CESNET-MINER22
收藏资源简介:
<strong>CESNET-MINER22 : Datasets of Cryptomining Communication</strong> This dataset was created to design a detector of cryptominers communication, soon to be published in NordSec 2022 - IT security conference: Plný, R.; Hynek, K.; Čejka; T.: DeCrypto: Finding Cryptocurrency Miners on ISP networks, in Proceedings of the 27th Nordic Conference on Secure IT Systems, 2022. File named <code>decrypto_dataset_design.csv</code> contains 2,024,903 anonymized flows collected on the national CESNET2 network from December 2021 to February 2022. File named <code>decrypto_dataset_evaluation.csv</code> contains of 1,075,576 anonymized flows collected on the national CESNET2 network during March 2022. Both datasets are provided in CSV format and were created by ipfixprobe. See field description provided below. <strong>BYTES</strong> Number of transferred bytes (from client to server). <strong>BYTES_REV</strong> Number of transferred bytes in the opposite direction (from server to client). <strong>DST_PORT</strong> Destination port. <strong>LABEL</strong> Flow label. Possible values are: Miner Other <strong>PACKETS</strong> Number of transferred packets (from client to server). <strong>PACKETS_REV</strong> Number of transferred packets in the opposite direction (from server to client). <strong>PPI_PKT_DIRECTIONS</strong> Array of directions of the first 30 packets. Values: 1 represents direction client->server -1 represents direction server->client. <strong>PPI_PKT_FLAGS</strong> Array of TCP flags of the first 30 packets. <strong>PPI_PKT_LENGTHS</strong> Array of packet sizes of the first 30 packets. <strong>PPI_PKT_TIMES</strong> Array of timestamps of intercept of the first 30 packets. <strong>PROTOCOL</strong> Used protocol on the Transport layer of the ISO/OSI. TCP is represented by the value 6. <strong>SRC_PORT</strong> Source port. <strong>TCP_FLAGS</strong> TCP flags of the first packet (sent by client). <strong>TCP_FLAGS_REV</strong> TCP flags of the first packer from the opposite direction (sent by server). <strong>TIME_FIRST</strong> Time of interception of the first packet in the flow. <strong>TIME_LAST</strong> Time of interception of the last packet in the flow.



