遇见数据集

HTTPS Brute-force dataset with extended network flows

收藏
Zenodo2022-04-11 更新2026-05-25 收录
数据链接:
官方服务:

资源简介:

We are publishing a dataset we created for designing a brute-force detector of attacks in HTTPS. The dataset consists of extended network flows that we captured with flow exporter Ipifixprobe. Apart from traditional fields like source and destination IP addresses and ports, each flow contains information (size, direction, inter-packet time, TCP flags) about up to the first 100 packets. The sizes of packets are taken from the transport layer (TCP, UPD); packets with zero payload (e.g., TCP ACKs) are ignored. We publish three files: <em>flows.csv</em>, which contains raw flow data. <em>aggregated_flows.csv</em>, which contains aggregated flows <em>samples.csv</em>, which contains samples with extracted features. This data can be used for training a machine-learning classification model. All IP addresses, source ports, TLS SNIs are sha256-hashed. Column <em>CLASS</em> is 0 for benign samples and 1 for brute-force samples. <br> <strong>Brute-force data</strong><br> The brute-force data were generated with three popular attack tools - Ncrack, Thc-hydra, and Patator. Attacks were performed against these applications: WordPress Joomla MediaWiki Ghost Grafana Discourse PhpBB OpenCart Redmine Nginx Apache The <em>SCENARIO</em> columns indicate which tool and application were used to generate the sample. <strong>Benign data</strong><br> Bening data consists of eight captures from a backbone network. The <em>SCENARIO</em> column indicates individual captures.

提供机构:
Zenodo
创建时间:
2020-11-16
二维码
社区交流群
二维码
科研交流群
商业服务