遇见数据集

KRONOS-SDN: A Large-Scale, Cross-Plane Dataset for Machine Learning Intrusion Detection in Software-Defined Networks

收藏
Zenodo2026-04-30 更新2026-05-26 收录
官方服务:

资源简介:

KRONOS-SDN is a large-scale, cross-plane dataset designed to support research on machine learning-based intrusion detection in Software-Defined Networking (SDN) environments. The dataset was generated from a SDN-based enterprise-like testbed that reproduces the structural complexity of corporate networks, including segmented business areas, server areas, open-access zones, IoT-like devices, Open vSwitch instances, Linux-based routing and an ONOS controller managing the OpenFlow infrastructure. The dataset includes two complementary data sources. The first consists of labelled network-flow records extracted from packet captures using CICFlowMeter. These flows describe benign and malicious traffic observed across multiple monitored virtual machines over a seven-day experimental campaign. The second consists of host-level system utilization measurements collected through collectd, including CPU, memory, load, entropy, disk, filesystem, process and interface statistics for the main SDN components. Malicious traffic was generated according to a scheduled multi-day attack plan reflecting a progressive kill-chain, including reconnaissance, service discovery, brute-force attacks, DNS and LDAP amplification, Slowloris, HTTP denial of service, OpenFlow packet crafting, OpenFlow traffic injection, flow table flooding and controller/switch-oriented denial-of-service scenarios. Benign activity was generated in parallel to emulate realistic enterprise operations, including DNS, NTP, HTTP/HTTPS, FTP, Active Directory interactions, email, application traffic and IoT telemetry. KRONOS-SDN is intended to facilitate reproducible benchmarking of intrusion detection systems, with particular emphasis on SDN-specific attack surfaces, temporal analysis, event-level evaluation, cross-plane correlation between network traffic and host telemetry and the development of machine learning and deep learning models for cyber-security monitoring. The archive contains labelled flow-level CSV files, system utilization statistics, metadata files, checksums, citation information, licensing information and documentation describing the dataset structure and reuse conditions.

提供机构:
Zenodo
创建时间:
2026-04-30
二维码
社区交流群
二维码
科研交流群
商业服务