SNMP 2016 dataset
收藏资源简介:
The enormous growth in computer networks and in Internet usage in recent years, combined with the growth in the amount of data exchanged over networks, have shown an exponential increase in the amount of malicious and mysterious threats to computer networks. Among many security issues, network attack is a major one. For example, Denial of Service (DoS) flooding attacks have recently become attractive to attackers, and these have posed devastating threats to network services. Therefore, the intrusion detection and network anomalies become very critical tasks in the field of network security research area. Researchers suffer from the lack of real-life datasets. Most of the datasets in hand depend on simulated-based approaches, which cannot represent the exact and the nature of network intrusion and anomaly scenarios. Hence, generating realistic datasets is very important as it allows for accurate and appropriate evaluation of the detection techniques. To overcome such shortcoming of the existing datasets, in this paper, we identify the important requirements to generate effective dataset and we also identify important attack scenarios and the method of injecting them in such data. Our systematic approach involves the investigation of Simple Network Management Protocol (SNMP) for network anomaly detection. For that, we present a Management Information Base (MIB) based mechanism capturing realistic SNMP-MIB statistical data. Then we use this data from an SNMP agent by means of real-life experiments involving six types of DoS attacks and Brute Force attack. Our dataset consists of 4998 records, where each record consists of 34 MIB variables, which are categorized into their corresponding groups, namely: Interface, IP, TCP and ICMP.
近年来,计算机网络与互联网应用规模持续扩张,网络传输的数据量同步攀升,这使得计算机网络面临的恶意与未知威胁呈指数级增长态势。在诸多网络安全问题中,网络攻击是最为核心的威胁之一。例如,拒绝服务(Denial of Service, DoS)泛洪攻击近期愈发受到攻击者青睐,此类攻击对网络服务构成了毁灭性威胁。故此,入侵检测与网络异常检测已成为网络安全研究领域的关键任务。当前研究人员面临的一大瓶颈是缺乏真实场景下的可用数据集:现有多数数据集依赖模拟生成手段,无法精准还原网络入侵与异常场景的真实本质。故而,构建贴合现实的数据集对精准评估检测技术而言至关重要。为弥补现有数据集的固有缺陷,本文明确了生成高效数据集的核心需求,同时梳理了关键攻击场景及其数据注入方法。本文采用系统化研究路径,围绕网络异常检测中的简单网络管理协议(Simple Network Management Protocol, SNMP)展开调研:提出了一种基于管理信息库(Management Information Base, MIB)的机制,用于采集真实的SNMP-MIB统计数据;随后通过包含6种DoS攻击与暴力破解(Brute Force)攻击的真实实验,从SNMP智能体中获取上述实验数据。本数据集共计包含4998条记录,每条记录涵盖34个MIB变量,这些变量被划分为四大类别,分别为接口(Interface)、网际协议(Internet Protocol, IP)、传输控制协议(Transmission Control Protocol, TCP)与互联网控制报文协议(Internet Control Message Protocol, ICMP)。




