Cloud Supply-Chain Dataset
收藏资源简介:
This dataset contains real-time, multi-source cloud supply-chain telemetry collected from a live, production-scale multi-cloud environment spanning August 2021 to September 2025. The data was recorded from distributed compute nodes, CI/CD pipelines, container registries, API gateways, identity providers, and security monitoring subsystems operating across hybrid cloud deployments. The dataset represents authentic operational behaviour, including workload fluctuations, dependency updates, routing shifts, and security-driven events that naturally occur in modern software supply-chain ecosystems. All telemetry is sampled at a fixed 15-minute interval, ensuring consistent temporal resolution for anomaly detection, provenance validation, and federated learning research. The dataset captures both normal operational patterns and real-world attack scenarios, including data-injection attempts, routing manipulation, API misuse, DoS pressure, credential abuse, and exfiltration behaviour. The dataset includes the following feature categories: 1. Cloud Infrastructure Metrics Cloud Provider, Region, Service Type — operational metadata identifying the execution environment. CPU Usage, Memory Usage, Disk I/O, Network In/Out — continuous measurements reflecting workload intensity, resource stress, and system anomalies. Baseline Deviation Score — deviation from long-term performance baselines computed inside the monitoring pipeline. 2. Dependency and Software Integrity Indicators Dependency Depth, Version Mismatch Count — structural and update-related characteristics of software components. Checksum Deviation, Unsigned Binary Count — integrity and trust indicators relevant to detecting tampering or poisoned dependencies. Repository Trust Score — confidence signal derived from release history and registry metadata. External Script Execution — event flag indicating unverified or unusual script activations. 3. Network and API Behaviour Inbound/Outbound Connection Count — network load and communication patterns. Failed or Unauthorized API Calls — signs of misuse, credential replay, or enumeration attempts. Encrypted Traffic Ratio — proportion of encrypted flows over total observed traffic. 4. Access and Identity Signals Failed Login Attempts, Privilege Escalation Flag, Access Token Reuse — identity and authentication-related indicators used to detect abuse or lateral movement. 5. Process and Execution Activity Process Creation Count, Dynamic Library Loads, Code Injection Flag — runtime behaviour that reflects execution anomalies or malware-like patterns. Malicious Signature Match — detection outcomes from integrated security engines. 6. Event Logs and Policy Compliance Error Log Count, Policy Breach Count, Unauthorized Access Events — system-level and administrative event markers. 7. Threat Intelligence and Incident Indicators Threat Intel Hits, Security Alerts, Critical Alert Ratio — threat-feed correlation and severity assessment. Incident Response Time — operational responsiveness under different incident conditions. 8. Temporal and Statistical Properties Burstiness Index, Change Rate Per Hour — temporal volatility descriptors suited for detecting drift, unusual bursts, or stealthy anomalies. 9. Labels and Target Variables Attack_Type — one of six real attack categories:Normal Operation, Data Injection, Routing Manipulation, DoS, Credential Abuse, Data Exfiltration. Attack_Label — binary (0 = normal, 1 = attack). Severity Score — real-time severity estimation derived from security alerts and behavioral deviation. Data Integrity and Preprocessing Before release, the dataset underwent a comprehensive quality-assurance pipeline that included: Timestamp normalization and deduplication Removal of corrupted or partially logged records Standardization of categorical fields Scaling of continuous features using empirical operating ranges Preservation of temporal ordering and original heterogeneity



