遇见数据集

Supplementary dataset: A digital twin and SOAR-based cyber resilience testbed for smart ships

收藏
Zenodo2026-06-15 更新2026-06-17 收录
官方服务:

资源简介:

Supplementary dataset: A digital twin and SOAR-based cyber resilience testbed for smart ships This record contains the demonstration video and experimental data supporting the manuscript: J.-K. Lim, H.-S. Song, J.-W. Kim, and Y.-H. Choi, "A Digital Twin and SOAR-based Cyber Resilience Testbed for Smart Ships," submitted to IEEE Access, 2026. Funding: Institute of Information & Communications Technology Planning & Evaluation (IITP) grant funded by the Korea government (MSIT) (No. RS-2024-00400955, Development of core security technology to respond to international smart ship regulations). CONTENTS- blackhawk_demo_video.mp4 — Recorded demonstration of the BLACK HAWK digital twin security-monitoring dashboard (84 s, 1280x720). Shows real-time ECDIS visualization, alarm history, and attack-detection overlay corresponding to Fig. 6 of the manuscript. A live interactive instance is additionally available at https://koreanregister.dev-timmanage.com/ (availability not guaranteed long-term; this archived video is the permanent record).- malware_corpus_sha256.csv — The 111-sample malware corpus used in detection Track 2 (Section V-A): SHA-256 hash, file type, category (53 trojan / 6 phishing / 52 ransomware), and per-sample detection outcome (105 detected / 6 missed). Hashes only — no malware binaries are distributed. Samples can be retrieved from public malware repositories (e.g., VirusTotal, MalwareBazaar) by hash.- e2e_pipeline_stage_timings_ms.csv — Stage-level timings (n = 40) for the end-to-end event-to-visualization pipeline (TABLE 5): detection-to-SOAR-trigger and trigger-to-isolation, in milliseconds. The attack-event-to-detection stage coincided with injection at the 1-second log resolution of the SIEM in all 40 trials.- isolation_path_timings_ms.csv — Per-execution timings (n = 100) for the three parallel network-isolation paths — FW Deny (FortiGate), EMS Deny (FortiClient EMS / FortiEDR), FSW Port Down (FortiSwitch) — in milliseconds (TABLE 9), with per-execution playbook completion (slowest path).- playbook_execution_timings_ms.csv — Per-execution completion times (n = 100 per playbook, 500 total) for the five maritime-specific SOAR playbooks (TABLE 8), in milliseconds.- README.md — This description, included as a file. NOTES ON METHODOLOGY- Detection Track 1: a trial is counted as detected if FortiSIEM or CEREBRO-XTD raised an alert correlated to the injected instance within 60 s of injection. Result: 40/47 detected (85.1%). Per-trial injection records for Track 1 were not retained; Track 1 detection outcomes are therefore reported in aggregate only.- Detection Track 2: a sample is counted as detected if the endpoint protection platform raised a detection alarm upon ZIP-archive extraction. Result: 105/111 detected (94.6%). Per-sample outcomes are provided in malware_corpus_sha256.csv.- All timing trials were spaced at least 60 s apart with a clean state reset between batches. See Section V-A of the manuscript for the full protocols and statistical methods. LICENSEData files (CSV) and demonstration video: Creative Commons Attribution 4.0 International (CC BY 4.0). CONTACTCorresponding author: Yoon-Ho Choi (yhchoi@pusan.ac.kr), Pusan National University.Dataset curation: Jeoung-Kyu Lim, Korean Register.

提供机构:
Zenodo
创建时间:
2026-06-15
二维码
社区交流群
二维码
科研交流群
商业服务