基于大规模动态可信行为分析的网络流量数据集UNSW-NB15
收藏资源简介:
随着计算机网络规模和开发应用程序的指数级增长,发起攻击可能造成的潜在损害显著增加,这一点变得显而易见。同时,入侵检测系统(IDS)和入侵防御系统(IPS)是抵御复杂且不断增长的网络攻击的最重要防御工具之一。由于缺乏足够的数据集,入侵检测系统中基于异常的方法难以准确部署、分析和评估。有许多这样的数据集,例如DARPA98、KDD99、ISC2012和ADFA13,研究人员已使用这些数据集来评估他们提出的入侵检测和入侵防御方法的性能。根据我们对自11个可用数据集的研究,许多此类数据集已经过时且不可靠。其中一些数据集缺乏流量多样性和数量,其中一些没有涵盖各种攻击,而另一些匿名数据包信息和有效载荷无法反映当前趋势,或者它们缺乏功能集和元数据。本文生成了一个可靠的数据集,其中包含良性和七种常见的攻击网络流,该数据集符合现实世界的标准并且是公开可用的
As the scale of computer networks and the deployment of applications grow exponentially, it has become increasingly evident that the potential damage caused by cyberattacks has risen significantly. Meanwhile, Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) are among the most critical defensive tools against complex and increasingly prevalent cyberattacks. However, anomaly-based methods in intrusion detection systems are difficult to accurately deploy, analyze, and evaluate due to the lack of sufficient datasets. Numerous such datasets, including DARPA98, KDD99, ISC2012 and ADFA13, have been used by researchers to evaluate the performance of their proposed intrusion detection and prevention methods. Based on our study of the 11 available datasets, many of these datasets are outdated and unreliable. Some lack traffic diversity and volume, some fail to cover a comprehensive range of attack types, while others have anonymous packet information and payloads that do not reflect current network trends, or lack functional sets and metadata. This paper generates a reliable dataset containing benign network traffic and seven common attack flows, which conforms to real-world standards and is publicly available.




