遇见数据集

CRAWDAD stanford/gates

收藏
Mendeley Data2024-03-27 更新2024-06-28 收录
官方服务:

资源简介:

This dataset contains traces of the Stanford CS department's wireless network.date/time of measurement start: 1999-09-20date/time of measurement end: 1999-12-12 collection environment: We collected a 12-week trace of a local-area wireless network installed throughout the Gates Computer Science Building of Stanford University. The building is L-shaped (the longer edge is called the a-wing, and the shorter the b-wing). It has four main floors with offices and labs, a basement with classrooms and labs, and a fifth floor with a lounge and a few offices. Each of the main floors has two access points, one for each wing. Additionally, the first floor has an access point for a large conference room; the library, which spans both the second and third floors, also has an access point. The basement has two access points, one near the classrooms and one for the Interactive Room, a special research project in the department. The smaller fifth floor only has one access point. The wireless user community consists of 74 users who can be roughly divided into four groups: - 35 first year PhD students, who were each given a laptop with a WaveLAN card upon arrival (which corresponds to the beginning of the trace). Their offices are primarily in the 2b wing. - 22 graphics students and staff, the majority of whom received laptops with WaveLAN cards a week into the tracing period. Their offices are primarily in the 3b wing. - Three robots, used by the robotics lab for research. The robots do not have to authenticate themselves to reach the outside network. While the robots are somewhat mobile, they stay in the 1a wing. Although these WaveLAN cards are intended to be used by the robots, students in the robotics lab also use the network cards for session connections and websurfing. - 14 other users (students, staff, and faculty) scattered throughout the building. In addition to these 74 users, there were also four users who authenticated themselves but only connected to wired ports on the public subnet rather than the wireless network. We do not consider these users in the rest of this analysis of the wireless network.network configuration: In the Gates Computer Science Building at Stanford University, administrators have made a "public" subnet available for any user affiliated with the university. Users desiring network access via this subnet must authenticate themselves to use their dynamically assigned IP address to access the rest of the departmental and university networks and the Internet. This subnet is accessible both from a wireless network and from Ethernet ports in public places in the building, such as conference rooms, lounges, the library, and labs. The wireless network is a WaveLAN network with WavePoint II access points acting as bridges between the wireless and wired networks. The access points each have two slots for wireless network interfaces; both slots are filled, one with older 2 Mbps cards to support the few users who have not updated their hardware yet, and the other with WaveLAN IEEE802.11-compatible 10 Mbps cards. Because all of the wireless users are on a single subnet (which promotes roaming without the need for Mobile IP or other such support), we gathered traces on the router that connects the public subnet to the rest of the departmental wired network. The router is a 90 MHz Pentium running RedHat Linux with two 10 Mbps network interfaces. One interface connects to the public subnet, and the other connects to the departmental network.data collection methodology: To gather all of the information we wanted, we collected three separate types of traces during a 12-week period encompassing the 1999 Fall quarter (from Monday, September 20 through Sunday, December 12). The first trace we gathered is a tcpdump trace of the link-level and network-level headers of all packets that went through the router. We use this information in conjunction with the other two traces. The second trace is an SNMP trace. Approximately every two minutes, the router queries, via Ethernet, all twelve access points for the MAC addresses of the hosts currently using that access point as a bridge to the wired network. Once we know which access point a MAC address uses for network access, we know the approximate location (floor and wing) of the device with that MAC address. We pair these MAC addresses with the link level addresses saved in the packet headers to determine the approximate locations of the hosts in the tcpdump trace. The overhead from the SNMP tracing is low: 530 packets or 50 KBytes is the average overhead from querying all twelve access points every two minutes. The overhead for querying an individual access point is 3.2 KBytes if no MAC addresses are using that access point; otherwise, the base overhead is 14.5 KBytes for one user at an access point, plus 1 KByte for every additional user. The last trace is the authentication log, which keeps track of which users request authentication to use the network. Each request has both the user's login name as well as the MAC address from which the user makes the request. We pair these MAC addresses with the link-level addresses saved in the tcpdump trace to determine which user sends out each packet.sanitization: We obtained permission to collect these traces from the Department Chair and informed all network users that this tracing was taking place. We additionally informed users we would record packet header information only (not the contents) and that we would anonymize the data. Knowledge of the tracing may have perturbed user behavior, but we have no way of quantifying the effect.stanford/gates/combined TracesetThis traceset contains traces of the Stanford CS department's wireless network.file: final.anon.tar.gzdescription: This traceset contains traces of the Stanford CS department's wireless network.measurement purpose: Usage Characterization, User Mobility Characterizationmethodology: We use the common timestamp and MAC address information to combine three traces (tcpdump, SNMP, and authentication logs) into a single trace. The original three traces are not publicly available. sanitization: We have anonymized the user and remote host names for privacy reasons. stanford/gates/combined Tracesanon: This trace contains traces of the Stanford CS department's wireless network.configuration: We use the common timestamp and MAC address information to combine these three traces (tcpdump, SNMP, and authentication logs) into a single trace with a total of 78,739,933 packets attributable to the 74 wireless users. An additional 37,893,656 packets are attributable to the SNMP queries and 1,551,167 packets are attributable to the four wired users. The number of packets attributable to the SNMP queries might seem high, but each access point is queried every two minutes even if no laptops are actively generating traffic. format: [time] [pkt size] [username] [access point loc] [app] [dir] [remote host]dir is the direction -- incoming or outgoing or both(i.e., internal, or neither i.e.,dhcp hadn't really gotten its act together yet).app will be a dotted port number (src/dst)if it's not recognized.time is at second granularity.pkt size is in bytes.note: Note that because we do not record any signal strength information, and since our access points generally cover a whole wing of a floor, we cannot necessarily detect movement within a wing but only movement between access points.

本数据集包含斯坦福大学计算机科学系无线网络的流量追踪数据。测量开始日期/时间:1999-09-20;测量结束日期/时间:1999-12-12。 ### 采集环境 我们采集了斯坦福大学盖茨计算机科学大楼内全覆盖的局域网无线网络的12周流量追踪数据。该大楼呈L形(长边称为A翼,短边称为B翼),共设有四层主楼层(配备办公室与实验室)、一层地下室(配备教室与实验室)以及五层阁楼(配备休闲区与少量办公室)。每层主楼层均设有两个接入点,分别服务对应翼楼。此外,一层设有服务于大型会议室的接入点;横跨二、三层的图书馆亦设有接入点。地下室设有两个接入点,一个紧邻教室区域,另一个服务于互动实验室(该实验室为该系的专项研究项目)。面积较小的五层阁楼仅设有一个接入点。 无线用户社区共有74名用户,大致可分为四组: 1. 35名一年级博士生:入学时(即本流量追踪启动时刻)每人配备搭载WaveLAN网卡的笔记本电脑,其办公室主要集中在2B翼楼。 2. 22名图形学方向学生与教职工:其中多数在流量追踪启动一周后获得搭载WaveLAN网卡的笔记本电脑,其办公室主要集中在3B翼楼。 3. 3台机器人:由机器人实验室用于研究工作。机器人无需认证即可接入外部网络,尽管具备一定移动性,但通常仅在1A翼楼活动。尽管这些WaveLAN网卡原本为机器人配备,但机器人实验室的学生也会使用该网卡进行会话连接与网页浏览。 4. 14名其他用户(学生、教职工与教员):分散在大楼各处。 除上述74名无线用户外,另有4名用户完成了身份认证,但仅连接至公共子网的有线端口而非无线网络,本无线网络分析中将不纳入该类用户。 ### 网络配置 在斯坦福大学盖茨计算机科学大楼内,管理员为所有隶属于该校的用户开放了“公共”子网。用户若需通过该子网获取网络访问权限,必须完成身份认证,以获取动态分配的IP地址,进而访问系内、大学校园网络及互联网。该子网既可通过无线网络访问,也可通过大楼内公共场所(如会议室、休闲区、图书馆与实验室)的以太网端口接入。 本无线网络为WaveLAN网络,采用WavePoint II接入点作为无线网络与有线网络的桥接设备。每个接入点均设有两个无线网络接口插槽:两个插槽均已启用,其一搭载老旧的2 Mbps网卡,以服务尚未更新硬件的少量用户;另一插槽搭载兼容IEEE802.11标准的10 Mbps WaveLAN网卡。 由于所有无线用户均处于同一子网(无需移动IP或其他类似技术即可实现漫游),我们在连接公共子网与系内其余有线网络的路由器上采集流量追踪数据。该路由器为搭载RedHat Linux系统的90 MHz Pentium设备,配备两个10 Mbps网络接口:一个接口连接公共子网,另一个接口连接系内网络。 ### 数据采集方法 为获取所需的全部信息,我们在涵盖1999年秋季学期(1999年9月20日周一至12月12日周日)的12周周期内,采集了三类独立的流量追踪数据: 1. TCPDUMP追踪:采集流经该路由器的所有数据包的链路层与网络层头部信息。我们将结合该追踪数据与另外两类追踪数据进行分析。 2. 简单网络管理协议(Simple Network Management Protocol, SNMP)追踪:路由器每隔约两分钟通过以太网轮询所有12个接入点,获取当前通过该接入点作为桥接设备接入有线网络的主机的媒体访问控制(Media Access Control, MAC)地址。一旦获知某MAC地址所使用的接入点,即可确定该设备的大致位置(楼层与翼楼)。我们将这些MAC地址与TCPDUMP追踪中保存的链路层地址进行匹配,以确定TCPDUMP追踪中各主机的大致位置。SNMP追踪的开销较低:每两分钟轮询全部12个接入点的平均开销为530个数据包或50 KB。单个接入点的轮询开销为:若无用户使用该接入点,开销为3.2 KB;若有用户使用,则基础开销为14.5 KB(对应1名用户),每新增1名用户额外增加1 KB开销。 3. 认证日志:记录所有请求网络访问权限的用户信息,每条日志均包含用户登录名与发起请求的MAC地址。我们将这些MAC地址与TCPDUMP追踪中保存的链路层地址进行匹配,以确定每个数据包对应的发送用户。 ### 数据脱敏 我们已获得系主任许可开展本流量追踪工作,并已告知所有网络用户本次追踪活动。此外,我们还告知用户仅会记录数据包头部信息(而非数据包内容),且会对数据进行匿名化处理。知晓本次追踪活动可能会对用户行为产生扰动,但我们无法量化该影响的具体程度。 ### stanford/gates/combined Traceset 本追踪集包含斯坦福大学计算机科学系无线网络的流量追踪数据。 文件:final.anon.tar.gz 描述:本追踪集包含斯坦福大学计算机科学系无线网络的流量追踪数据。 测量目的:使用特征刻画、用户移动性特征刻画 采集方法:我们通过公共时间戳与MAC地址信息,将三类追踪数据(TCPDUMP、SNMP与认证日志)整合为单一流水线追踪数据。原始三类追踪数据未公开。 脱敏处理:出于隐私保护考虑,我们已对用户与远程主机名称进行匿名化处理。 ### stanford/gates/combined Tracesanon 本追踪集包含斯坦福大学计算机科学系无线网络的流量追踪数据。 配置:我们通过公共时间戳与MAC地址信息,将三类追踪数据(TCPDUMP、SNMP与认证日志)整合为单一流水线追踪数据,其中共计78,739,933个数据包可归因于74名无线用户,另有37,893,656个数据包归因于SNMP轮询请求,1,551,167个数据包归因于4名有线用户。尽管SNMP轮询产生的数据包数量看似较高,但即便无笔记本电脑主动生成流量,接入点仍会每两分钟被轮询一次。 格式:"[time] [pkt size] [username] [access point loc] [app] [dir] [remote host]" 其中: - `dir`为数据包传输方向:入站、出站或双向(即内部流量,或无明确方向——彼时动态主机配置协议(Dynamic Host Configuration Protocol, DHCP)尚未完善)。 - 若无法识别应用类型,则`app`以`源端口/目的端口`的点分格式表示。 - `time`精确到秒级。 - `pkt size`以字节为单位。 备注:由于我们未记录任何信号强度信息,且接入点通常覆盖整层楼的一个翼楼,因此我们无法检测翼楼内部的移动,仅能识别接入点之间的移动。

创建时间:
2023-06-28
二维码
社区交流群
二维码
科研交流群
商业服务