SDN_IDPS: A Realistic Software-Defined Networking Intrusion Detection Dataset with SDN-Specific Attack Modeling
收藏资源简介:
This dataset presents a comprehensive Software-Defined Networking Intrusion Detection Dataset (SDN_IDPS) designed to support research in SDN security and intelligent intrusion detection systems. The dataset consists of two complementary components: Full Network Dataset – A large-scale flow-based dataset derived from network traffic captured using Wireshark (PCAP format) and processed using CICFlowMeter. It includes 84 statistical flow features and covers a wide range of attack categories alongside normal traffic. ARP and MITM Dataset – A specialized dataset derived from ARP spoofing and Man-in-the-Middle (MITM) attack scenarios. Packet-level data was captured using Wireshark/TShark and transformed into bidirectional flow records through custom feature engineering, resulting in 29 flow-level features capturing temporal, directional, and protocol-level behaviors. The dataset includes the following attack categories: Normal Traffic DoS / DDoS Reconnaissance Web Attacks Credential Access (R2L) Malware SDN-specific attacks The data was generated in a realistic SDN emulation environment using GNS3, OpenDaylight controller, Open vSwitch, and Linux-based hosts. This dataset is released in raw form to allow researchers to apply their own preprocessing, feature engineering, and modeling pipelines. It is particularly suitable for SDN-based intrusion detection and hybrid detection approaches combining general network and SDN-specific attack analysis



