遇见数据集

Aktaion Dataset

收藏
DataCite Commons2020-07-30 更新2025-04-09 收录
官方服务:

资源简介:

Data was collected from multiple sources, most notably contagiodump.blogspot.com and malware-traffic-analysis.net as PCAP data. Due to license restrictions, the shared data is limited to the example data, which is in ARFF format, and derived from the raw PCAP data in two steps: PCAP to Bro format conversion, and then feature extraction (microbehaviors) to ARFF (using Aktaion). Aktaion is a lightweight Java virtual machine based project for detecting exploits (and more generally attack behaviors). The project is meant to be a learning/teaching tool on how to blend multiple security signals and behaviors into an expressive framework for intrusion detection. The key abstraction we wanted to prototype is the idea of a micro behavior. This concept helps to provide an expressive mechanism to add high level IOCs such as timing behavior of a certain malware family in parallel to simple statistics, rules or anything relevant to building a programmatic description of a sequential evolving set of adverse behaviors.

本数据集采集自多个来源,其中最具代表性的为contagiodump.blogspot.com与malware-traffic-analysis.net,原始数据为数据包捕获(PCAP)格式数据。由于许可限制,共享数据仅包含采用属性关系文件格式(ARFF)的示例数据,该示例数据源自原始PCAP数据,经两步处理得到:首先将PCAP数据转换为Bro格式,随后通过提取微行为(microbehaviors)特征的流程,借助Aktaion工具转换为ARFF格式。Aktaion是一款轻量级基于Java虚拟机(Java Virtual Machine)的项目,用于检测漏洞利用行为,以及更广泛意义上的攻击行为。该项目旨在作为一款学习与教学工具,演示如何将多种安全信号与行为整合至一个高表达性的入侵检测框架中。我们希望进行原型验证的核心抽象概念为微行为(micro behavior)。该概念可提供一种高表达性的机制,能够在结合简单统计指标、规则或其他相关内容的同时,添加特定恶意软件家族的时序行为等高级失陷指标(Indicator of Compromise),以程序化方式描述一组随时间演进的恶意行为序列。

提供机构:
IMPACT
创建时间:
2019-09-10
搜集汇总
数据集介绍
Aktaion Dataset 数据集图片
背景与挑战
背景概述
Aktaion Dataset是一个用于网络入侵检测的外部数据集,包含ARFF格式的标记网络流量数据,主要用于训练勒索软件检测模型。数据来源于公开的PCAP文件,经过特征提取处理,规模较小(14.6KB),由University of Arizona托管,主题涉及网络安全和流量分析。
以上内容由遇见数据集搜集并总结生成
二维码
社区交流群
二维码
科研交流群
商业服务