UKMDDoSDN: A DDoS Attacks Dataset for Software-Defined Networks
收藏NIAID Data Ecosystem2026-05-10 收录
下载链接:
https://data.mendeley.com/datasets/43nfv26gpk
下载链接
链接失效反馈官方服务:
资源简介:
The UKMDDoSDN dataset is a comprehensive benchmark designed to advance research in Distributed Denial-of-Service (DDoS) attack detection within Software-Defined Networks (SDNs). It supports multi-attack dataset generation, including SYN flood (1), UDP flood (2), and ICMP flood (3) attacks, alongside normal benign traffic (0), providing a diverse and realistic mix of network traffic. Built on a realistic enterprise network topology, the architecture consists of four isolated subnets: an External Network (h1: 192.168.10.x), a Corporate Internal Network (h2-h5: 192.168.20.x), a Server/DMZ Network (h6: 192.168.30.x), and a Management Network (C0: 192.168.0.x), ensuring proper segmentation and accurate representation of enterprise environments.
UKMDDoSDN produces three complementary CSV datasets, , captured simultaneously to support multi-perspective analysis:
1. packet_features.csv, a packet-level dataset optimized for real-time detection;
2. flow_features.csv, containing flow-level statistical features extracted from the SDN controller; and
3. cicflow_features.csv, offering advanced flow-based features generated using CICFlowMeter.
In addition to the CSV datasets, raw PCAP files are provided, allowing for deep packet inspection, custom feature extraction, and traffic replay for extended experimentation.
The dataset was generated in batch mode over approximately 52 hours, ensuring sufficient volume and diversity for robust model training and evaluation. Leveraging the Ryu SDN controller, it enables intelligent traffic management and realistic attack simulations. With high-quality labeling for both multi-class (0–3) and binary (0–1) classification, UKMDDoSDN provides a versatile and practical resource for intrusion detection, traffic analysis and network security research in SDN environments.
创建时间:
2025-10-03



