遇见数据集

Security-Gym Dataset: Labeled Linux Log and eBPF Streams for Continual Learning Research

收藏
Zenodo2026-04-09 更新2026-05-26 收录
官方服务:

资源简介:

Ground-truth-labeled Linux server log and eBPF kernel event streams for cybersecurity continual learning research. Contains 11.2M benign events (7.9M server logs + 3.24M eBPF kernel events from 3 servers) mixed with 60K scripted attack events across 5 types (SSH brute force, credential stuffing, port scanning, Log4Shell CVE-2021-44228, Redis CVE-2022-0543) executed against a purpose-built vulnerable server. Includes 4 pre-composed experiment streams from 4.9M events (7-day) to 257.7M events (365-day), ready for use with the security-gym Gymnasium environment. All events are timestamped, parsed, and labeled with ground truth including attack type and MITRE ATT&CK stage. Files: - DATASET_README.md — Full documentation, schema, quick start, and baselines - benign_v4.db.zst — 11,159,241 benign events from 4 personal Linux servers (auth.log, syslog, nginx, eBPF). PII-scrubbed. - campaigns_v2.db.zst — 60,468 attack events from 10 campaigns across 5 attack types, with log + eBPF kernel events - exp_7d_brute_v4.db.zst — 7-day experiment stream (4,891,541 events, SSH brute force only, 1 campaign/day) - exp_30d_heavy_v4.db.zst — 30-day experiment stream (21,511,208 events, all 5 attack types, heavy attack rate) - exp01_90d_v4.db.zst — 90-day experiment stream (63,212,997 events, all 5 attack types, moderate rate) - exp_365d_realistic_v4.db.zst — 365-day experiment stream (257,654,256 events, all 5 attack types, realistic rate) All databases are SQLite with WAL mode. Decompress with zstd -d <file>.zst. Experiment streams are composed from benign + attack data with Poisson-scheduled campaigns and 24.2% eBPF downsampling.

提供机构:
Zenodo
创建时间:
2026-03-07
二维码
社区交流群
二维码
科研交流群
商业服务