ICS-MMOC3: Realistic Multi-Modal Power Generation ICS Dataset
收藏资源简介:
Overview MMOC3 is an ICS dataset collected from a physical power generation testbed operated by a national ICS laboratory. The dataset emulates a combined-cycle power plant and exposes over one thousand industrial process tags, including sensors, actuators and control variables. In addition to raw IP and SCADA network traffic, specifically S7Comm and Modbus, the dataset includes a comprehensive set of historian records, IDS alerts, system events logs, SCADA-to-NetFlow second-level statistics with over 70 features, and a mapping between industrial variables and their representation in SCADA messages. Data were recorded during extended periods of normal operation, and was subjected to a wide range of controlled operational events and fault scenarios, as well as deliberate cyber attacks targeting both the network and control layers. This dataset is part of the CPSS '26 conference publication: ICS-MMOC3: Exploring Operational Faults and Cyber Attacks with a Realistic Multi-Modal Power Generation ICS Dataset Key Features The dataset is designed to explicitly bridge the gap between information technology (IT) network traffic and operational-technology (OT) physical process behavior in ICS. Rather than treating IT and OT data sources as independent modalities, MMOC3 provides a unified view in which network-level communication, SCADA protocolsemantics, and physical process dynamics are temporally aligned and semantically connected. Dataset Structure The MMOC3 dataset comprises six capture days, totaling approximately 30 hours of operation of the power generation testbed. For each day, we provide benign and anomalous data to enable realistic benchmarking of ICS detection methods. 🟢 Normal🟡 Operational Failures🔴 Cyber Attacks Day Date Type Recorded Network Pcap Recorded Historian SCADA-to-Netflow Recorded IDS Alerts Recorded Events Logs 1 13/6 🟢 ✓ ✓ ✓ ✓ ✓ 2 14/6 🟢 🟡 ✓ ✓ ✓ ✓ ✓ 3 15/6 🟢 🟡 ✓ ✓ ✓ ✓ ✓ 4 18/6 🟢 🟡 🔴 ✓ ✓ ✓ ✓ ✓ 5 19/6 🟢 🟡 🔴 ✓ ✓ ✓ ✓ ✓ 6 20/6 🟢 🟡 🔴 ✓ ✓ ✓ ✓ ✓ Files Structure For each capture day, a set of 5 corresponding files is provided. Files are logically grouped by their capture day using an `MM_DD_` naming prefix as detailed in the table below. Together, these files expose packet-level network traffic, physical process measurements, derived SCADA flow statistics, IDS alerts, and event logs. Files provided per capture day in MMOC3 Filename Ext. Description Time zone MM_DD_network .pcap Packet-level trace of all network traffic captured in the system, including SCADA communications (S7Comm and Modbus) UTC MM_DD_historian .csv Historian-style record of all industrial process tags at second-level. UTC MM_DD_S7Comm_Flow .csv Flow-level aggregated statistics of SCADA traffic, partitioned into fixed 1-second windows and comprising more than 70 features per window. UTC MM_DD_events .json OT IDS events and alerts generated by Suricata. UTC MM_DD_sysmon .evtx HMI operating system event log capturing host-level activity and system events. UTC Additionally, the repository includes global, dataset-wide files that provide essential context for the daily captures: siemens tag address.csv: Mapping between industrial variables and Database (DB) addresses observed in the SCADA messages. ip_mapping.csv : Mapping of IP addresses across the network. Ground Truth and Event Labeling To facilitate machine learning learning and precise temporal analysis, ground truth labeling is provided at a one-second granularity. The MM_DD_historian and MM_DD_S7Comm_Flow artifacts include normal and anomalous labels according to the table below.The following table summarizes the exact time windows for all simulated system faults and cyber attacks executed during the data collection. For more information about the attack vectors, threat models, and simulated system faults, please refer to the accompanying publication. Table: Summary of Anomalous Events Event Date Event type Start (HH:MM:SS) UTC End (HH:MM:SS) UTC Label Description 1 13/6 Normal Bumpless Tranfser 11:45:10 12:30:07 E1 Switch to diesel turbine 2 14/6 Operational failure ⚠️ 07:37:55 07:42:38 E2 Disconnect HMI from PLC 3 14/6 Unexpected historian failure ⚠️ 07:42:39 08:40:42 E3 No historian data 4 14/6 Operational failure 09:15:47 09:17:07 E4 Close valve 5 14/6 Operational failure 09:17:08 09:22:31 E5 Switch to diesel turbine 6 14/6 Operational failure 09:22:32 09:28:11 E6 Open valve 7 14/6 Operational failure 10:53:41 10:56:49 E7 Disconnect temprature sensor 8 15/6 Operational failure 08:03:07 08:05:41 E8 Emergency stop 9 15/6 Operational failure 08:05:42 08:11:09 E9 Restart process - back to normal 10 15/6 Operational failure 11:38:09 11:40:34 E10 Insufficient supply to gas turbine 11 15/6 Operational failure 12:14:23 12:15:51 E11 Disconnect tag LSL305A 12 18/6 Cyber attack ⚠️ 10:59:08 11:00:09 E12 USB Malware Injection 13 18/6 Cyber attack 11:08:51 12:52:29 E13 Industrial process stop as a result of the attack. No HMI and historian data. 14 19/6 Cyber attack ⚠️ 09:15:58 09:36:07 E14 Attacker connects to the network 15 19/6 Cyber attack ⚠️ 09:36:08 10:04:14 E15 Attacker performs port scan and gains control to the HMI 16 19/6 Cyber attack 10:18:27 10:27:26 E16 Attacker performs tag poisoning 17 19/6 Operational failure 11:39:19 11:41:59 E17 Tag disconnection - turbine stop 18 20/6 Cyber attack ⚠️ 10:01:38 10:12:23 E18 Malicious update on HMI, take over HMI 19 20/6 Cyber attack 10:12:24 10:34:22 E19 Attacker performs tag posioning 20 20/6 Operational failure 11:36:04 11:41:54 E20 Emergency stop + Restart 21 20/6 Cyber attack ⚠️ 11:59:24 12:00:32 E21 Attacker connects to the network 22 20/6 Cyber attack ⚠️ 12:00:33 12:17:10 E22 Attacker performs port scan and gains control to the HMI. 23 20/6 Cyber attack 12:17:11 12:26:41 E23 Attacker performs tag poisoning 24 20/6 Cyber attack 12:26:42 12:35:43 E24 Attacker continues to write to addresses in HMI Because MMOC3 captures data across multiple system levels, not all events listed above induce anomalies across all data modalities simultaneously. ⚠️ - Note that although E2, E3, E12, E14, E15, E18, E21, E22 are labelled as anomalous, there might not be an impact on the industrial process. Citation If you use this dataset, please cite the following publication: @inproceedings{shafir-cpss26, title = {{ICS-MMOC3}: Exploring Operational Faults and Cyber Attacks with a Realistic Multi-Modal Power Generation {ICS} Dataset}, author={L. Shafir and A. Elyashar and J. Cohen and M. Zeitoun and M. Holipsky and B. Yaakov and E. Aliev and R. Puzis and Y. Harel and A. Wool}, year = 2026, booktitle = {Proc. 12th ACM Cyber-Physical System Security Workshop (CPSS 2026)}, pages={63--76}, month = jun, address = {Bangalore, India}, url={\url{https://doi.org/10.1145/3775042.3807883}},}



