UGR'16: A New Dataset for the Evaluation of Cyclostationarity-Based Network IDSs

The dataset presented here is built with real traffic and up-to-date attacks. These data come from several netflow v9 collectors strategically located in the network of a spanish ISP. It is composed of two differentiated sets of data that are previously split in weeks:

The main advantage of this dataset over previous ones is its usefulness for evaluating IDSs that consider long-term evolution and traffic periodicity. Models that consider differences in daytime/night or labour weekdays/weekends can also be trained and evaluated with it.


Reference:
Gabriel Maciá Fernández, José Camacho, Roberto Magán-Carrión, Pedro García-Teodoro, Roberto Theron, Ugr'16: a new dataset for the evaluation of cyclostationarity-based network IDSs, In Computers & Security, 2017
Author paper version available for download by clicking here


July - Week #5 Date range: 07/27/2016 - 07/31/2016

All traffic flows


# File Name File Type Description Upload time Download
1 july_week5_nfcapd Collected binary netflow 10/06/2017 17:43:36
2 july_week5_csv Collected CSV netflow flows (labeled) 04/04/2018 14:50:03

Attack execution timestamps (mins)


# File Name File Type Description Upload time Download
1 attack_ts_july_week5.csv Contains the timestamps (in mins) where the attacks were executed 11/30/2017 08:40:14

Flows per type of attack (labeled)


# File Name File Type Description Upload time Download
1 dos_july_week5_csv Extracted flows for DoS attacks 11/30/2017 08:27:48
2 scan11_july_week5_csv Extracted flows for scan11 attacks 11/30/2017 08:40:13
3 scan44_july_week5_csv Extracted flows for scan44 attacks 11/30/2017 08:40:13
4 blacklist_july_week5_csv Extracted flows where the involved IPs are in the black lists 11/30/2017 08:27:47
5 spam_july_week5_csv Extracted flows for spam attacks 11/30/2017 08:40:14
6 nfcapd_july_week5_sshscan_csv.csv Extracted flows for SSH scan attacks 11/30/2017 08:40:14
7 udpscan_july_week5_csv Extracted flows for UDP scan attacks 11/30/2017 08:40:14
8 botnet_july_week5_csv Extracted flows for Neris botnet attack 11/30/2017 08:27:47