib.pyplot as plt
import numpy as np
from sklearn.cluster import KMeans
from datetime import datetime
import pytz
import re

