Skip to main content
zenodoopen

Trace-Share Dataset for Evaluation of Trace Meaning Preservation

<p>The dataset contains all data used during the evaluation of trace meaning preservation. Archives are protected by password &quot;<strong>trace-share</strong>&quot; to avoid false detection by antivirus software.</p> <p>For more information, see the project repository at <strong><a href="https://github.com/Trace-Share">https://github.com/Trace-Share</a></strong>.</p> <p>&nbsp;</p> <p><strong>Selected Attack Traces</strong></p> <p>The following list contains trace datasets used for evaluation. Each attack was chosen to have not only a different meaning but also different statistical properties.</p> <ul> <li><strong>dos_http_flood</strong>&nbsp;&mdash; the capture of GET and POST requests sent to one server by one attacker (HTTP~traffic);</li> <li><strong>ftp_bruteforce</strong>&nbsp;&mdash; short and unsuccessful attempt to guess a user&rsquo;s password for FTP service (FTP traffic);</li> <li><strong>ponyloader_botnet</strong>&nbsp;&mdash; Pony Loader botnet used for stealing of credentials from 3 target devices reporting to single IP with a large number of intermediate addresses (DNS and HTTP traffic);</li> <li><strong>scan</strong>&nbsp;&mdash; the capture of nmap tool that scans given subnet using ICMP echo and TCP SYN requests (consist of ARP, ICMP, and TCP traffic);</li> <li><strong>wannacry_ransomware</strong>&nbsp;&mdash; the capture of Wanacry ransomware that spreads in a domain with three workstations, a domain controller, and a file-sharing server (SMB and SMBv2 traffic).</li> </ul> <p>&nbsp;</p> <p><strong>Background Traffic Data</strong></p> <p>Publicly available dataset <a href="https://www.unb.ca/cic/datasets/ids-2018.html">CSE-CIC-IDS-2018</a>&nbsp;was used as a background traffic data. The evaluation uses data from the day Thursday-01-03-2018 containing a sufficient proportion of regular traffic without any statistically significant attacks. Only traffic aimed at victim machines (range 172.31.69.0/24) is used to reduce less significant traffic.</p> <p>&nbsp;</p> <p><strong>Evaluation Results and Dataset&nbsp;Structure</strong></p> <ul> <li>Traces variants (<a href="https://zenodo.org/record/3547528/files/traces.zip"><em>traces.zip</em></a>) <ul> <li>./traces-original/&nbsp;&mdash; trace PCAP files and crawled details in YAML format;</li> <li>./traces-normalized&nbsp;&mdash; normalized PCAP files and details in YAML format;</li> <li>./traces-adjusted&nbsp;&mdash; adjusted PCAP files using various timestamp generation settings, combination configuration in YAML format, and lables provided by ID2T in XML format.</li> </ul> </li> <li>Extracted alerts (<a href="https://zenodo.org/record/3547528/files/alerts.zip"><em>alerts.zip</em></a>) <ul> <li>./alerts-original/&nbsp;&mdash; extracted Suricata alerts, Suricata log, and full Suricata output for all original trace files;</li> <li>./alerts-normalized/&nbsp;&mdash; extracted Suricata alerts, Suricata log, and full Suricata output for all normalized trace files;</li> <li>./alerts-adjusted/&nbsp;&mdash; extracted Suricata alerts, Suricata log, and full Suricata output for all adjusted trace files.</li> </ul> </li> <li>Evaluation results&nbsp; <ul> <li>*.csv&nbsp;files in the root directory &mdash; data contains extracted alert signatures and their count per each trace variant.</li> </ul> </li> </ul> <p>&nbsp;</p>

ShareScore

32/100

Overall dataset sharing score

Score breakdown

These five areas show where the dataset supports — or may limit — practical reuse.

Stewardship
8
Harmonization
4
Access
16
Reuse readiness
0
Engagement
4

Topics