遇见数据集

APEX-IDS2026: A Real-World Network Perimeter Threat Dataset

收藏
Zenodo2026-08-19 更新2026-08-20 收录
官方服务:

资源简介:

APEX-IDS2026 acts as a modern, large-scale, real-world benchmark for evaluating machine learning models in network intrusion detection. Historically, research in this field relies on synthetic datasets or outdated captures. APEX-IDS2026 solves this by supplying traffic captured from a live, internet-facing /24 IPv4 honeynet over a 44-day period in early 2026. This exposes models to actual threats rather than simulated lab environments. The repository includes the data in two formats: The Full Dataset (Partitioned): Contains 141.6 million records divided into three categories (Attacks, Suspicious, Normal). It includes traffic from 64,084 distinct attacking IP addresses targeting actual services (Redis, MongoDB, Elasticsearch, VoIP). The High-Confidence Subset: A strictly filtered 69.1 million record subset containing only verified attacks and suspicious flows. We created this subset exclusively for machine learning model training and evaluation. Real-world 'Normal' traffic often contains unclassified background noise or zero-day threats that compromise label integrity. The High-Confidence Subset guarantees a 0% false-positive ground truth by removing the ambiguous 'Normal' class entirely. This allows researchers to train models on verified malicious traffic and evaluate them with absolute certainty regarding the labels. Features include: 70+ Layer 7 attributes extracted via the Zeek Network Analysis Framework (including HTTP, DNS, TLS, and SSH metadata). Standard NetFlow v9 attributes (byte counts, packets, flags). TCP connection states and inter-arrival time statistics. Geographical and temporal data for all connections. Note: All IP addresses are deterministically anonymized (SHA-256 truncation) to protect privacy while preserving subnet patterns for model training.

提供机构:
Zenodo
创建时间:
2026-08-19
二维码
社区交流群
二维码
科研交流群
商业服务