遇见数据集

CRAWDAD gatech/fingerprinting

收藏
Mendeley Data2024-01-31 更新2024-06-28 收录
官方服务:

资源简介:

Fingerprinting of wireless devices exploiting information leaked due to different device hardware compositions: Inter-Arrival-Time (IAT) of packets from wireless devices.In these datasets, we present the the inter-arrival time information collected actively and passively from different wireless devices using wire-side observations in a local network. The captures were collected from 30 wireless devices including iPads, iPhones, Kindles, Google-Phones, Netbooks, IP Printers, IP Cameras, etc., from various applications and protocols such as Skype, ICMP, SCP, Iperf. Due to heterogeneity in devices (e.g., deterministic hardware and software configurations), time-variant behavior of network traffic stemming from different devices can be used to create unique, reproducible device and device type signatures and to fingerprint devices and their types as explained in A. Selcuk Uluagac, Sakthi V. Radhakrishnan, Cherita Corbett, Antony Baca, and Raheem A. Beyah, A Passive Technique for Fingerprinting Wireless Devices with Wired-side Observations, Proceedings of the IEEE Conference on Communications and Network Security (CNS), October 2013. Further details are available at http://users.ece.gatech.edu/~selcuk/devFingerprinting.htmldate/time of measurement start: 2012-12-01date/time of measurement end: 2013-05-31collection environment: In these datasets, we present the inter-arrival time information, which is the delay between successive packets stemming from the same wireless device as observed on the first hop at a wired segment between the access point (AP) and the final destination in a local network environment. The captures were collected from 30 wireless devices including iPads, iPhones, Kindles, Google-Phones, Netbooks, IP Printers, IP Cameras, etc., from various applications and protocols such as Skype, ICMP, SCP, Iperf. Due to heterogeneity in devices (e.g., deterministic hardware and software configurations), time-variant behavior of network traffic stemming from different devices can be used to create unique, reproducible device and device type signatures as explained in in A. Selcuk Uluagac, Sakthi V. Radhakrishnan, Cherita Corbett, Antony Baca, and Raheem A. Beyah, A Passive Technique for Fingerprinting Wireless Devices with Wired-side Observations, Proceedings of the IEEE Conference on Communications and Network Security (CNS), October 2013. Further details are available at http://users.ece.gatech.edu/~selcuk/devFingerprinting.htmlnetwork configuration: Two automated testbeds were assembled to transmit and record traffic from the wireless devices to the wired segment and vice versa. In the isolated testbed, a control machine was used to send commands to the different devices in the testbed. The device under test was placed in an isolation box to reduce RF leakage and interference. For the campus network testbed, the Access Point and LAN destination were connected to a campus backbone switch. This helped us collect the data under MAC and physical layer interference from other wireless users in proximity (during peak hours).data collection methodology: The data was collected by tcpdump. As traffic from devices are collected, we recorded the packet inter-arrival time (IAT), which measures the delay between successive packets. Furthermore, two generic applications were used to generate traffic in our testbeds. One was Iperf, which was used to generate both TCP and UDP traffic at controlled rates, and the other was Ping. In addition to these, we performed tests using other applications such as secure copy (SCP) and Skype. TCP, SCP, and Skype were allowed to flow at their natural rate, while Ping and UDP were controlled. In our experiments using Ping, we set the rate to 100 pings/second and tested payload sizes of 64 Bytes and 1400 Bytes. For UDP analysis we used two payload sizes, 64 Bytes and 1400 Bytes, and sending rates of 1Mpbs and 8Mbps. Also, note that we classify all the above traffic types as either Active or Passive. Active traffic types are generated from the target in response to a trigger. For ex., pinging a target device will result in ping responses (Active Traffic), which can then be fingerprinted (Active Fingerprinting). The passive traffic types are cases where the target system generates traffic without any trigger, e.g., a computer uploading data to a server. In these cases, the fingerprinting of such traffic is termed as passive fingerprinting. Note that for each protocol/application in our datasets, we only focused on one application/protocol without combining any protocols/applications. We captured more than 400 hours of traffic from 30 devices belonging to a diverse set of device classes including iPads, iPhones, Kindles, Google-Phones, Netbooks, Printers, Cameras, Game Consoles, TVs, etc. from various applications and protocols such as Skype, ICMP, SCP, Iperf.sanitization: The collected traffic data only includes the inter-arrival time of packets. Hence, no sanitation is necessary. note: More information about our study is located at: http://users.ece.gatech.edu/~selcuk/devFingerprinting.html and the following publication: A. Selcuk Uluagac, Sakthi V. Radhakrishnan, Cherita Corbett, Antony Baca, and Raheem A. Beyah, A Passive Technique for Fingerprinting Wireless Devices with Wired-side Observations, in Proceedings of the IEEE Conference on Communications and Network Security (CNS), October 2013.Tracesetgatech/fingerprinting/realtestbedIn this dataset, we present the the inter-arrival time information of successive packets collected actively and passively from different wireless devices using wire-side observations in a real local network environment. Hence, there are two traces in this traceset.measurement purpose: Network Securitymethodology: The Access Point and LAN destination were connected to a campus backbone switch. This helped us collect the data under MAC and physical layer interference from other wireless users in proximity (during peak hours).gatech/fingerprinting/realtestbed Traces gatech/fingerprinting/realtestbed/active: Active traffic types are generated from the target in response to a trigger. For ex., pinging a target device will result in ping responses (Active Traffic), which can then be collected as Active traffic dataset.file: ActiveRealTestbedData.zipconfiguration: The Access Point and LAN destination were connected to a campus backbone switch. This helped us collect the data under MAC and physical layer interference from other wireless users in proximity (during peak hours). More information is at: http://users.ece.gatech.edu/~selcuk/devFingerprinting.htmlformat: Matlab files containing the Inter-arrival time (IAT) information.gatech/fingerprinting/realtestbed/passive: Active traffic types are generated from the target in response to a trigger. For ex., pinging a target device will result in ping responses (Active Traffic), which can then be collected as Active traffic dataset.file: PassiveRealTestbedData.zipconfiguration: The Access Point and LAN destination were connected to a campus backbone switch. This helped us collect the data under MAC and physical layer interference from other wireless users in proximity (during peak hours). More information is at: http://users.ece.gatech.edu/~selcuk/devFingerprinting.htmlformat: Matlab files containing the Inter-arrival time (IAT) information.gatech/fingerprinting/isolatedtestbedIn the isolated testbed, a control machine was used to send commands to the different devices in the testbed. The device under test was placed in an isolation box to reduce RF leakage and interference.measurement purpose: Network Securitymethodology: In these datasets, we present the inter-arrival time information, which is the delay between successive packets stemming from the same wireless device as observed in an isolation box to reduce RF leakage and interference. The captures were collected from wireless devices including iPhones, Netbooks, Nokia-Phones, etc., from various applications and protocols such as Skype, ICMP, SCP, Iperf. gatech/fingerprinting/isolatedtestbed Trace gatech/fingerprinting/isolatedtestbed/isolated: Active traffic types are generated from the target in response to a trigger. For ex., pinging a target device will result in ping responses (Active Traffic), which can then be collected as Active traffic dataset.file: isolatedTestbedData.zipconfiguration: In the isolated testbed, a control machine was used to send commands to the different devices in the testbed. The device under test was placed in an isolation box to reduce RF leakage and interference. More information is at: http://users.ece.gatech.edu/~selcuk/devFingerprinting.htmlformat: Matlab files containing inter-arrival time (IAT) information stemming from wireless devices.

本数据集面向无线设备指纹识别任务,通过利用不同设备硬件组成所泄露的信息,采集无线设备数据包的到达间隔时间(Inter-Arrival-Time, IAT)。本数据集包含通过本地局域网有线侧观测,主动与被动采集的各类无线设备的到达间隔时间信息。 数据采集覆盖30台无线设备,包括iPad、iPhone、Kindle、谷歌手机、上网本、网络打印机、网络摄像头等,涉及Skype、ICMP、SCP、Iperf等多种应用与协议。由于不同设备在硬件与软件配置上存在异构性,不同设备产生的网络流量具有时变特性,可用于生成唯一且可复现的设备及设备类型特征签名,实现设备及其类型的指纹识别,相关方法详见A. Selcuk Uluagac、Sakthi V. Radhakrishnan、Cherita Corbett、Antony Baca与Raheem A. Beyah发表于2013年10月IEEE通信与网络安全会议(IEEE Conference on Communications and Network Security, CNS)的论文《A Passive Technique for Fingerprinting Wireless Devices with Wired-side Observations》。更多详细信息可访问:http://users.ece.gatech.edu/~selcuk/devFingerprinting.html ## 测量时段 测量开始时间:2012-12-01;测量结束时间:2013-05-31 ## 采集环境 本数据集所呈现的到达间隔时间信息,指在本地局域网环境中,于接入点(Access Point, AP)与最终目的地之间的有线网段的首跳位置,观测到的同一无线设备连续数据包之间的时延。数据采集覆盖30台无线设备,包括iPad、iPhone、Kindle、谷歌手机、上网本、网络打印机、网络摄像头等,涉及Skype、ICMP、SCP、Iperf等多种应用与协议。由于不同设备在硬件与软件配置上存在异构性,不同设备产生的网络流量具有时变特性,可用于生成唯一且可复现的设备及设备类型特征签名,相关方法详见上述2013年IEEE CNS会议论文。更多详细信息可访问:http://users.ece.gatech.edu/~selcuk/devFingerprinting.html ## 网络配置 本研究搭建了两套自动化测试平台,用于传输并记录无线设备与有线网段之间的流量(含双向流量)。 1. 隔离测试平台:使用控制机向测试平台内的各类设备发送指令,待测设备放置于隔离箱中以降低射频泄露与干扰。 2. 校园网测试平台:将接入点与局域网目的地连接至校园骨干交换机,可采集到邻近其他无线用户在高峰时段产生的媒体访问控制(Media Access Control, MAC)层与物理层干扰下的流量数据。 ## 数据采集方法 数据通过tcpdump工具采集。在采集设备流量时,我们记录了数据包到达间隔时间(IAT),即连续数据包之间的时延。此外,我们使用两类通用应用生成测试平台的流量:其一为Iperf,用于以可控速率生成TCP与UDP流量;其二为Ping。除此之外,我们还使用安全拷贝(Secure Copy, SCP)与Skype等其他应用开展测试。TCP、SCP与Skype以其自然速率传输流量,而Ping与UDP流量的传输速率可控。在Ping测试中,我们将速率设置为100个ping包/秒,并测试了64字节与1400字节两种载荷大小;在UDP分析中,我们使用了64字节与1400字节两种载荷大小,以及1兆比特每秒(Megabits per second, Mbps)与8Mbps两种发送速率。 需注意,我们将上述所有流量类型划分为主动流量与被动流量两类:主动流量指目标设备响应外部触发而生成的流量,例如向目标设备发送ping请求后收到的ping响应(主动流量),可用于主动指纹识别;被动流量指目标设备无外部触发时自发产生的流量,例如计算机向服务器上传数据时的流量,此类流量的指纹识别称为被动指纹识别。 本数据集针对每个协议/应用仅单独开展测试,未合并多协议/多应用流量。我们共采集了来自30台设备的超过400小时的流量数据,覆盖iPad、iPhone、Kindle、谷歌手机、上网本、打印机、摄像头、游戏主机、电视等多种设备类别,涉及Skype、ICMP、SCP、Iperf等多种应用与协议。 ## 数据脱敏处理 采集的流量数据仅包含数据包到达间隔时间,因此无需进行数据脱敏处理。 ## 补充说明 本研究的更多信息可访问:http://users.ece.gatech.edu/~selcuk/devFingerprinting.html,以及上述2013年IEEE CNS会议论文:A. Selcuk Uluagac, Sakthi V. Radhakrishnan, Cherita Corbett, Antony Baca, and Raheem A. Beyah, A Passive Technique for Fingerprinting Wireless Devices with Wired-side Observations, in Proceedings of the IEEE Conference on Communications and Network Security (CNS), October 2013. --- ### 子数据集1:gatech/fingerprinting/realtestbed 本数据集包含在真实本地局域网环境中,通过有线侧观测主动与被动采集的不同无线设备的连续数据包到达间隔时间信息,包含两类轨迹数据。 - 测量目的:网络安全 - 采集方法:将接入点与局域网目的地连接至校园骨干交换机,可采集到邻近其他无线用户在高峰时段产生的MAC层与物理层干扰下的流量数据。 #### 子目录:gatech/fingerprinting/realtestbed/active 主动流量指目标设备响应外部触发而生成的流量,例如向目标设备发送ping请求后收到的ping响应(主动流量),可作为主动流量数据集进行采集。 - 数据文件:ActiveRealTestbedData.zip - 配置:将接入点与局域网目的地连接至校园骨干交换机,可采集到邻近其他无线用户在高峰时段产生的MAC层与物理层干扰下的流量数据。更多信息可访问:http://users.ece.gatech.edu/~selcuk/devFingerprinting.html - 数据格式:包含到达间隔时间(IAT)信息的Matlab文件。 #### 子目录:gatech/fingerprinting/realtestbed/passive 被动流量指目标设备无外部触发时自发产生的流量,例如计算机向服务器上传数据时的流量。此类流量可作为被动流量数据集进行采集。 - 数据文件:PassiveRealTestbedData.zip - 配置:将接入点与局域网目的地连接至校园骨干交换机,可采集到邻近其他无线用户在高峰时段产生的MAC层与物理层干扰下的流量数据。更多信息可访问:http://users.ece.gatech.edu/~selcuk/devFingerprinting.html - 数据格式:包含到达间隔时间(IAT)信息的Matlab文件。 --- ### 子数据集2:gatech/fingerprinting/isolatedtestbed 在隔离测试平台中,使用控制机向测试平台内的各类设备发送指令,待测设备放置于隔离箱中以降低射频泄露与干扰。 - 测量目的:网络安全 - 采集方法:本数据集所呈现的到达间隔时间信息,指在隔离箱中观测到的同一无线设备连续数据包之间的时延,该隔离箱用于降低射频泄露与干扰。数据采集覆盖包括iPhone、上网本、诺基亚手机等在内的无线设备,涉及Skype、ICMP、SCP、Iperf等多种应用与协议。 #### 子目录:gatech/fingerprinting/isolatedtestbed/isolated 主动流量指目标设备响应外部触发而生成的流量,例如向目标设备发送ping请求后收到的ping响应(主动流量),可作为主动流量数据集进行采集。 - 数据文件:isolatedTestbedData.zip - 配置:在隔离测试平台中,使用控制机向测试平台内的各类设备发送指令,待测设备放置于隔离箱中以降低射频泄露与干扰。更多信息可访问:http://users.ece.gatech.edu/~selcuk/devFingerprinting.html - 数据格式:包含无线设备数据包到达间隔时间(IAT)信息的Matlab文件。

创建时间:
2024-01-31
二维码
社区交流群
二维码
科研交流群
商业服务