遇见数据集

HTTPS Brute-force dataset with extended network flows

收藏
Zenodo2022-04-11 更新2026-05-25 收录
数据链接:
官方服务:

资源简介:

We are publishing a dataset we created for designing a brute-force detector of attacks in HTTPS. The dataset consists of extended network flows that we captured with flow exporter Ipifixprobe. Apart from traditional fields like source and destination IP addresses and ports, each flow contains information (size, direction, inter-packet time, TCP flags) about up to the first 100 packets. The sizes of packets are taken from the transport layer (TCP, UPD); packets with zero payload (e.g., TCP ACKs) are ignored. We publish three files: <em>flows.csv</em>, which contains raw flow data. <em>aggregated_flows.csv</em>, which contains aggregated flows <em>samples.csv</em>, which contains samples with extracted features. This data can be used for training a machine-learning classification model. All IP addresses, source ports, TLS SNIs are sha256-hashed. Column <em>CLASS</em> is 0 for benign samples and 1 for brute-force samples. <br> <strong>Brute-force data</strong><br> The brute-force data were generated with three popular attack tools - Ncrack, Thc-hydra, and Patator. Attacks were performed against these applications: WordPress Joomla MediaWiki Ghost Grafana Discourse PhpBB OpenCart Redmine Nginx Apache The <em>SCENARIO</em> columns indicate which tool and application were used to generate the sample. <strong>Benign data</strong><br> Bening data consists of eight captures from a backbone network. The <em>SCENARIO</em> column indicates individual captures.

本团队公开一套专为设计HTTPS暴力破解攻击检测器构建的数据集。该数据集包含使用流量导出器Ipifixprobe捕获的扩展网络流。除源IP地址、目的IP地址与端口等传统字段外,每条流还存储了至多前100个数据包的相关信息,包括数据包大小、传输方向、包间间隔以及TCP标志位。数据包大小取自传输层(TCP、UDP);净负载为零的数据包(如TCP ACK报文)将被忽略。本次公开包含三个文件:<em>flows.csv</em>(存储原始流数据)、<em>aggregated_flows.csv</em>(存储聚合流数据)以及<em>samples.csv</em>(存储提取了特征的样本数据)。该数据集可用于训练机器学习分类模型。所有IP地址、源端口以及TLS SNI(TLS Server Name Indication)均经过sha256哈希处理。<em>CLASS</em>字段取值为0时代表正常样本,取值为1时代表暴力破解攻击样本。 <strong>暴力破解攻击数据</strong> 本次暴力破解攻击数据使用三款主流攻击工具生成:Ncrack、Thc-hydra及Patator。攻击目标涵盖以下应用:WordPress、Joomla、MediaWiki、Ghost、Grafana、Discourse、PhpBB、OpenCart、Redmine、Nginx、Apache。<em>SCENARIO</em>字段用于标识生成该样本所使用的攻击工具与目标应用。 <strong>正常流量数据</strong> 正常流量数据取自骨干网络的八次流量捕获结果。<em>SCENARIO</em>字段用于标识每一次独立的流量捕获。

提供机构:
Zenodo
创建时间:
2020-11-16
二维码
社区交流群
二维码
科研交流群
商业服务