遇见数据集

MAD (MAlicious Traffic Dataset) in home and commercial environments - Environment with scalability

收藏
Zenodo2021-07-19 更新2026-05-25 收录
数据链接:
官方服务:

资源简介:

We have used the Internet environment: 01 Switch, 01 IP camera, 01 server for monitoring, 01 server for honeypot and no firewall. This environment is directly connected to the Internet. We installed a server, functioning as a Monitoring Environment. The network traffic was obtained via Port Mirroring on the switch to the Monitoring Environment server. We added 08 virtual machines and performed the following test with a denial of service DoS attack: 01 virtual machine from 04:00 pm to 23:55 pm on 2019-12-04 with an interval every 01 hour;<br> 02 virtual machines from 23:55 am on 2019-12-04 to 08:50 am on 2019-12-05 with an interval every 01 hour;<br> 04 virtual machines as of 08:55 am on 2019-12-05 to 05:25 pm on 2019-12-06 with an interval every 5 minutes;<br> 08 virtual machines from 05:30 pm on 2019-12-06 to 23:59 on 2019-12-06 with an interval every 5 minutes;<br> End of tests with shutdown of virtual machines at 23:59 on 2019-12-06. The results were obtained from Suricata and Telegraf collections from the TICK stack. All evidence was performed by queries via EveBox, which received data from Suricata, Grafana or graphics with information extracted from the InfluxDB (Grafana) and PostgreSQL (EveBox) databases. events.csv.gz - Suricata / Evebox collections net.csv.gz - Telegraf collections from the TICK stack netstat.csv.gz - Telegraf collections from the TICK stack For correlation purposes, use the events.csv.gz file as a basis. The key to correlation is the 'timestamp' column events.csv.gz with the 'time' column in the net.csv.gz and netstat.csv.gz files. The interval between collections, non-consecutive, was from 2019-12-04 to 2019-12-06

本实验搭建了直连互联网的测试环境,包含1台交换机、1台IP摄像头、1台监控服务器、1台蜜罐服务器,且未部署防火墙。我们部署了一台作为监控节点的服务器,通过交换机的端口镜像(Port Mirroring)将网络流量导入该监控服务器。新增8台虚拟机,并开展如下拒绝服务(Denial of Service, DoS)攻击测试:1. 2019年12月4日16:00至23:55期间,使用1台虚拟机发起攻击,攻击间隔为1小时;2. 2019年12月4日23:55至2019年12月5日08:50期间,使用2台虚拟机发起攻击,攻击间隔为1小时;3. 2019年12月5日08:55至2019年12月6日17:25期间,使用4台虚拟机发起攻击,攻击间隔为5分钟;4. 2019年12月6日17:30至23:59期间,使用8台虚拟机发起攻击,攻击间隔为5分钟;本次测试于2019年12月6日23:59通过关闭所有虚拟机终止。实验结果通过Suricata与TICK栈的Telegraf工具采集得到。所有验证数据均通过EveBox进行查询生成,其中EveBox接收来自Suricata的数据;Grafana则用于可视化展示从InfluxDB与PostgreSQL数据库中提取的信息,其中InfluxDB供Grafana调用、PostgreSQL供EveBox调用。本次实验生成的数据集文件包括:- events.csv.gz:Suricata与EveBox采集的事件数据;- net.csv.gz:TICK栈中Telegraf采集的网络数据;- netstat.csv.gz:TICK栈中Telegraf采集的网络状态数据。如需进行多源数据关联分析,建议以events.csv.gz文件为基准,关联键为events.csv.gz中的`timestamp`字段与net.csv.gz、netstat.csv.gz文件中的`time`字段。本次数据采集的非连续时间范围为2019年12月4日至2019年12月6日。

提供机构:
Zenodo
创建时间:
2021-07-19
二维码
社区交流群
二维码
科研交流群
商业服务