africa-apt-espionage
收藏资源简介:
该数据集是一个合成的网络威胁情报数据集,专门用于模拟针对非洲19个国家的网络间谍活动和国家级高级持续性威胁(APT)行动。背景源于非洲日益成为网络间谍活动的重要战场,涉及全球主要大国和商业间谍软件供应商对非洲政府、电信、矿业和公民社会的针对性攻击。数据集建模了包括Lazarus(朝鲜)、APT41(中国)、APT28(俄罗斯)、Sidewinder(印度)、OilRig(伊朗)以及Mustang Panda、BackdoorDiplomacy、Turla等多个知名APT组织,同时也包含国内监控行为体和商业间谍软件(如NSO集团的Pegasus)的活动。数据规模为10,000行,正负样本平衡(APT攻击标记为1,合法活动标记为0),所有记录均为基于真实世界研究报告生成的合成数据(is_synthetic=1)。数据集以表格形式呈现,包含丰富的特征列,详细描述了每次事件的攻击属性(如目标国家、APT组织、归属国家、目标行业、攻击向量、恶意软件家族、战略目标)、技术复杂性指标(如MITRE ATT&CK战术数量、是否使用零日漏洞、自定义恶意软件、无文件攻击等)、攻击影响(如系统失陷数量、数据泄露量、财务损失、国家安全影响、外交事件)以及检测与响应情况(如是否被检测、检测时间、响应激活)。此外,README还提及了可从原始特征中提取的衍生特征,例如复杂度评分、隐身性指标、持久性指标、影响严重性评分、检测成熟度评分,以及对APT组织、归属国、目标行业、攻击向量等的独热编码表示。该数据集适用于表格分类任务,旨在支持网络安全研究、威胁情报分析、APT攻击检测模型开发以及针对非洲地缘政治网络威胁的风险评估。数据来源基于INTERPOL、卡巴斯基、Mandiant、ESET、Recorded Future、Citizen Lab、Amnesty International和MITRE ATT&CK等机构在2024-2025年发布的关于非洲网络威胁的公开报告和研究。
This dataset is a synthetic cyber threat intelligence (CTI) dataset specifically designed to simulate cyber espionage and state-sponsored advanced persistent threat (APT) campaigns targeting 19 countries in Africa. The background stems from the fact that Africa has increasingly become a critical battlefield for cyber espionage, with targeted attacks against African governments, telecommunications, mining, and civil society sectors carried out by major global powers and commercial spyware vendors. The dataset models multiple well-known APT groups including Lazarus (Democratic People's Republic of Korea), APT41 (People's Republic of China), APT28 (Russian Federation), Sidewinder (India), OilRig (Iran), Mustang Panda, BackdoorDiplomacy, and Turla, as well as the activities of domestic monitoring actors and commercial spyware such as Pegasus by the NSO Group. The dataset has a scale of 10,000 rows with balanced positive and negative samples (APT attacks are labeled as 1, while legitimate activities are labeled as 0). All records are synthetic data generated based on real-world research reports (is_synthetic=1). Presented in tabular format, the dataset includes a rich set of feature columns that comprehensively describe the attack attributes of each incident (e.g., target country, APT group, attributed country, target industry, attack vector, malware family, strategic objectives), technical complexity metrics (e.g., number of MITRE ATT&CK tactics, use of zero-day exploits, custom malware, fileless attacks), attack impacts (e.g., number of compromised systems, data exfiltration volume, financial losses, national security impacts, diplomatic incidents), and detection and response status (e.g., whether detected, detection time, response activation). Additionally, the README mentions derived features that can be extracted from the original features, such as complexity score, stealth metrics, persistence metrics, impact severity score, detection maturity score, as well as one-hot encoding representations for APT groups, attributed countries, target industries, attack vectors, and more. This dataset is suitable for tabular classification tasks, aiming to support cybersecurity research, threat intelligence analysis, APT attack detection model development, and risk assessment of geopolitical cyber threats in Africa. The dataset's sources are based on public reports and research on African cyber threats published in 2024-2025 by institutions including INTERPOL, Kaspersky, Mandiant, ESET, Recorded Future, Citizen Lab, Amnesty International, and MITRE ATT&CK.




