UDP Flooding Attack Dataset (UDP_DDoS_2025)
收藏资源简介:
This dataset contains 10,187,963 network traffic flow records with 88 features, representing both UDP-based Distributed Denial-of-Service (DDoS) flood attack traffic and benign traffic. It has been curated to support research in intrusion detection systems (IDS), network forensics, real-time DDoS attack detection, and machine learning–based network security analytics. The dataset models a realistic traffic scenario involving a UDP flooding attack targeting a single victim server. Attack traffic is generated from multiple distributed sources, while benign traffic consists of diverse legitimate protocol flows occurring before, during, and after the attack window. Class Distribution Category Records Percentage UDP Flood Attack 7,131,574 ~70% Benign Traffic 3,056,389 ~30% Benign traffic is further split to reflect temporal characteristics of real network conditions: Before attack: 45% of benign flows During attack: 20% of benign flows (background legitimate traffic continues) After attack: 35% of benign flows This distribution makes the dataset particularly valuable for evaluating temporal intrusion detection, sliding-window analysis, concept drift, and real-time streaming analytics. Flow Feature Summary Each record provides detailed flow-level attributes, including: Source & destination IP/port pairs Transport protocol (UDP, TCP, ICMP, DNS, HTTP) Flow duration, timestamp, inter-arrival times Packet and byte counts in forward/backward directions Segment/header size metrics Statistical descriptors of packet length distribution TCP flag counts (SYN, ACK, PSH, etc.), when applicable Derived behavioral metrics such as: Flow Bytes/s Flow Packets/s Down/Up Ratio Average Packet Size Attack flows are generated from randomized high-rate UDP packet emissions targeting a single victim IP, simulating bandwidth exhaustion at scale. Benign traffic includes realistic variations of: Service / Protocol Behavior Modeled TCP Handshakes, partial and full connections UDP Lightweight application datagrams DNS UDP-based query-response traffic ICMP Diagnostic echo request/reply flows HTTP (TCP) Request/response with typical PSH/ACK patterns Usage Applications This dataset can serve as a benchmark for: Traditional IDS (signature and anomaly-based) Machine learning and deep learning models DDoS mitigation and traffic engineering research Class imbalance and resampling strategy evaluation Feature selection and flow behavior analysis Streaming and real-time detection systems File Format & Documentation The dataset is provided in CSV format to support seamless integration with: Python (Pandas, NumPy, Scikit-learn, PyTorch, TensorFlow) R, MATLAB, Weka, RapidMiner Big data platforms (Spark, Flink)



