遇见数据集

ICS-MMOC3: Realistic Multi-Modal Power Generation ICS Dataset

收藏
Zenodo2026-06-04 更新2026-05-26 收录
官方服务:

资源简介:

Overview MMOC3 is an ICS dataset collected from a physical power generation testbed operated by a national ICS laboratory. The dataset emulates a combined-cycle power plant and exposes over one thousand industrial process tags, including sensors, actuators and control variables. In addition to raw IP and SCADA network traffic, specifically S7Comm and Modbus, the dataset includes a comprehensive set of historian records, IDS alerts, system events logs, SCADA-to-NetFlow second-level statistics with over 70 features, and a mapping between industrial variables and their representation in SCADA messages. Data were recorded during extended periods of normal operation, and was subjected to a wide range of controlled operational events and fault scenarios, as well as deliberate cyber attacks targeting both the network and control layers. This dataset is part of the CPSS '26 conference publication: ICS-MMOC3: Exploring Operational Faults and Cyber Attacks with a Realistic Multi-Modal Power Generation ICS Dataset Key Features The dataset is designed to explicitly bridge the gap between information technology (IT) network traffic and operational-technology (OT) physical process behavior in ICS. Rather than treating IT and OT data sources as independent modalities, MMOC3 provides a unified view in which network-level communication, SCADA protocolsemantics, and physical process dynamics are temporally aligned and semantically connected. Dataset Structure The MMOC3 dataset comprises six capture days, totaling approximately 30 hours of operation of the power generation testbed. For each day, we provide benign and anomalous data to enable realistic benchmarking of ICS detection methods. 🟢 Normal🟡 Operational Failures🔴 Cyber Attacks Day Date Type Recorded Network Pcap Recorded Historian SCADA-to-Netflow Recorded IDS Alerts Recorded Events Logs 1 13/6 🟢 ✓ ✓ ✓ ✓ ✓ 2 14/6 🟢 🟡 ✓ ✓ ✓ ✓ ✓ 3 15/6 🟢 🟡 ✓ ✓ ✓ ✓ ✓ 4 18/6 🟢 🟡 🔴 ✓ ✓ ✓ ✓ ✓ 5 19/6 🟢 🟡 🔴 ✓ ✓ ✓ ✓ ✓ 6 20/6 🟢 🟡 🔴 ✓ ✓ ✓ ✓ ✓ Files Structure For each capture day, a set of 5 corresponding files is provided. Files are logically grouped by their capture day using an `MM_DD_` naming prefix as detailed in the table below. Together, these files expose packet-level network traffic, physical process measurements, derived SCADA flow statistics, IDS alerts, and event logs. Files provided per capture day in MMOC3 Filename Ext. Description Time zone MM_DD_network .pcap Packet-level trace of all network traffic captured in the system, including SCADA communications (S7Comm and Modbus) UTC MM_DD_historian .csv Historian-style record of all industrial process tags at second-level. UTC MM_DD_S7Comm_Flow .csv Flow-level aggregated statistics of SCADA traffic, partitioned into fixed 1-second windows and comprising more than 70 features per window. UTC MM_DD_events .json OT IDS events and alerts generated by Suricata. UTC MM_DD_sysmon .evtx HMI operating system event log capturing host-level activity and system events. UTC Additionally, the repository includes global, dataset-wide files that provide essential context for the daily captures: siemens tag address.csv: Mapping between industrial variables and Database (DB) addresses observed in the SCADA messages. ip_mapping.csv : Mapping of IP addresses across the network. Ground Truth and Event Labeling To facilitate machine learning learning and precise temporal analysis, ground truth labeling is provided at a one-second granularity. The MM_DD_historian and MM_DD_S7Comm_Flow artifacts include normal and anomalous labels according to the table below.The following table summarizes the exact time windows for all simulated system faults and cyber attacks executed during the data collection. For more information about the attack vectors, threat models, and simulated system faults, please refer to the accompanying publication. Table: Summary of Anomalous Events Event Date Event type Start (HH:MM:SS) UTC End (HH:MM:SS) UTC Label Description 1 13/6 Normal Bumpless Tranfser 11:45:10 12:30:07 E1 Switch to diesel turbine 2 14/6 Operational failure ⚠️ 07:37:55 07:42:38 E2 Disconnect HMI from PLC 3 14/6 Unexpected historian failure ⚠️ 07:42:39 08:40:42 E3 No historian data 4 14/6 Operational failure 09:15:47 09:17:07 E4 Close valve 5 14/6 Operational failure 09:17:08 09:22:31 E5 Switch to diesel turbine 6 14/6 Operational failure 09:22:32 09:28:11 E6 Open valve 7 14/6 Operational failure 10:53:41 10:56:49 E7 Disconnect temprature sensor 8 15/6 Operational failure 08:03:07 08:05:41 E8 Emergency stop 9 15/6 Operational failure 08:05:42 08:11:09 E9 Restart process - back to normal 10 15/6 Operational failure 11:38:09 11:40:34 E10 Insufficient supply to gas turbine 11 15/6 Operational failure 12:14:23 12:15:51 E11 Disconnect tag LSL305A 12 18/6 Cyber attack ⚠️ 10:59:08 11:00:09 E12 USB Malware Injection 13 18/6 Cyber attack 11:08:51 12:52:29 E13 Industrial process stop as a result of the attack. No HMI and historian data. 14 19/6 Cyber attack ⚠️ 09:15:58 09:36:07 E14 Attacker connects to the network 15 19/6 Cyber attack ⚠️ 09:36:08 10:04:14 E15 Attacker performs port scan and gains control to the HMI 16 19/6 Cyber attack 10:18:27 10:27:26 E16 Attacker performs tag poisoning 17 19/6 Operational failure 11:39:19 11:41:59 E17 Tag disconnection - turbine stop 18 20/6 Cyber attack ⚠️ 10:01:38 10:12:23 E18 Malicious update on HMI, take over HMI 19 20/6 Cyber attack 10:12:24 10:34:22 E19 Attacker performs tag posioning 20 20/6 Operational failure 11:36:04 11:41:54 E20 Emergency stop + Restart 21 20/6 Cyber attack ⚠️ 11:59:24 12:00:32 E21 Attacker connects to the network 22 20/6 Cyber attack ⚠️ 12:00:33 12:17:10 E22 Attacker performs port scan and gains control to the HMI. 23 20/6 Cyber attack 12:17:11 12:26:41 E23 Attacker performs tag poisoning 24 20/6 Cyber attack 12:26:42 12:35:43 E24 Attacker continues to write to addresses in HMI Because MMOC3 captures data across multiple system levels, not all events listed above induce anomalies across all data modalities simultaneously. ⚠️ - Note that although E2, E3, E12, E14, E15, E18, E21, E22 are labelled as anomalous, there might not be an impact on the industrial process. Citation If you use this dataset, please cite the following publication: @inproceedings{shafir-cpss26, title = {{ICS-MMOC3}: Exploring Operational Faults and Cyber Attacks with a Realistic Multi-Modal Power Generation {ICS} Dataset}, author={L. Shafir and A. Elyashar and J. Cohen and M. Zeitoun and M. Holipsky and B. Yaakov and E. Aliev and R. Puzis and Y. Harel and A. Wool}, year = 2026, booktitle = {Proc. 12th ACM Cyber-Physical System Security Workshop (CPSS 2026)}, pages={63--76}, month = jun, address = {Bangalore, India}, url={\url{https://doi.org/10.1145/3775042.3807883}},}

# 概述 MMOC3是一款由国家级工业控制系统(Industrial Control System, ICS)实验室运营的实物发电试验平台采集得到的工业控制系统数据集。 本数据集模拟联合循环发电厂,包含超千条工业过程标签,涵盖传感器、执行器与控制变量三类核心对象。除原始IP流量与工业控制系统(Supervisory Control And Data Acquisition, SCADA)网络流量(特指S7Comm与Modbus协议流量)外,数据集还包含完整的历史记录集、入侵检测系统(Intrusion Detection System, IDS)告警、系统事件日志、基于秒级粒度的SCADA到NetFlow流量统计特征(单窗口特征数超70),以及工业变量与SCADA报文中对应表示形式的映射关系。 数据采集覆盖长时间正常运行工况,并包含大量受控的运行事件、故障场景,以及针对网络层与控制层的蓄意网络攻击场景。本数据集收录于CPSS 2026会议论文:《ICS-MMOC3:基于真实多模态发电工业控制系统数据集探索运行故障与网络攻击》。 # 核心特性 本数据集旨在填补工业控制系统中信息技术(Information Technology, IT)网络流量与运营技术(Operational Technology, OT)物理过程行为之间的鸿沟。不同于将IT与OT数据源视为独立模态的传统方案,MMOC3提供了统一视角,将网络级通信、SCADA协议语义与物理过程动态进行时序对齐与语义关联。 # 数据集结构 MMOC3数据集包含6个采集日的数据,总时长约30小时的发电试验平台运行记录。每个采集日均提供正常与异常数据,以支持工业控制系统检测方法的真实基准测试。 🟢 正常工况 🟡 运行故障 🔴 网络攻击 | 采集日 | 日期 | 数据类型 | 录制网络Pcap文件 | 录制历史记录 | SCADA到NetFlow统计 | IDS告警记录 | 系统事件日志 | |--------|-------|--------------|------------------|--------------|--------------------|------------|--------------| | 1 | 13/6 | 🟢 | ✓ | ✓ | ✓ | ✓ | ✓ | | 2 | 14/6 | 🟢 🟡 | ✓ | ✓ | ✓ | ✓ | ✓ | | 3 | 15/6 | 🟢 🟡 | ✓ | ✓ | ✓ | ✓ | ✓ | | 4 | 18/6 | 🟢 🟡 🔴 | ✓ | ✓ | ✓ | ✓ | ✓ | | 5 | 19/6 | 🟢 🟡 🔴 | ✓ | ✓ | ✓ | ✓ | ✓ | | 6 | 20/6 | 🟢 🟡 🔴 | ✓ | ✓ | ✓ | ✓ | ✓ | # 文件结构 每个采集日对应5个配套文件,所有文件均以`MM_DD_`作为命名前缀,按采集日进行逻辑分组,具体如下表所示。这些文件涵盖数据包级网络流量、物理过程测量数据、衍生SCADA流量统计特征、IDS告警与事件日志。 ## 单采集日配套文件 | 文件名 | 扩展名 | 描述 | 时区 | |---------------------|--------|----------------------------------------------------------------------|------| | MM_DD_network | .pcap | 系统全量网络流量数据包捕获文件,包含SCADA通信流量(S7Comm与Modbus协议) | UTC | | MM_DD_historian | .csv | 秒级粒度的全量工业过程标签历史记录文件 | UTC | | MM_DD_S7Comm_Flow | .csv | 基于固定1秒窗口聚合的SCADA流量流统计特征,单窗口包含超70项特征 | UTC | | MM_DD_events | .json | Suricata生成的运营技术IDS事件与告警文件 | UTC | | MM_DD_sysmon | .evtx | 人机界面(HMI)操作系统事件日志,记录主机级活动与系统事件 | UTC | 此外,数据集仓库还包含全局数据集级文件,为各采集日数据提供必要上下文: 1. `siemens tag address.csv`:工业变量与SCADA报文中观测到的数据库(DB)地址的映射表 2. `ip_mapping.csv`:网络内IP地址映射表 # 真实标签与事件标注 为便于机器学习与精准时序分析,本数据集提供秒级粒度的真实标签标注。`MM_DD_historian`与`MM_DD_S7Comm_Flow`数据文件包含下表所示的正常与异常标签。下表汇总了数据采集期间所有模拟系统故障与网络攻击的精确时间窗口。如需了解攻击向量、威胁模型与模拟系统故障的更多细节,请参阅配套论文。 ## 异常事件汇总表 | 事件ID | 日期 | 事件类型 | 开始时间(UTC) | 结束时间(UTC) | 标签 | 事件描述 | |--------|-------|------------------------------|----------------|----------------|-------|--------------------------------------------------------------------------| | 1 | 13/6 | 正常无扰切换 | 11:45:10 | 12:30:07 | E1 | 切换至柴油轮机 | | 2 | 14/6 | 运行故障 ⚠️ | 07:37:55 | 07:42:38 | E2 | 断开人机界面(HMI)与可编程逻辑控制器(PLC)的连接 | | 3 | 14/6 | 意外历史记录服务故障 ⚠️ | 07:42:39 | 08:40:42 | E3 | 无历史记录数据 | | 4 | 14/6 | 运行故障 | 09:15:47 | 09:17:07 | E4 | 关闭阀门 | | 5 | 14/6 | 运行故障 | 09:17:08 | 09:22:31 | E5 | 切换至柴油轮机 | | 6 | 14/6 | 运行故障 | 09:22:32 | 09:28:11 | E6 | 开启阀门 | | 7 | 14/6 | 运行故障 | 10:53:41 | 10:56:49 | E7 | 断开温度传感器 | | 8 | 15/6 | 运行故障 | 08:03:07 | 08:05:41 | E8 | 紧急停机 | | 9 | 15/6 | 运行故障 | 08:05:42 | 08:11:09 | E9 | 重启进程,恢复至正常工况 | | 10 | 15/6 | 运行故障 | 11:38:09 | 11:40:34 | E10 | 燃气轮机供能不足 | | 11 | 15/6 | 运行故障 | 12:14:23 | 12:15:51 | E11 | 断开标签LSL305A | | 12 | 18/6 | 网络攻击 ⚠️ | 10:59:08 | 11:00:09 | E12 | USB恶意软件注入 | | 13 | 18/6 | 网络攻击 | 11:08:51 | 12:52:29 | E13 | 攻击导致工业进程停机,无人机界面与历史记录数据 | | 14 | 19/6 | 网络攻击 ⚠️ | 09:15:58 | 09:36:07 | E14 | 攻击者接入网络 | | 15 | 19/6 | 网络攻击 ⚠️ | 09:36:08 | 10:04:14 | E15 | 攻击者执行端口扫描并获取人机界面控制权 | | 16 | 19/6 | 网络攻击 | 10:18:27 | 10:27:26 | E16 | 攻击者执行标签投毒攻击 | | 17 | 19/6 | 运行故障 | 11:39:19 | 11:41:59 | E17 | 标签断开,汽轮机停机 | | 18 | 20/6 | 网络攻击 ⚠️ | 10:01:38 | 10:12:23 | E18 | 恶意更新人机界面,获取其控制权 | | 19 | 20/6 | 网络攻击 | 10:12:24 | 10:34:22 | E19 | 攻击者执行标签投毒攻击 | | 20 | 20/6 | 运行故障 | 11:36:04 | 11:41:54 | E20 | 紧急停机+重启 | | 21 | 20/6 | 网络攻击 ⚠️ | 11:59:24 | 12:00:32 | E21 | 攻击者接入网络 | | 22 | 20/6 | 网络攻击 ⚠️ | 12:00:33 | 12:17:10 | E22 | 攻击者执行端口扫描并获取人机界面控制权 | | 23 | 20/6 | 网络攻击 | 12:17:11 | 12:26:41 | E23 | 攻击者执行标签投毒攻击 | | 24 | 20/6 | 网络攻击 | 12:26:42 | 12:35:43 | E24 | 攻击者持续向人机界面地址写入数据 | ⚠️ 注意:尽管E2、E3、E12、E14、E15、E18、E21、E22被标记为异常事件,但未必会对工业过程产生影响。 # 引用说明 若使用本数据集,请引用以下论文: bibtex @inproceedings{ics_mmoc3_2026, author = {Shafir, Lior and Elyashar, Aviad and Cohen, Jonathan and Zeitoun, Mickael and Holipsky, Miroslav and Yaakov, Barak, and Aliev, Eli and Puzis, Rami and Harel, Yaniv and Wool, Avishai}, title = {{ICS-MMOC3}: Exploring Operational Faults and Cyber Attacks with a Realistic Multi-Modal Power Generation ICS Dataset}, booktitle = {Proceedings of the 12th ACM Cyber-Physical System Security Workshop (CPSS '26), June 1--5, 2026, Bangalore, India}, year = {2026}, publisher = {ACM}, note = {To appear} }

提供机构:
Zenodo
创建时间:
2026-05-10
二维码
社区交流群
二维码
科研交流群
商业服务