A 6-Month Dataset of SSH Botnet Interactions and Command Payloads
收藏资源简介:
Overview This dataset contains 145,499 records of granular interactive logs collected by a specialized asynchronous SSH Honeypot. The data was captured over a six-month period (May 11, 2025 – November 14, 2025) and reflects real-world automated and manual attack patterns against Linux-based systems. Research Context The collection was conducted as part of the study "Adaptive Decoy Systems for Preemptive Detection of Cyber Threats in Web Environments" at the National University "Odesa Law Academy". The project focuses on improving the cyber resilience of critical web systems through dynamic management of resource-intensive traps (Tarpits). Authors and Contributions Viktor Boiko (ORCID: 0000-0001-5929-657X) — Scientific Supervisor & Lead Researcher. Associate Professor at the Department of Cybersecurity. Oleksandr Niiakyi (ORCID: 0009-0005-1025-1617) — Software Developer & Researcher. Affiliation Faculty of Cybersecurity and Information Technologies, National University "Odesa Law Academy". Technical Specifications Architecture: Asynchronous Python-based SSH server. Log Fidelity: Full reconstruction of the attacker's "kill chain" via unique session tracking (UUID). Payload Capture: Comprehensive shell command logging, including malware droppers and fileless execution attempts (via /dev/tcp). Key Research Findings Interactive Payloads: Capture of post-login behavior and complex automated scripts. Brute Force Intelligence: Analysis of over 1,500 unique credential pairs, including default IoT passwords and botnet-specific identifiers. Temporal Dynamics: Identification of daily attack cycles with significant spikes around 13:00 UTC. Data Structure Fields include: timestamp, session_id, ip, port, event_type, command, message, and level. Usage and Licensing Intended for academic research in Cybersecurity, IDS Machine Learning, and Threat Intelligence. License: Creative Commons Attribution 4.0 International (CC BY 4.0).



