遇见数据集

Cloud Supply-Chain Dataset

收藏
Zenodo2025-11-27 更新2026-05-26 收录
官方服务:

资源简介:

This dataset contains real-time, multi-source cloud supply-chain telemetry collected from a live, production-scale multi-cloud environment spanning August 2021 to September 2025. The data was recorded from distributed compute nodes, CI/CD pipelines, container registries, API gateways, identity providers, and security monitoring subsystems operating across hybrid cloud deployments. The dataset represents authentic operational behaviour, including workload fluctuations, dependency updates, routing shifts, and security-driven events that naturally occur in modern software supply-chain ecosystems. All telemetry is sampled at a fixed 15-minute interval, ensuring consistent temporal resolution for anomaly detection, provenance validation, and federated learning research. The dataset captures both normal operational patterns and real-world attack scenarios, including data-injection attempts, routing manipulation, API misuse, DoS pressure, credential abuse, and exfiltration behaviour. The dataset includes the following feature categories: 1. Cloud Infrastructure Metrics Cloud Provider, Region, Service Type — operational metadata identifying the execution environment. CPU Usage, Memory Usage, Disk I/O, Network In/Out — continuous measurements reflecting workload intensity, resource stress, and system anomalies. Baseline Deviation Score — deviation from long-term performance baselines computed inside the monitoring pipeline. 2. Dependency and Software Integrity Indicators Dependency Depth, Version Mismatch Count — structural and update-related characteristics of software components. Checksum Deviation, Unsigned Binary Count — integrity and trust indicators relevant to detecting tampering or poisoned dependencies. Repository Trust Score — confidence signal derived from release history and registry metadata. External Script Execution — event flag indicating unverified or unusual script activations. 3. Network and API Behaviour Inbound/Outbound Connection Count — network load and communication patterns. Failed or Unauthorized API Calls — signs of misuse, credential replay, or enumeration attempts. Encrypted Traffic Ratio — proportion of encrypted flows over total observed traffic. 4. Access and Identity Signals Failed Login Attempts, Privilege Escalation Flag, Access Token Reuse — identity and authentication-related indicators used to detect abuse or lateral movement. 5. Process and Execution Activity Process Creation Count, Dynamic Library Loads, Code Injection Flag — runtime behaviour that reflects execution anomalies or malware-like patterns. Malicious Signature Match — detection outcomes from integrated security engines. 6. Event Logs and Policy Compliance Error Log Count, Policy Breach Count, Unauthorized Access Events — system-level and administrative event markers. 7. Threat Intelligence and Incident Indicators Threat Intel Hits, Security Alerts, Critical Alert Ratio — threat-feed correlation and severity assessment. Incident Response Time — operational responsiveness under different incident conditions. 8. Temporal and Statistical Properties Burstiness Index, Change Rate Per Hour — temporal volatility descriptors suited for detecting drift, unusual bursts, or stealthy anomalies. 9. Labels and Target Variables Attack_Type — one of six real attack categories:Normal Operation, Data Injection, Routing Manipulation, DoS, Credential Abuse, Data Exfiltration. Attack_Label — binary (0 = normal, 1 = attack). Severity Score — real-time severity estimation derived from security alerts and behavioral deviation. Data Integrity and Preprocessing Before release, the dataset underwent a comprehensive quality-assurance pipeline that included: Timestamp normalization and deduplication Removal of corrupted or partially logged records Standardization of categorical fields Scaling of continuous features using empirical operating ranges Preservation of temporal ordering and original heterogeneity

提供机构:
Zenodo
创建时间:
2025-11-27
二维码
社区交流群
二维码
科研交流群
商业服务