Network traffic analysis is a crucial aspect of maintaining server performance and security. This study aims to implement the K-Means clustering algorithm to group network traffic characteristics on a server running the Debian 12 Bookworm operating system. Raw data was collected in real time using the tcpdump utility on the enp0s3 network interface by capturing 3,000 data packets (packet capture/PCAP). The raw data was then extracted using tshark into CSV format based on the Packet Size and Frequency features as input parameters for data mining. Clustering was evaluated for K values ranging from 2 to 10 using inertia, the Silhouette Score, and the Davies–Bouldin Index. K=3 was retained to represent macro-level segmentation, while K=5 was examined to provide a more detailed traffic representation based on the combined consideration of cluster validity and interpretability. For K=3, the mean packet sizes ranged from 121.00 to 1,241.85 bytes, while for K=5 they ranged from 118.75 to 1,303.81 bytes. The findings demonstrate the feasibility of K-Means as an initial approach for descriptive network-traffic segmentation. However, the study did not directly evaluate anomaly-detection accuracy or cybersecurity effectiveness. The findings demonstrate the feasibility of K-Means as an initial approach for descriptively segmenting Debian 12 network traffic based on packet size and packet frequency.
Copyrights © 2026