UKMDDoSDN: A DDoS Attacks Dataset for Software-Defined Networks
收藏资源简介:
The UKMDDoSDN dataset is a comprehensive benchmark designed to advance research in Distributed Denial-of-Service (DDoS) attack detection within Software-Defined Networks (SDNs). It supports multi-attack dataset generation, including SYN flood (1), UDP flood (2), and ICMP flood (3) attacks, alongside normal benign traffic (0), providing a diverse and realistic mix of network traffic. Built on a realistic enterprise network topology, the architecture consists of four isolated subnets: an External Network (h1: 192.168.10.x), a Corporate Internal Network (h2-h5: 192.168.20.x), a Server/DMZ Network (h6: 192.168.30.x), and a Management Network (C0: 192.168.0.x), ensuring proper segmentation and accurate representation of enterprise environments. UKMDDoSDN produces three complementary CSV datasets, , captured simultaneously to support multi-perspective analysis: 1. packet_features.csv, a packet-level dataset optimized for real-time detection; 2. flow_features.csv, containing flow-level statistical features extracted from the SDN controller; and 3. cicflow_features.csv, offering advanced flow-based features generated using CICFlowMeter. In addition to the CSV datasets, raw PCAP files are provided, allowing for deep packet inspection, custom feature extraction, and traffic replay for extended experimentation. The dataset was generated in batch mode over approximately 52 hours, ensuring sufficient volume and diversity for robust model training and evaluation. Leveraging the Ryu SDN controller, it enables intelligent traffic management and realistic attack simulations. With high-quality labeling for both multi-class (0–3) and binary (0–1) classification, UKMDDoSDN provides a versatile and practical resource for intrusion detection, traffic analysis and network security research in SDN environments.
UKMDDoSDN数据集是一款综合性基准数据集,旨在推动软件定义网络(Software-Defined Networks, SDN)内分布式拒绝服务(Distributed Denial-of-Service, DDoS)攻击检测领域的研究进展。该数据集支持多类型攻击数据集生成,涵盖SYN泛洪(1)、UDP泛洪(2)与ICMP泛洪(3)三类攻击,同时包含正常良性流量(0),可提供多样化且贴合实际的网络流量组合。 数据集基于真实企业网络拓扑构建,整体架构包含四个隔离子网:外部网络(h1: 192.168.10.x)、企业内部网络(h2-h5: 192.168.20.x)、服务器/隔离区(DMZ)网络(h6: 192.168.30.x)以及管理网络(C0: 192.168.0.x),可实现合理的网络分段,精准还原企业网络环境。 UKMDDoSDN可生成三类互补的CSV格式数据集,同步采集以支持多视角分析: 1. packet_features.csv:面向数据包级的数据集,优化用于实时攻击检测; 2. flow_features.csv:包含从SDN控制器提取的流级统计特征; 3. cicflow_features.csv:提供基于CICFlowMeter生成的高级流特征。 除上述CSV格式数据集外,还提供原始PCAP文件,支持深度数据包检测、自定义特征提取以及流量重放等拓展实验。 该数据集采用批量模式生成,耗时约52小时,可生成足够规模且多样的流量数据,以支撑稳健的模型训练与评估工作。本数据集依托Ryu SDN控制器实现智能流量管理与贴合实际的攻击模拟。 凭借针对多分类(0–3)与二分类(0–1)任务的高质量标注,UKMDDoSDN可为软件定义网络环境下的入侵检测、流量分析与网络安全研究提供一款通用且实用的优质资源。




