iobhunter_open_dataset.vtclean.csv
收藏资源简介:
该数据集包含用于论文的部分FP案例,这些案例由第三方(VirusTotal、Spamhaus、URLhaus、Abuse.ch)检测,并被第三方翻转为良性(即也被第三方视为FP)。每个案例包含五个字段:实体(FP域名)、接受状态(始终为yes)、检测日期、处理日期和VirusTotal评分(始终为0)。
This dataset contains partial false positive (FP) cases for academic papers. These cases were first detected by third-party platforms including VirusTotal, Spamhaus, URLhaus, and Abuse.ch, and were subsequently reclassified as benign by these same platforms, which also confirms that these parties identified these cases as false positives. Each case includes five fields: the entity (FP domain name), acceptance status (always "yes"), detection date, processing date, and VirusTotal score (always 0).
数据集概述
数据集基本信息
- 数据集名称:iobhunter-dataset
- 关联论文:Indicator of Benignity: An Industry View of False Positive in Malicious Domain Detection and its Mitigation
- 论文发表会议:Network and Distributed System Security (NDSS) Symposium 2026
- 数据来源:Palo Alto Networks 研究人员处理的误报案例
- 数据文件:
iobhunter_open_dataset.vtclean.csv
数据集内容说明
- 数据性质:该数据集是论文所用误报数据集的一部分,包含被第三方安全情报源(VirusTotal, Spamhaus, URLhaus, Abuse.ch)检测为恶意,但随后被第三方翻转为良性的域名(即也被第三方认为是误报)。
- 数据限制:
- 仅包含由第三方情报源检测到的误报案例。
- 不包含用户提交的误报报告中的评论,因其可能涉及敏感或个人身份信息。
数据格式
数据文件 iobhunter_open_dataset.vtclean.csv 为CSV格式,每行代表一个报告的误报案例,包含以下五个字段:
- entity:被第三方检测到的完全限定域名(FQDN),即误报域名。
- accepted:固定为
yes,表示被Palo Alto Networks研究人员接受为真实误报。 - detection_date:该FQDN被检测到的日期。
- cr_date:报告的FQDN被Palo Alto Networks研究人员处理的日期。
- vt_score:固定为
0,表示在数据集编译时(2025年12月02日)VirusTotal检测为清洁。
数据注意事项
- 重复条目:部分实体存在重复条目,这是由于同一实体有多个误报变更请求(CR)所致。这些重复的误报CR大多在Palo Alto Networks研究人员接受或拒绝前的24小时内(少数在3天内)报告。这些重复的CR具有相同的
cr_date,即报告实体验证结果被翻转的日期。
引用信息
如需引用,请使用以下BibTeX条目:
@article{liu2025iobhunter, title={Indicator of Benignity: An Industry View of False Positive in Malicious Domain Detection and its Mitigation}, author={Liu, Daiping and Sun, Danyu and Chen, Zhenhua and Wang, Shu and Li, Zhou}, journal={Network and Distributed System Security (NDSS) Symposium}, year={2026} }




