Cybersecurity dataset of water distribution plant communications under replay attacks
收藏资源简介:
This dataset documents replay attacks targeting MQTT communications in a water distribution level control system. The attacks affect both directions of communication independently: Replaying historical control commands sent from the PC to the plants Replaying historical process parameter messages sent from the plants to the PC When a message arrives at the broker during an active attack campaign, a replay sequence is triggered, causing between 1 and 20 previously recorded messages of the same type to be resent. Replayed messages are selected randomly from historical data and preserve the original sampling time, producing syntactically valid but temporally inconsistent traffic. The dataset includes original and replayed messages, enabling temporal sequence analysis and comparison. Attack campaigns have variable durations and are separated by cooldown periods, reflecting realistic attack execution patterns. Acknowledgements This activity is carried out in execution of the Strategic Project "Critical infrastructures cybersecure through intelligent modeling of attacks, vulnerabilities and increased security of their IoT devices for the water supply sector" (C061/23), the result of a collaboration agreement signed between the National Institute of Cybersecurity (INCIBE) and the University of A Coruña. This initiative is carried out within the framework of the funds of the Recovery, Transformation and Resilience Plan, financed by the European Union (Next Generation), the project of the Government of Spain that outlines the roadmap for the modernization of the Spanish economy, the recovery of economic growth and job creation, for the solid, inclusive and resilient economic reconstruction after the COVID19 crisis, and to respond to the challenges of the next decade.



