遇见数据集

IEC104-IDS-2025: Labeled Network Traffic Dataset for Intrusion Detection in IEC 60870-5-104 SCADA Communication

收藏
Zenodo2026-07-17 更新2026-08-02 收录
官方服务:

资源简介:

IEC104-IDS-2025 is a labeled network-traffic dataset for intrusion detection system (IDS) research on IEC 60870-5-104 (IEC-104) SCADA communication. Traffic was captured from a laboratory physical SCADA testbed with real field devices: a SCADA Master, a physical Remote Station, a Bay Control Unit (IEC 61850), physical field devices (circuit breaker and power meter), an attacker node (Kali Linux 2023.3), and a managed switch with port mirroring for passive capture. This is version 2.0.0. It extends version 1.0.0 (three scenarios) to five attack scenarios by adding the integrity-attack category (False Data Injection) and a five-class multi-class dataset. Feature extraction, labeling, and machine-learning training were fully re-done with a unified pipeline across all scenarios; models use a 20-feature set from which identity attributes (IP/MAC addresses, TCP ports, IP TTL, TCP window size) are deliberately excluded to prevent data leakage. The APDU Flood capture is retained from v1.0.0; the other scenarios were re-captured, and the command-injection attack (CCIA) is now generated with an NFQUEUE-based engine. Attack scenarios:1. SYN Flood — Availability, Layer 4. DoS via SYN flood with randomized source IPs on port 2404 (hping3).2. APDU Flood — Availability, Layer 7. DoS via APDU flood on port 2404.3. CCIA (Command & Control Injection Attack) — Integrity, Layer 7. Man-in-the-Middle interception of IEC-104 Double Command packets (ASDU Type 46), flipping the command value (ON/OFF). The MitM position is established via ARP spoofing (attacker impersonates the Master toward the RTU); packet modification uses an NFQUEUE engine.4. FDI Bias — Integrity, Layer 7. False Data Injection on measurement packets (ASDU Type 13) with a random +/-5% offset, via Scapy-based ARP-spoofing MitM (attacker impersonates the RTU).5. FDI Targeted — Integrity, Layer 7. False Data Injection with fixed values (49.5 Hz, 95 kV), via Scapy-based ARP-spoofing MitM. Dataset files (binary CSV per scenario + a multi-class CSV + PCAP captures):- dataset_syn_binary.csv (full labeled, 7,302,719 rows; undersampled 1:10 at training time)- dataset_apdu_binary.csv (3,123,030 rows)- dataset_ccia_binary.csv (22,540 rows)- dataset_fdi_bias_binary.csv (53,988 rows)- dataset_fdi_targeted_binary.csv (60,924 rows)- dataset_multiclass_5class_v3.csv (198,404 rows: NORMAL, SYN_FLOOD, APDU_FLOOD, CCIA, FDI) Reference results (best model per scenario): FDI Targeted 99.61% (GB), FDI Bias 99.56% (KNN), APDU Flood 96.74% (RF), CCIA 85.20% (GB), SYN Flood 86.45% (GB); five-class multi-class 88.96% accuracy, Macro-F1 0.816 (GB). Note: attack-generation scripts are intentionally not included for critical-infrastructure safety. This dataset accompanies the paper "Comparative Study of Machine Learning Models for Intrusion Detection in SCADA Communication Based on IEC 60870-5-104" (ISITIA 2026). Version 1.0.0 remains available and is the version referenced by that paper. To cite all versions, use the concept DOI 10.5281/zenodo.19704482.

提供机构:
Zenodo
创建时间:
2026-07-17
二维码
社区交流群
二维码
科研交流群
商业服务