遇见数据集

Dataset of intrusion detection alerts from a sharing platform

收藏
Mendeley Data2019-06-10 更新2026-04-09 收录
官方服务:

资源简介:

The dataset consists of the main file with the intrusion detection alerts and four auxiliary files with enriched data. The alerts were collected from the SABU alert sharing platform for one week and are stored in the IDEA format. Almost 12 million alerts were collected from 34 intrusion detection systems, honeypots, and other data sources deployed in 3 distinct organizations. The IP addresses, hostname, URLs, and other identifiers in the alerts are anonymized, but the information in the auxiliary files allow for the profiling of malicious actors. The auxiliary files contain information on over 1.7 million IP addresses contained in the alerts, the most frequent identifiers of attackers and victims of observed events. Reputation scores, geolocation, and data from PassiveDNS system are provided. The reputation scores include information on the presence of the IP addresses on publicly available blacklists or results of scans by Internet-wide scanners. The geolocation provides the approximate geographical locations of the IP addresses; a data layer for a common geographical information system is provided. The PassiveDNS data are in the form of a feature vector of domain names the IP addresses were translated to in the time of their involvement in malicious activities. The list of files goes as follow: dataset.idea.zip - compressed dataset.idea file with the alerts in IDEA format, one alert per line, Aux_1A_Geolocation-csv - CSV file with geolocation information, Aux_1B_GIS_data.zip - compressed archive of spatial data for use with a geographical information system ArcGIS, Aux_2_Passive_DNS - CSV file with characteristics of DNS records for the IP addresses in the data obtained via PassiveDNS system, Aux_3_Enrichment - compressed archive of various other enrichments of IP addresses, splitted per days, see README in the archive.

本数据集包含一份存储入侵检测告警的主文件,以及四份附带增强数据的辅助文件。本次采集的告警来自SABU告警共享平台,采集周期为一周,均以IDEA格式存储。本次共从部署于3家不同机构的34台入侵检测系统、蜜罐及其他数据源中,采集得到近1200万条告警。告警中的IP地址、主机名、URL及其他标识符均已完成匿名化处理,但辅助文件中的信息可用于构建恶意行为者的行为画像。 辅助文件涵盖了告警中出现的超170万个IP地址的相关信息,包含观测到的攻击事件中最频繁出现的攻击者与受害者标识符。其中提供了信誉评分、地理定位信息以及被动DNS(PassiveDNS)系统采集的数据:信誉评分包含IP地址是否存在于公开可用黑名单中,或是互联网范围扫描器的扫描结果相关信息;地理定位信息可提供IP地址的近似地理位置,同时附带了适配通用地理信息系统的空间数据图层;被动DNS数据以特征向量的形式呈现,记录了IP地址在参与恶意活动期间所解析到的域名信息。 数据集包含的文件如下: 1. dataset.idea.zip:存储IDEA格式告警的压缩数据集文件,每行存储一条告警; 2. Aux_1A_Geolocation-csv:存储地理定位信息的CSV文件; 3. Aux_1B_GIS_data.zip:适配ArcGIS地理信息系统的空间数据压缩归档文件; 4. Aux_2_Passive_DNS:通过被动DNS系统获取的、对应数据集中IP地址的DNS记录特征CSV文件; 5. Aux_3_Enrichment:按日期拆分的各类IP地址增强信息压缩归档文件,详细说明请参阅归档内的README文件。

创建时间:
2019-06-10
二维码
社区交流群
二维码
科研交流群
商业服务