africa-maritime-port-cybersecurity
收藏资源简介:
Maritime & Port Cybersecurity (Africa) 是一个专注于非洲海事与港口网络安全领域的合成数据集,属于Africa Cyber Threat Intelligence系列,旨在模拟针对非洲关键海事基础设施(包括港口、船舶及相关系统)的网络攻击场景。非洲拥有38个沿海国家、90多个主要商业港口以及苏伊士运河、几内亚湾等战略要道,年贸易额超万亿美元,但其海事网络安全的脆弱性在2021年南非Transnet勒索软件攻击等事件中暴露无遗。本数据集基于国际海事组织(IMO)、波罗的海国际航运公会(BIMCO)、国际刑警组织(INTERPOL)等权威机构2023-2025年的报告和指南合成,捕捉了非洲各地区(如南非、埃及、吉布提、几内亚湾、东非、北非)特有的攻击模式,例如针对港口管理系统的勒索软件、针对船舶自动识别系统(AIS)和GPS的欺骗攻击、以及对工业控制系统(SCADA/OT)的攻击等。数据集包含10,000条平衡记录(50%为攻击事件,50%为正常活动)。每条记录包含37个原始特征,详细描述了事件发生的国家、具体港口、攻击类型、目标系统、攻击向量、威胁行为者、涉及的船舶与货物类型,以及大量二元指标(如是否影响OT/IT系统、是否造成运营中断、财务损失、安全环境风险、是否与走私或海盗活动关联、检测与响应情况等)和数值指标(如延误时间、损失金额、赎金金额等)。此外,数据集还提供了一系列从原始特征中提取的衍生特征,包括系统目标分类、运营影响等级、财务损失等级、风险严重性、犯罪关联标志、检测与响应有效性评分,以及攻击类型、威胁行为者、船舶类型的独热编码或分类特征。最后,数据集还计算了三个综合评分:maritime_threat_score(威胁严重性综合评分)、economic_impact_score(经济损害综合评分)和maritime_resilience_score(检测与响应弹性综合评分)。该数据集适用于表格分类任务,特别是用于海事网络安全威胁检测、风险建模、影响评估以及相关机器学习模型的训练与验证。
Maritime & Port Cybersecurity (Africa) is a synthetic dataset focused on the African maritime and port cybersecurity domain, part of the Africa Cyber Threat Intelligence series. It aims to simulate cyber attack scenarios targeting Africa's critical maritime infrastructure, including ports, vessels and their associated systems. Africa hosts 38 coastal countries, over 90 major commercial ports, and strategic maritime routes such as the Suez Canal and the Gulf of Guinea, with an annual trade volume exceeding $1 trillion. However, the vulnerability of its maritime cybersecurity was exposed in incidents such as the 2021 ransomware attack on South Africa's Transnet. This dataset is synthesized based on reports and guidelines from authoritative organizations including the International Maritime Organization (IMO), Baltic and International Maritime Council (BIMCO), and International Criminal Police Organization (INTERPOL) for the 2023–2025 period, capturing region-specific attack patterns across African regions such as South Africa, Egypt, Djibouti, the Gulf of Guinea, East Africa, and North Africa. These patterns include ransomware targeting port management systems, spoofing attacks against ship Automatic Identification System (AIS) and GPS, and attacks on industrial control systems (SCADA/OT). The dataset contains 10,000 balanced records, with 50% representing attack events and 50% normal activities. Each record includes 37 original features that comprehensively describe the incident's country of occurrence, specific port, attack type, target system, attack vector, threat actor, involved vessel and cargo types, as well as numerous binary indicators (e.g., 'whether OT/IT systems are affected, whether operational disruption, financial loss, or security environment risk is caused, association with smuggling or piracy activities, detection and response status, etc.') and numerical indicators (e.g., 'delay time, loss amount, ransom amount, etc.'). Additionally, the dataset provides a set of derived features extracted from the original features, including system target classification, operational impact level, financial loss level, risk severity, crime association flag, detection and response effectiveness score, as well as one-hot encoded or categorical features for attack types, threat actors, and vessel types. Finally, the dataset computes three comprehensive scores: maritime_threat_score (comprehensive threat severity score), economic_impact_score (comprehensive economic damage score), and maritime_resilience_score (comprehensive detection and response resilience score). This dataset is suitable for tabular classification tasks, especially for training and validating machine learning models for maritime cybersecurity threat detection, risk modeling, impact assessment, and related research and applications.





