950K-Entry Modbus/OPC-UA/Profinet Dataset - Multi-Protocol ICS/OT Intrusion Detection via Hybrid Threshold-ML Fusion in SDN
收藏资源简介:
This dataset supports the study of intrusion detection in Industrial Control Systems (ICS) and Operational Technology (OT) environments using Software-Defined Networking (SDN) and hybrid Machine Learning (ML) techniques. It contains approximately 950,000 flow-level entries generated from a controlled experimental testbed integrating an SDN controller with multi-protocol industrial communication traffic, including Modbus/TCP, OPC-UA, and Profinet. The dataset was constructed through a combination of normal operational traffic and systematically injected attack scenarios. These include volumetric flooding attacks, low-rate stealth attacks, and protocol-specific anomalous behaviors designed to emulate realistic threat conditions in ICS/OT environments. Traffic was captured and processed into aggregated flow windows (1-second intervals), with features extracted from OpenFlow statistics and enriched with protocol-level characteristics. Each record includes flow-based features such as packet counts, byte counts, duration, inter-arrival statistics, and protocol identifiers, along with corresponding labels indicating normal or attack classes. The dataset enables the evaluation of both supervised and unsupervised intrusion detection approaches, including Random Forest classifiers and AutoEncoder-based anomaly detection models. This dataset was specifically designed to support the validation of a controller-integrated, in-flight IDS deployed within the Ryu SDN controller. It is particularly suited for research on real-time detection, hybrid model fusion (e.g., threshold + ML pipelines), and runtime latency analysis in SDN-managed ICS/OT networks. Key characteristics: ~950,000 labeled flow entries Multi-protocol coverage: Modbus/TCP, OPC-UA, Profinet Includes normal traffic and multiple attack classes Flow-based features derived from OpenFlow statistics Suitable for supervised, unsupervised, and hybrid ML evaluation Designed for controller-integrated SDN IDS research Potential applications: Intrusion Detection Systems (IDS) benchmarking SDN security research in ICS/OT environments Hybrid ML model evaluation (RF, AutoEncoder, ensemble methods) Runtime latency and deployment feasibility analysis



