遇见数据集

Beyond Bots: Identifying Human-Driven SSH Intrusions in the Wild

收藏
Zenodo2026-04-17 更新2026-05-29 收录
官方服务:

资源简介:

This dataset contains SSH session logs collected using a high-interaction deception system based on Cowrie operating in proxy mode. The deployment was active for approximately eight months (July 2025 – March 2026) and captured real-world attacker interactions after successful authentication. To increase realism and reduce noise from large-scale automated login attempts, the system forwards sessions to isolated backend environments and applies adaptive credential filtering. The dataset includes raw session data. Each session is represented as a sequence of executed commands together with metadata such as timestamps, and session identifiers. To enable reproducible analysis while protecting attacker privacy, IP addresses were anonymised prior to dataset release. Each unique source IP was assigned a stable numeric identifier (attacker_00001 … attacker_03479). The mapping is deterministic and consistent across all sessions — sessions originating from the same IP share the same pseudonymous identifier, preserving within-attacker session linkability without exposing the original addresses. The dataset is intended to support research on attacker behavior in SSH environments, including the distinction between automated and human-driven activity, behavioral clustering, anomaly detection, and the evaluation of deception systems. Due to the absence of ground truth labels, the provided behavioral indicators should be interpreted as heuristic signals rather than definitive classifications. Each session JSON contains the following fields: - session_id — unique 12-character hex identifier for the session - attacker_id — replacing the original attacker_ip field - country — 2-letter country code of the attacker - session_type — type of session (e.g. Full) - start_time — ISO 8601 timestamp of when the session began - end_time — ISO 8601 timestamp of when the session ended - total_commands — number of commands entered in the session - commands — list of command objects, each containing: - timestamp — exact time the command was entered - input — the raw command string as typed by the attacker - raw_eventid — Cowrie event type (e.g. cowrie.command.input) The attacker_ip field has been removed from this release for anonymization.

提供机构:
Zenodo
创建时间:
2026-04-16
二维码
社区交流群
二维码
科研交流群
商业服务