遇见数据集

IDS2025 (Balanced Intrusion Detection Evaluation Dataset)

收藏
Mendeley Data2026-04-18 收录
官方服务:

资源简介:

This dataset, titled IDS2025: Balanced Intrusion Detection Evaluation Dataset, is an enhanced and refined version of the original CICIDS2017 dataset, designed specifically for research and development in Intrusion Detection Systems (IDS). It addresses key limitations identified in a detailed analysis of the CICIDS2017 dataset, including severe class imbalance (e.g., Benign traffic dominating at 83.34%), high data volume leading to processing challenges, scattered attack instances across files, and inconsistencies in labeling. Key Improvements and Features: Class Balancing: Minority classes have been relabeled and merged where appropriate (e.g., combining similar attack variants like DoS subtypes) to reduce imbalance, improving model training efficacy and reducing bias toward dominant classes like Benign. The resulting distribution aims for a more equitable representation, with prevalence ratios adjusted from extremes like 0.0009% for rare attacks to more balanced levels. Data Volume Optimization: Redundant or low-value instances were resampled or removed, resulting in a more manageable size while preserving essential network traffic patterns. The dataset retains approximately [insert approximate total instances, e.g., 2,830,540 based on original, adjusted post-processing] records across merged classes. Attack Coverage: Includes a comprehensive set of real-world attack scenarios captured from simulated network environments, such as DoS/DDoS (e.g., Hulk, GoldenEye, Slowloris), Brute Force (FTP/SSH), Web Attacks (XSS, SQL Injection), Infiltration, Botnet, PortScan, and Heartbleed. Attacks are now more uniformly distributed across files for easier access and analysis. Features: Comprises 80 network flow features (e.g., flow duration, packet lengths, flags, protocols like HTTP, HTTPS, SSH), extracted using tools like CICFlowMeter, ensuring compatibility with machine learning frameworks for IDS model development. File Structure: Organized into daily CSV files (e.g., Monday-WorkingHours.csv to Friday-WorkingHours.csv) with labeled benign and attack traffic, facilitating chronological analysis of network behavior over a 5-day period. This dataset is ideal for cybersecurity researchers, machine learning practitioners, and IDS developers seeking a benchmark resource for evaluating anomaly detection, classification algorithms, and defensive strategies against modern cyber threats. It supports tasks like binary/multiclass classification, with improved suitability for imbalanced learning techniques. Cite: Panigrahi, R., & Borah, S. (2018). A detailed analysis of CICIDS2017 dataset for designing Intrusion Detection Systems. International Journal of Engineering & Technology, 7(3.24), 479-482. Iman Sharafaldin, Arash Habibi Lashkari, and Ali A. Ghorbani, “Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization”, 4th International Conference on Information Systems Security and Privacy (ICISSP), Portugal, January 2018.

本数据集命名为IDS2025:平衡型入侵检测评估数据集,是原始CICIDS2017数据集的增强精炼版本,专为入侵检测系统(Intrusion Detection Systems,简称IDS)的研发与研究工作设计。该数据集针对学界对CICIDS2017数据集的详细分析中发现的多项核心局限进行了优化,包括严重的类别不平衡问题(例如良性流量占比高达83.34%)、数据体量过大导致处理难度较大、攻击样本分散存储于多个文件以及标注不一致等问题。 核心改进与特性: 1. 类别平衡:对少数类样本进行了合理的重标注与合并操作(例如将类似的攻击变体如拒绝服务(Denial of Service, DoS)子类型进行合并),以降低类别不平衡程度,提升模型训练效果并减少对良性流量这类占主导地位类别的预测偏差。最终的类别分布力求实现更公平的样本占比,将稀有攻击样本的占比从极端的0.0009%调整至更为平衡的水平。 2. 数据体量优化:对冗余或低价值样本进行了重采样或移除操作,在保留核心网络流量特征的前提下,将数据集规模调整至更易于处理的范围。经合并后的数据集总样本量约为[插入近似总样本量,例如基于原始数据集经后处理调整后的2,830,540条记录]。 3. 攻击覆盖范围:涵盖了从模拟网络环境中捕获的多类真实攻击场景,包括DoS/DDoS攻击(如Hulk、GoldenEye、Slowloris)、暴力破解攻击(FTP/SSH)、Web攻击(跨站脚本(Cross-Site Scripting, XSS)、SQL注入)、渗透攻击、僵尸网络、端口扫描以及心脏滴血(Heartbleed)漏洞攻击。当前攻击样本已在各文件中实现更均匀的分布,便于访问与分析。 4. 特征集:包含80项网络流特征(例如流持续时间、数据包长度、标记位、HTTP、HTTPS、SSH等协议),这些特征通过CICFlowMeter工具提取,可兼容用于入侵检测系统模型开发的各类机器学习框架。 5. 文件结构:按日期组织为多个CSV文件(例如Monday-WorkingHours.csv至Friday-WorkingHours.csv),文件中包含标注后的良性与攻击流量,便于对5天内的网络行为进行时序分析。 本数据集非常适合网络安全研究人员、机器学习从业者以及入侵检测系统开发者使用,可作为评估异常检测、分类算法以及应对现代网络威胁的防御策略的基准资源。其支持二分类/多分类任务,更适配不平衡学习相关技术的应用场景。 引用文献: Panigrahi, R., & Borah, S. (2018). 面向入侵检测系统设计的CICIDS2017数据集详细分析. 国际工程与技术期刊, 7(3.24), 479-482. Iman Sharafaldin, Arash Habibi Lashkari, 及 Ali A. Ghorbani, "面向新型入侵检测数据集构建与入侵流量特征表征", 第4届信息系统安全与隐私国际会议(ICISSP), 葡萄牙, 2018年1月.

创建时间:
2025-11-19
二维码
社区交流群
二维码
科研交流群
商业服务