Trace-Share Dataset for Evaluation of Trace Meaning Preservation
<p>The dataset contains all data used during the evaluation of trace meaning preservation. Archives are protected by password "<strong>trace-share</strong>" to avoid false detection by antivirus software.</p> <p>For more information, see the project repository at <strong><a href="https://github.com/Trace-Share">https://github.com/Trace-Share</a></strong>.</p> <p> </p> <p><strong>Selected Attack Traces</strong></p> <p>The following list contains trace datasets used for evaluation. Each attack was chosen to have not only a different meaning but also different statistical properties.</p> <ul> <li><strong>dos_http_flood</strong> — the capture of GET and POST requests sent to one server by one attacker (HTTP~traffic);</li> <li><strong>ftp_bruteforce</strong> — short and unsuccessful attempt to guess a user’s password for FTP service (FTP traffic);</li> <li><strong>ponyloader_botnet</strong> — Pony Loader botnet used for stealing of credentials from 3 target devices reporting to single IP with a large number of intermediate addresses (DNS and HTTP traffic);</li> <li><strong>scan</strong> — the capture of nmap tool that scans given subnet using ICMP echo and TCP SYN requests (consist of ARP, ICMP, and TCP traffic);</li> <li><strong>wannacry_ransomware</strong> — the capture of Wanacry ransomware that spreads in a domain with three workstations, a domain controller, and a file-sharing server (SMB and SMBv2 traffic).</li> </ul> <p> </p> <p><strong>Background Traffic Data</strong></p> <p>Publicly available dataset <a href="https://www.unb.ca/cic/datasets/ids-2018.html">CSE-CIC-IDS-2018</a> was used as a background traffic data. The evaluation uses data from the day Thursday-01-03-2018 containing a sufficient proportion of regular traffic without any statistically significant attacks. Only traffic aimed at victim machines (range 172.31.69.0/24) is used to reduce less significant traffic.</p> <p> </p> <p><strong>Evaluation Results and Dataset Structure</strong></p> <ul> <li>Traces variants (<a href="https://zenodo.org/record/3547528/files/traces.zip"><em>traces.zip</em></a>) <ul> <li>./traces-original/ — trace PCAP files and crawled details in YAML format;</li> <li>./traces-normalized — normalized PCAP files and details in YAML format;</li> <li>./traces-adjusted — adjusted PCAP files using various timestamp generation settings, combination configuration in YAML format, and lables provided by ID2T in XML format.</li> </ul> </li> <li>Extracted alerts (<a href="https://zenodo.org/record/3547528/files/alerts.zip"><em>alerts.zip</em></a>) <ul> <li>./alerts-original/ — extracted Suricata alerts, Suricata log, and full Suricata output for all original trace files;</li> <li>./alerts-normalized/ — extracted Suricata alerts, Suricata log, and full Suricata output for all normalized trace files;</li> <li>./alerts-adjusted/ — extracted Suricata alerts, Suricata log, and full Suricata output for all adjusted trace files.</li> </ul> </li> <li>Evaluation results <ul> <li>*.csv files in the root directory — data contains extracted alert signatures and their count per each trace variant.</li> </ul> </li> </ul> <p> </p>
ShareScore
32/100
Overall dataset sharing score
Score breakdown
These five areas show where the dataset supports — or may limit — practical reuse.
- Stewardship
- 8
- Harmonization
- 4
- Access
- 16
- Reuse readiness
- 0
- Engagement
- 4