遇见数据集

Android Mischief Dataset: network dataset of mobile phones infected with Android Remote Access Trojans

收藏
Mendeley Data2024-03-27 更新2024-06-28 收录
官方服务:

资源简介:

The Android Mischief Dataset is a dataset of network traffic from mobile phones infected with Android RATs. Its goal is to offer the community a dataset to learn and analyze the network behavior of RATs to propose new detections to protect our devices. The dataset consists of 8 packet captures from 8 executed Android RATs. The Android RATs used in the dataset are: - RAT01 - Android Tester v6.4.6 - RAT02 - DroidJack v4.4 - RAT03 - HawkShaw - RAT04 - SpyMAX v2.0 - RAT05 - AndroRAT - RAT06 - Saefko Attack Systems v4.9 - RAT07 - AhMyth - RAT08 - Command-line AndroRAT The dataset contains a folder and its zip for each of the experiments. Each experiment was conducted manually by controlling the attacker and the victim. Considering that, each folder contains the following files: - README.md - the generic description of the execution, containing the name of the executed RAT, details of the RAT execution environment, details of the pcap (client’s IP and server’s IP, time of start of the infection). - APK - APK file generated by the RAT’s attacker program. - Log - very detailed and specific time log of all the actions performed in the client and the server during the experiment. - Pcap - network traffic of the whole infection. - Screenshots - a folder with screenshots of the mobile device and controller while performing malicious actions. - Zeek logs - a folder with Zeek generated logs after running Zeek on a RAT pcap. The zip files are encrypted with the password ‘infected’.

Android恶意软件数据集(Android Mischief Dataset)是一组源自感染Android远程访问木马(Android RATs)的移动设备的网络流量数据集。其旨在为社区提供可用于学习、分析RAT网络行为的数据集,以推动新型检测方案的研发,进而保护终端设备安全。 该数据集包含8组由8款已部署运行的Android RAT生成的网络数据包捕获文件。本次数据集所使用的Android RAT包括: - RAT01:Android Tester v6.4.6 - RAT02:DroidJack v4.4 - RAT03:HawkShaw - RAT04:SpyMAX v2.0 - RAT05:AndroRAT - RAT06:Saefko Attack Systems v4.9 - RAT07:AhMyth - RAT08:命令行版AndroRAT 数据集为每项实验单独配置了专属文件夹及其压缩包。每项实验均通过手动操控攻击端与受害端完成。在此实验框架下,每个实验文件夹包含以下文件: - README.md:实验执行通用说明文档,涵盖所运行RAT的名称、RAT运行环境详情、数据包捕获(pcap)文件的相关参数(客户端IP地址、服务端IP地址、感染起始时间)。 - APK:由RAT攻击程序生成的APK安装包。 - Log:实验期间攻击端与受害端所有操作的详细时序日志,包含精准的时间戳信息。 - Pcap:完整感染流程的全量网络流量捕获文件。 - Screenshots:存放执行恶意操作期间移动设备与控制器界面截图的文件夹。 - Zeek logs:在对应RAT的流量pcap文件上运行Zeek网络流量分析工具后生成的Zeek日志文件夹。 所有压缩包均使用密码"infected"进行加密。

创建时间:
2024-01-23
搜集汇总
背景与挑战
背景概述
Android Mischief Dataset是一个专门收集感染Android远程访问木马(RATs)手机网络流量的数据集,旨在为社区提供资源以分析RATs的网络行为并开发新的检测方法,保护设备安全。该数据集包含8个不同RATs的实验数据包捕获,每个实验提供详细的执行文件,如日志、网络流量记录和截图,所有压缩文件均使用密码'infected'加密。
以上内容由遇见数据集搜集并总结生成
二维码
社区交流群
二维码
科研交流群
商业服务