遇见数据集

Real-Time Network Traffic Dataset for IDS

收藏
Zenodo2026-03-09 更新2026-05-26 收录
官方服务:

资源简介:

This dataset contains network traffic generated in a controlled experimental environment designed to study and evaluate machine learning-based Intrusion Detection Systems (IDS). The dataset includes both legitimate network activity and artificially generated attack traffic in order to represent realistic cybersecurity scenarios. Network packets were captured during the experiment using packet monitoring tools and later processed to extract meaningful traffic features. The captured packet data was converted into a structured CSV format to facilitate analysis using machine learning and data mining techniques. The dataset includes several network-related attributes such as source IP address, destination IP address, communication protocol, packet size, TCP flag information, and other statistical traffic characteristics derived from the packet capture. To simulate malicious activity, different types of attack traffic were intentionally generated within the test network. These attacks represent commonly observed intrusion patterns such as SYN flood attacks, ICMP flooding, and port scanning. Conducting the experiments in a controlled setup ensured that both normal and malicious traffic patterns were captured accurately while maintaining realistic network behavior. The dataset can be used for several research and educational purposes, including: • Training and evaluating machine learning models for intrusion detection • Studying anomaly detection techniques in network security • Benchmarking and comparing IDS algorithms • Supporting academic research and teaching in cybersecurity The dataset includes a label column that indicates whether a network traffic instance corresponds to normal activity or malicious behavior. For machine learning purposes, the traffic instances are encoded using binary values. Label values are defined as follows: 0 – Normal traffic: Represents legitimate network activity generated during regular user operations such as browsing, communication, and other benign interactions within the network. 1 – Attack traffic: Represents malicious network activity generated during simulated intrusion scenarios, including SYN flood attacks, ICMP flooding, and port scanning. This binary labeling allows the dataset to be used directly for supervised machine learning algorithms designed for binary classification tasks in intrusion detection systems. This dataset has been publicly released to encourage further research and development in the field of network security and to assist researchers in designing more effective intrusion detection systems.

本数据集包含于受控实验环境中生成的网络流量,旨在研究与评估基于机器学习的入侵检测系统(Intrusion Detection Systems, IDS)。数据集涵盖合法网络活动与人工生成的攻击流量,以还原真实的网络安全场景。 实验过程中,研究人员通过数据包监控工具捕获网络数据包,后续对其进行处理以提取具有分析价值的流量特征。捕获的数据包数据被转换为结构化的CSV格式,以方便使用机器学习与数据挖掘技术开展分析。数据集包含多项与网络相关的属性,例如源IP地址、目的IP地址、通信协议、数据包大小、TCP标记信息,以及从数据包捕获中衍生的其他流量统计特征。 为模拟恶意活动,研究人员在测试网络中主动生成多种类型的攻击流量。这些攻击涵盖了常见的入侵模式,如SYN泛洪攻击、ICMP泛洪攻击与端口扫描。在受控环境中开展实验,可确保准确捕获正常与恶意流量模式的同时,维持真实的网络运行行为。 本数据集可用于多项研究与教学场景,包括: • 训练与评估用于入侵检测的机器学习模型 • 研究网络安全领域的异常检测技术 • 对入侵检测系统算法进行基准测试与对比 • 支撑网络安全领域的学术研究与教学工作 数据集包含一列标签,用于标识网络流量样本属于正常活动还是恶意行为。针对机器学习应用需求,流量样本采用二值化编码方式进行标注。 标签的定义如下: 0 – 正常流量:代表常规用户操作中产生的合法网络活动,例如网络浏览、通信及其他良性网络交互行为。 1 – 攻击流量:代表模拟入侵场景中生成的恶意网络活动,包括SYN泛洪攻击、ICMP泛洪攻击与端口扫描。 这种二分类标注方式使得本数据集可直接应用于入侵检测系统中的二分类监督机器学习算法。 本数据集已公开发布,旨在推动网络安全领域的进一步研究与开发,并协助研究人员设计更高效的入侵检测系统。

提供机构:
Zenodo
创建时间:
2026-03-09
二维码
社区交流群
二维码
科研交流群
商业服务