遇见数据集

A 6-Month Dataset of SSH Botnet Interactions and Command Payloads

收藏
Zenodo2026-04-25 更新2026-05-26 收录
官方服务:

资源简介:

Overview This dataset contains 145,425 events (after refinement) of granular interactive logs collected by a specialized asynchronous SSH Honeypot. The data was captured over a six-month period (May 11, 2025 – November 14, 2025) and reflects real-world automated and manual attack patterns against Linux-based systems. Research Context The collection was conducted as part of the study "Adaptive Decoy Systems for Preemptive Detection of Cyber Threats in Web Environments" at the National University "Odesa Law Academy". The project focuses on improving the cyber resilience of critical web systems through dynamic management of resource-intensive traps (Tarpits). Revision Note (April 2026): This version (v2.0) is a refined release of the original dataset. We have conducted a thorough data sanitization process to remove all internal loopback interactions and administrative testing artifacts. The resulting database is optimized for high-fidelity cybersecurity research and machine learning applications in intrusion detection. Authors and Contributions Viktor Boiko (ORCID: 0000-0001-5929-657X) — Scientific Supervisor & Lead Researcher. Associate Professor at the Department of Cybersecurity. Oleksandr Niiakyi (ORCID: 0009-0005-1025-1617) — Software Developer & Researcher. Affiliation Faculty of Cybersecurity and Information Technologies, National University "Odesa Law Academy". Technical Specifications Asynchronous Python-based SSH server. Full reconstruction of the attacker's "kill chain" via unique session tracking (UUID). Comprehensive shell command logging, including malware droppers and fileless execution attempts (via /dev/tcp). Key Research Findings (v2.0 Updated) The dataset captures the complete post-authentication lifecycle, including 28 unique interactive shell sessions originating from 7 distinct external threat actors. Documentation of sophisticated attack techniques, including a high-value instance of a malware dropper utilizing /dev/tcp bash sockets to establish stealthy network connections. A comprehensive library of 2,109 unique credential pairs (login/password), providing insights into modern automated authentication patterns and specialized botnet markers. Analysis of attack cycles spanning 6 months, with peak intensities exceeding 10,700 interactions per hour during automated surge events. Version 2.0 has been audited to exclude 74 administrative test sessions (localhost/127.0.0.1), ensuring the dataset exclusively represents genuine external threats. Data Structure Fields include: timestamp, session_id, ip, port, event_type, command, message, and level. Usage and Licensing Intended for academic research in Cybersecurity, IDS Machine Learning, and Threat Intelligence. License: Creative Commons Attribution 4.0 International (CC BY 4.0).

提供机构:
Zenodo
创建时间:
2026-04-24
二维码
社区交流群
二维码
科研交流群
商业服务