DNS-tunnelling-detection-by-fusing-encoding-feature-and-behavioral-feature
收藏资源简介:
该数据集由天津大学可信软件实验室联合企业内部安全实验室共同构建,用于研究DNS隧道检测。数据集包含基础数据集和泛化测试集两部分,采用pcap格式存储。基础数据集通过访问Alexa排名前1K网站的子域名获取可信站点子网站,并在校内实验室环境中采集良性DNS样本。恶意样本部分则使用开源贡献的DNS隧道流量,模拟环境中使用8种不同的DNS隧道工具收集。泛化测试集从一家安全企业的办公网络中获取,用于测试模型的鲁棒性。
This dataset was jointly constructed by the Trusted Software Laboratory of Tianjin University and an internal security laboratory of a corporate entity, aimed at researching DNS tunnel detection. The dataset comprises two parts: a foundational dataset and a generalization test set, both stored in pcap format. The foundational dataset was created by accessing subdomains of the top 1K websites according to Alexa rankings to obtain trusted sub-sites, and benign DNS samples were collected within the laboratory environment on campus. The malicious samples were gathered using open-source contributed DNS tunnel traffic, employing eight different DNS tunneling tools in a simulated environment. The generalization test set was acquired from the office network of a security company, intended to test the robustness of the model.
DNS-tunnelling-detection-by-fusing-encoding-feature-and-behavioral-feature 数据集概述
数据集构建
- 合作单位:天津大学可信软件实验室与企业内部安全实验室。
- 数据集用途:用于文章《DNS tunnelling detection by fusing encoding feature and behavioral feature》研究。
数据集内容
基础数据集
- 良性样本:通过查询Alexa排名前1K网站的子域名,获取10万个可信站点子网站,并在校内实验室环境中采集良性DNS样本。
- 恶意样本:采用开源贡献的DNS隧道流量,使用8种不同DNS隧道工具(如iodine, dnscat2等)在模拟环境中收集。
泛化测试数据集
- 良性样本:从安全企业的办公网络中获取手动筛选的DNS数据包。
- 恶意样本:收集了150个黑客常用的命令,用于Linux和Windows系统上的内网渗透,通过不同的DNS隧道工具获取。
数据集格式
- 存储格式:使用PCAP格式存储数据。
- IP地址:数据集中的IP地址仅限于独立组网环境,与现实网络中的IP无关。
注意事项
- 数据集可能包含非DNS协议的packets,解析时需注意过滤。
引用信息
- 引用文献:Tu Y, Liu S, Sun Q. DNS tunnelling detection by fusing encoding feature and behavioral feature[J]. Computers & Security, 2023:132.




