ICS Dataset
收藏资源简介:
This dataset was generated to support research on anomaly detection in Cyber-Physical Systems (CPS), with a focus on distinguishing cyber attacks from system faults. It was created using an extended version of the ICSSIM emulator, which replicates an industrial bottle-filling process with two PLCs, two HMIs, a water tank, valves, and conveyor belts. We extended ICSSIM by adding a data generation module that records and synchronizes three complementary data sources: Sensor readings (physical process data) System logs (PLC and HMI events) Network traffic (PCAP traces from TCPDump) All data streams are timestamp-aligned to allow multi-source analysis. The dataset contains three categories of operational scenarios: Normal operation – baseline process execution without faults or attacks. System faults – five injected fault types: Sensor drift Tank leak Overheating (PLC delay) Valve malfunction Memory corruption Cyber attacks – four representative attacks mapped to MITRE ATT&CK for ICS: Reconnaissance [T1089] Denial-of-Service (DoS) [T0806] Man-in-the-Middle (MITM) [T0830, T0831] Replay Attack [T0813]



