Multi-Node Honeypot HTTP Threat Intelligence Dataset (May-July 2026), Gemini 2.5-Labeled
收藏资源简介:
This dataset contains 47,598 HTTP-layer attack logs captured by a three-node honeypot network (DigitalOcean droplets in London, New York, and Bangalore) between May 30 and July 8, 2026, from 5,095 unique attacker IP addresses. Each log was classified for attack type and severity (Low/Medium/High/Critical) by Gemini 2.5 via an automated pipeline, then cleaned (schema normalization, majority-vote resolution of repeated-payload label instability affecting 50.5% of repeated payloads) and validated against a stratified, blind human-labeled audit of 100 payloads (κ=0.662 raw, κ=0.803 with High/Critical merged). See included cleaning_report.json for full cleaning statistics and the accompanying repository for methodology and pipeline code. Fields: timestamp, ip, classification, severity, risk_score, summary, node, technique (raw HTTP request), total_attacks. severity labels are LLM-generated and cleaned/audited but not exhaustively human-verified beyond the n=100 sample.



