Skip to main content
Powered by ShareScore

Find research datasets worth reusing

Search datasets from major research repositories and use ShareScore to quickly assess how well each record supports discovery, access, and reuse.

190

datasets available to search

ShareScore release 0.9.0

Reset

Dataset results

190 results for “intrusions”

Learn how ShareScore rates datasets ↗
zenodo32/100

Hydraulic and geochemical impact of occasional saltwater intrusions through a submarine spring in a karst and thermal aquifer (Balaruc peninsula near Montpellier, France)

<p>Contains geochemical and isotopic data presented in the scientific paper &quot;Hydraulic and geochemical impact of occasional saltwater intrusions through a submarine spring in a karst and thermal aquifer (Balaruc peninsula near Montpellier, France)&quot;.</p> <p>Files contain physico-chemical parameters, major ions, rare earth elements and isotopic data (Sr, B) for karst and thermal groundwater samples collected between 2010 and 2018 in the Balaruc-les-Bains (France) area.</p>

opencc-by-4.0Jun 2020View details →
zenodo32/100

Asynchronous event-based clustering and tracking for intrusion monitoring in UAS

<p>This dataset describes a collection of rosbag files for event-based intruder monitoring using UAS. A DAVIS346 camera was mounted over a DJI Flamewheel F550 Drone, and an onboard computer recorded the sensor information from the event camera. Each dataset includes events, frames, and IMU measurements. The monitoring scenes were recorded outdoors at the School of Engineering of the University of Seville. In each dataset, an intruder moves and hides from the field of view of the camera simulating a scape-intrusion situation. A total of four monitoring setting were recorded:</p> <p><strong>Daylight monitoring:</strong>&nbsp;A daylight scene for intruder monitoring. An intruder runs and hides behind the objects of the scene to evade the camera field of view.<br> <br> <strong>Night light monitoring:</strong>&nbsp;A monitoring scene during the night without the presence of any artificial light. The low light condition increases the difficulty of monitoring task due to the increment of noisy events.<br> <br> <strong>Multi-target:</strong>&nbsp;An experiment with a suspect and a chaser drone moving in the monitoring area. The drone follows the suspect by simulating a pursuit operation.<br> <br> <strong>Monitoring under illumination changes:</strong>&nbsp;A night scene where the lighting conditions changes by the movement of artificial lights in the scene.</p>

opencc-by-4.0Jul 2020View details →
dryad32/100

Data from: Turning defence into offence? intrusion of cladoceran brood chambers by a green alga leads to reproductive failure

Microalgae are the foundation of aquatic food webs. Their ability to defend against grazers is paramount to their survival, and modulates their ecological functions. Here we report a novel anti-grazer strategy in the common green alga Chlorella vulgaris against two grazers, Daphnia magna and Simocephalus sp. The algal cells entered the brood chamber of both grazers, presumably using the brood current generated by the grazer's abdominal appendages. Once inside, the alga densely colonised the eggs, significantly reducing reproductive success. The effect was apparent under continuous light or higher light intensity. The algal cells remained viable following removal from the brood chamber, continuing to grow when inoculated in fresh medium. No brood chamber colonisation was found when the grazers were fed the reference diet Raphidocelis subcapitata under the same experimental conditions, despite the fact that both algal species were readily ingested by the grazers and were small enough to enter their brood chambers. These observations suggest that C. vulgaris can directly inflict harm on the grazers' reproductive structure. There is no known prior example of brood chamber colonisation by a microalgal prey; our results point to a new type of grazer-algae interaction in the plankton that fundamentally differs from other antagonistic ecological interactions.

opencc-zeroAug 2020View details →
dryad32/100

Experimental predator intrusions in a cooperative breeder reveal threat-dependent task partitioning

In cooperatively breeding species, non-breeding individuals provide alloparental care and help in territory maintenance and defence. Antipredator behaviours of subordinates can enhance offspring survival, which may provide direct and indirect fitness benefits to all group members. Helping abilities and involved costs and benefits, risks and outside options (e.g. breeding independently) usually diverge between group members, which calls for status-specific differentiated behavioural responses. Such role differentiation within groups may generate task-specific division of labour, as exemplified by eusocial animals. In vertebrates, little is known about such task differentiation among group members. We show how breeders and helpers of the cooperatively breeding cichlid Neolamprologus savoryi partition predator defence depending on intruder type and the presence of dependent young. In the field, we experimentally simulated intrusions by different fish species posing a risk either specifically to eggs, young, or adults. We used intrusions by harmless algae-eaters as a control. Breeders defended most when dependent young were present, while helper investment hinged mainly on their body size and on the potential threat posed by the respective intruders. Breeders and helpers partitioned defence tasks primarily when dependent young were exposed to immediate risk, with breeders investing most in antipredator defence, while helpers increased guarding and care in the breeding chamber. Breeders' defence likely benefits helpers as well, as it was especially enhanced in the treatment where helpers were also at risk. These findings illustrate that in a highly social fish different group members exhibit fine-tuned behavioural responses in dependence of ecological and reproductive parameter variation.

opencc-zeroSep 2020View details →
zenodo32/100

Data for Multiscale temporal response of salt intrusion to transient river and ocean forcing

<p>Data used in the paper &#39;Multiscale temporal response of salt intrusion to transient river and ocean forcing&#39;</p>

opencc-by-4.0Dec 2020View details →
zenodo32/100

Data in support of manuscript "Tidal intrusion fronts, surface convergence, and mixing in an estuary with complex topography"

<p>North River observational data&nbsp;in support of manuscript "Tidal intrusion fronts, surface convergence, and mixing in an estuary with complex topography". Fieldwork&nbsp;in Oct - Nov&nbsp;2021. CTD data and ADCP data collected during shipboard surveys at a channel constriction and a bend. CTD data and Aquadopp data collected at multiple mooring sites.</p>

opencc-by-4.0Oct 2023View details →
zenodo32/100

Systematic Review Dataset Collection for Intrusion Detection

Open the record for dataset details and reuse information.

opencc-by-4.0Mar 2024View details →
zenodo32/100

Supporting Dataset for "Synoptic Moisture Intrusion Provided Heavy Isotope Precipitations in Inland Antarctica during the Last Glacial Maximum"

<p><strong>Data used in <a href="https://doi.org/10.1029/2024GL108191" target="_blank" rel="noopener">Kino et al. (2024, GRL)</a> are stored as zip and CSV files.</strong></p> <ul> <li>All data (except for Antarctica_LGM_Proxies.csv) resulted from an isotope-enabled atmospheric general circulation model named "iso-MIROC5"&nbsp;<a href="https://doi.org/10.1029/2018JD029463" target="_blank" rel="noopener">(Okazaki and Yoshimura, 2019, JGR)</a>.</li> <li>Antarctica_LGM_Proxies.csv resulted from Table 1 of <a href="https://www.nature.com/articles/s41467-018-05430-y" target="_blank" rel="noopener">Werner et al. (2018, Nat. Com.)</a> and <a href="https://www.usap-dc.org/view/dataset/601239" target="_blank" rel="noopener">Steig et al. (2020, USAP-DC)</a>.</li> <li>The definition of southward moisture fluxes proposed by <a href="https://journals.ametsoc.org/view/journals/clim/25/21/jcli-d-11-00665.1.xml" target="_blank" rel="noopener">Newman et al. (2012, JC)</a> was adopted.<br>The module of <a href="https://gmd.copernicus.org/articles/13/1179/2020/" target="_blank" rel="noopener">ESMValTool (Righi et al., 2020, GMD)</a> was customized to calculate the Eady growth rate.</li> <li>Scripts are available in a&nbsp;<a href="https://github.com/kanonundgigue/kino2024grl" target="_blank" rel="noopener">GitHub repository</a>.</li> </ul> <p>Sources are available at <a href="https://github.com/kanonundgigue/kino2024grl">https://github.com/kanonundgigue/kino2024grl</a>.</p> <p>If you use data for your work, please ask the author to be a co-author or cite the paper according to data contributions.</p>

openMar 2024View details →
zenodo32/100

Dataset from Rummel et al.: "Spatially resolved salt intrusion mechanisms in a tidal estuary and the impact of channel deepening" - Part 1

<p>Model data from the numerical setup of the Weser River Estuary used in Rummel et al. (submitted to JGR:Oceans): "Spatially resolved salt intrusion mechanisms in a tidal estuary and the impact of channel deepening" - Part 1.</p> <p>The dates in the file names are connected to specific model runs and do not explain the modelled time period.</p> <p>Explanation of datasets:</p> <ul> <li>2D_elev*&nbsp; -&nbsp; 2D model output for the entire year 2016&nbsp; for validation at one location each (associated station name included in file name), original topography.</li> <li>3D_stat*&nbsp; -&nbsp; 3D model output for the entire year 2016 for validation at one location each (associated station name included in file name), original topography.</li> <li>3D_cross_30_80*&nbsp; -&nbsp; 3D model output for one month of 2016 for the model domain from Weser km 30 to 80 including variables needed for the salt transport decomposition. <ul> <li>2024-05-23&nbsp; -&nbsp; March 2016, original topography</li> <li>2024-06-07&nbsp; -&nbsp; March 2016, dredged topography</li> <li>2024-06-06&nbsp; -&nbsp; September 2016, original topography (different temporal resolution)</li> <li>2024-06-10&nbsp; -&nbsp; September 2016, dredged topography</li> </ul> </li> <li>3D_channel*&nbsp; -&nbsp; 3D model output for the navigational channel in the entire model domain for the entire year 2016. <ul> <li>2024-04-02&nbsp; -&nbsp; original topography</li> <li>2024-05-16&nbsp; -&nbsp; dredged topography</li> </ul> </li> <li>3D_cross_55/65_2024-09-02*&nbsp; -&nbsp; 3D model output for September 2016, original topography for crosssections at Weser km 55 and 65 including variables needed for the salt transport decomposition.</li> </ul>

opencc-by-4.0Nov 2024View details →
zenodo32/100

Dataset from Rummel et al.: "Spatially resolved salt intrusion mechanisms in a tidal estuary and the impact of channel deepening" - Part 2

<p>Model data from the numerical setup of the Weser River Estuary used in Rummel et al. (submitted to JGR: Oceans): "Spatially resolved salt intrusion mechanisms in a tidal estuary and the impact of channel deepening" - Part 2.</p> <p>The dates in the file names are connected to specific model runs and do not explain the modelled time period.</p> <p>This dataset contains daily averaged 3D model output for the entire year 2016 of the whole model domain with the original, not dredged topography.</p> <p>&nbsp;</p>

opencc-by-4.0Nov 2024View details →
zenodo32/100

Dataset from Rummel et al.: "Spatially resolved salt intrusion mechanisms in a tidal estuary and the impact of channel deepening" - Part 3

<p>Model data from the numerical setup of the Weser River Estuary used in Rummel et al. (submitted to JGR: Oceans): "Spatially resolved salt intrusion mechanisms in a tidal estuary and the impact of channel deepening" - Part 3.</p> <p>The dates in the file names are connected to specific model runs and do not explain the modelled time period.</p> <p>This dataset contains daily averaged 3D model output for the entire year 2016 of the whole model domain with the dredged topography.</p>

opencc-by-4.0Nov 2024View details →
zenodo32/100

Phytoplankton Community Patterns in the Northeastern South China Sea: Implications of intensified Kuroshio intrusion during the 2015/16 El Niño

<p>Phytoplankton Community Patterns in the Northeastern South China Sea:<br> Implications of intensified Kuroshio intrusion during the 2015/16 El Ni&ntilde;o</p>

opencc-by-4.0Nov 2021View details →
zenodo32/100

Non-intrusive semi-analytical uncertainty quantification using Bayesian quadrature with application to CFD simulations

<p>The data contained in the uploaded &#39;.zip&#39; file is for some of the plots in the paper &lsquo;Duan Y*, Eaton MD, Bluck MJ, 2021, Non-intrusive semi-analytical uncertainty quantification using Bayesian quadrature with application to CFD simulations, International Journal of Heat and Fluid Flow.&rsquo; (accepted)</p>

opencc-by-4.0Dec 2021View details →
zenodo32/100

Data of publication "Impact of biomass burning and stratospheric intrusions in the remote South Pacific Ocean troposphere" by N. Daskalakis et al.

<p>Modeled data and measured data as used for the publication &quot; Impact of biomass burning and stratospheric intrusions in the remote South Pacific Ocean troposphere&quot; by N. Daskalakis et al. All measured data were obtained from the official sources, and model results are described in the publication. Please refer to the manuscript for further information for the data and the model.</p>

opencc-by-4.0Mar 2022View details →
zenodo32/100

Shallow and deep subsurface sediment remobilization and intrusion in the Middle Jurassic to Lower Cretaceous Agardhfjellet Formation (Svalbard) [Supplementary material/digital model data]

<p>Supplementary model data for the publication Ogata et al. (in review):</p> <p>Most of the models suffer from incorrect location metadata, limiting their use to mostly qualitative interpretations.</p> <p>Shallow and deep subsurface sediment remobilization and intrusion in the Middle Jurassic to Lower Cretaceous Agardhfjellet Formation (Svalbard).</p>

opencc-by-4.0May 2022View details →
zenodo32/100

Subspecies and Distribution. C. o. obtusirostris Peters, 1851 — Save and Changane river systems of C & S Mozambique, with marginal intrusion into SE Zimbabwe and Limpopo Province of NE South Africa. C. o. chrysillus Thomas & Schwann, 1905 — from Maputo, S Mozambique, S to Maputaland, NE KwaZulu-Natal, E South Africa. C. o. limpopoensis Roberts, 1946 — from around mouth of Limpopo River S to coastal plains near Maputo, SE Mozambique. in Chrysochloridae

Subspecies and Distribution. C. o. obtusirostris Peters, 1851 — Save and Changane river systems of C &amp; S Mozambique, with marginal intrusion into SE Zimbabwe and Limpopo Province of NE South Africa. C. o. chrysillus Thomas &amp; Schwann, 1905 — from Maputo, S Mozambique, S to Maputaland, NE KwaZulu-Natal, E South Africa. C. o. limpopoensis Roberts, 1946 — from around mouth of Limpopo River S to coastal plains near Maputo, SE Mozambique.

opennotspecifiedJul 2018View details →
zenodo32/100

Dataset used in Can process mining help in anomaly-based intrusion detection?

<p>This is the dataset used in the paper&nbsp;Can process mining help in anomaly-based intrusion detection?</p>

opencc-by-4.0Jun 2022View details →
zenodo32/100

real time intrusion detection systems

<p>This repository includes data and results in chapter 5 of PhD thesis &quot;A policy compliance detection architecture for data exchange infrastructures&quot;</p>

opencc-by-4.0Sep 2022View details →
zenodo32/100

IEC 60870-5-104 Intrusion Detection Dataset

<p><strong>IEC 60870-5-104</strong></p> <p><strong>Intrusion Detection Dataset</strong></p> <p><strong>Readme File</strong></p> <p>ITHACA &ndash; University of Western Macedonia - <a href="https://ithaca.ece.uowm.gr/">https://ithaca.ece.uowm.gr/</a></p> <p>Authors: Panagiotis Radoglou-Grammatikis, Thomas Lagkas, Vasileios Argyriou, Panagiotis Sarigiannidis</p> <p><strong>Publication Date:</strong> September 23, 2022</p> <p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p> <p>1.Introduction</p> <p>The evolution of the Industrial Internet of Things (IIoT) introduces several benefits, such as real-time monitoring, pervasive control and self-healing. However, despite the valuable services, security and privacy issues still remain given the presence of legacy and insecure communication protocols like IEC 60870-5-104. IEC 60870-5-104 is an industrial protocol widely applied in critical infrastructures, such as the smart electrical grid and industrial healthcare systems. The IEC 60870-5-104 Intrusion Detection Dataset was implemented in the context of the research paper entitled &quot;Modeling, Detecting, and Mitigating Threats Against Industrial Healthcare Systems: A Combined Software Defined Networking and Reinforcement Learning Approach&quot; [1], in the context of two H2020 projects: ELECTRON: rEsilient and seLf-healed EleCTRical pOwer Nanogrid (101021936) and SDN-microSENSE: SDN - microgrid reSilient Electrical eNergy SystEm (833955). This dataset includes labelled Transmission Control Protocol (TCP)/Internet Protocol (IP) network flow statistics (Common-Separated Values (CSV) format) and IEC 60870-5-104 flow statistics (CSV format) related to twelve IEC 60870-5-104 cyberattacks. In particular, the cyberattacks are related to unauthorised commands and Denial of Service (DoS) activities against IEC 60870-5-104. Moreover, the relevant Packet Capture (PCAP) files are available. The dataset can be utilised for Artificial Intelligence (AI)-based Intrusion Detection Systems (IDS), taking full advantage of Machine Learning (ML) and Deep Learning (DL).</p> <p>2.Instructions</p> <p>The IEC 60870-5-104 dataset was implemented following the methodology of A. Gharib et al. in [2], including eleven features: (a) Complete Network Configuration, (b) Complete Traffic, (c) Labelled Dataset, (d) Complete Interaction, (e) Complete Capture, (f) Available Protocols, (g) Attack Diversity, (h) Heterogeneity, (i) Feature Set and (j) Metadata.</p> <p>A network topology consisting of (a) seven industrial entities, (b) one Human Machine Interfaces (HMI) and (c) three cyberattackers was used to construct the IEC 60870-5-104 Intrusion Detection Dataset. The industrial entities use IEC TestServer<a href="#_ftn1">[1]</a>, while the HMI uses Qtester104<a href="#_ftn2">[2]</a>. On the other hand, the cyberattackers use Kali Linux<a href="#_ftn3">[3]</a> equipped with Metasploit<a href="#_ftn4">[4]</a>, OpenMUC j60870<a href="#_ftn5">[5]</a> and Ettercap<a href="#_ftn6">[6]</a>. The cyberattacks were performed during the following days.</p> <ul> <li>On Saturday, April 25, 2020, a DoS cyberattack (M_SP_NA_1_DoS) was executed for 2 hours, using the M_SP_NA_1 command.</li> <li>On Sunday, April 26, 2020, two cyberattacks were executed, namely (a) DoS (C_CI_NA_1_DoS) and (b) unauthorised injection (C_CI_NA_1), using the C_CI_NA_1 command for 2 hours.</li> <li>On Monday, April 27, 2020, one unauthorised injection attack (C_SE_NA_1) was executed for 4 hours, using the C_SE_NA_1 command.</li> <li>Tuesday, April 28, 2020 two cyberattacks were executed, namely (a) unauthorised injection (C_SC_NA_1) and (b) DoS (C_SE_NA_1_DoS), using the C_SC_NA_1 and C_SE_NA_1 commands for 2 hours and 4 hours, respectively.</li> <li>Wednesday, April 29, 2020, one DoS (C_SC_NA_1) cyberattack was performed for 2 hours, using the C_SC_NA_1 command.</li> <li>Friday, June 05, 2020, two cyberattacks were executed, namely (a) DoS (C_RD_NA_1_DoS) and (b) unauthorised injection (C_RD_NA_1), using the C_RD_NA_1 command for 2 and 4 hours, respectively.</li> <li>Saturday, June 06, 2020, two cyberattacks were executed, namely (a) DoS (C_RP_NA_1_DoS) and (b) unauthorised injection (C_RP_NA_1), using the C_RP_NA_1 command for 2 and 4 hours, respectively.</li> <li>Monday, June 08, 2020, a Man In The Middle (MITM) cyberattack was executed for 2 hours, filtering and dropping the IEC 60870-5-104 packets.</li> </ul> <p>For each attack, a 7zip file is provided, including the network traffic and the network flow statistics for each entity. Moreover, a relevant diagram is provided, illustrating the corresponding cyberattack. In particular, for each entity, a folder is given, including (a) the relevant pcap file, (b) Transmission Control Protocol (TCP) / Internet Protocol (IP) network flow statistics in a Common Separated Value (CSV) format and (c) IEC 60870-5-104 flow statistics in a CSV format. The TCP/IP network flow statistics were generated by CICFlowMeter<a href="#_ftn7">[7]</a>, while the IEC 60870-5-104 flow statistics were generated based on a Custom IEC 60870-5-104 Python Parser<a href="#_ftn8">[8]</a>, taking full advantage of Scapy<a href="#_ftn9">[9]</a>.</p> <p>3.Dataset Structure</p> <p>The dataset consists of the following files:</p> <ul> <li><strong>20200425_UOWM_IEC104_Dataset_m_sp_na_1_DoS.7z</strong>: A 7zip file including the pcap and CSV files related to the M_SP_NA_1 attack.</li> <li><strong>20200426_UOWM_IEC104_Dataset_c_ci_na_1_DoS.7z</strong>: A 7zip file including the pcap and CSV files related to the C_CI_NA_1_DoS attack.</li> <li><strong>20200426_UOWM_IEC104_Dataset_c_ci_na_1.7z</strong>: A 7zip file including the pcap and CSV files related to C_CI_NA_1 attack.</li> <li><strong>20200427_UOWM_IEC104_Dataset_c_se_na_1.7z</strong>: A 7zip file including the pcap and CSV files related to the C_SE_NA_1 attack.</li> <li><strong>20200428_UOWM_IEC104_Dataset_c_sc_na_1.7z</strong>: A 7zip file including the pcap and CSV files related to the C_SC_NA_1 attack.</li> <li><strong>20200428_UOWM_IEC104_Dataset_c_se_na_1_DoS.7z</strong>: A 7zip file including the pcap and CSV files related to the C_SE_NA_1_DoS attack.</li> <li><strong>20200429_UOWM_IEC104_Dataset_c_sc_na_1_DoS.7z</strong>: A 7zip file including the pcap and CSV files related to the C_SC_NA_1_DoS attack.</li> <li><strong>20200605_UOWM_IEC104_Dataset_c_rd_na_1_DoS.7z</strong>: A 7zip file including the pcap and CSV files related to the C_RD_NA_1_DoS attack.</li> <li><strong>20200605_UOWM_IEC104_Dataset_c_rd_na_1.7z</strong>: A 7zip file including the pcap and CSV files related to the C_RD_NA_1 attack.</li> <li><strong>20200606_UOWM_IEC104_Dataset_c_rp_na_1_DoS.7z</strong>: A 7zip file including the pcap and CSV files related to the C_RP_NA_1_DoS attack.</li> <li><strong>20200606_UOWM_IEC104_Dataset_c_rp_na_1.7z</strong>: A 7zip file including the pcap and CSV files related to the C_RP_NA_1 attack.</li> <li><strong>20200608_UOWM_IEC104_Dataset_mitm_drop.7z</strong>: A 7zip file including the pcap and CSV files related to the MITM attack.</li> <li><strong>Balanced_IEC104_Train_Test_CSV_Files.zip</strong>: This zip file includes balanced CSV files from CICFlowMeter and the Custom IEC 60870-5-104 Python Parser that could be utilised for training ML and DL methods. The zip file includes different folders for the corresponding flow timeout values used for CICFlowMeter and IEC 60870-5-104 Python Parser, respectively.</li> </ul> <p>Each 7zip file includes respective folders related to the entities/devices (described in the following section) participating in each attack. In particular, for each entity/device, there is a folder including (a) the overall network traffic (pcap file) related to this entity/device during each attack, (b) the TCP/IP network flow statistics (CSV file) from CICFlowMeter for the overall network traffic, (c) the IEC 60870-5-104 network traffic (pcap file) related to this entity/device during each attack, (d) the TCP/IP network flow statistics (CSV file) from CICFlowMeter for the IEC 608770-5-104 network traffic, (e) the IEC 60870-5-104 flow statistics (CSV file) from the Custom IEC 60870-5-104 Python Parser for the IEC 608770-5-104 network traffic and finally, (f) an image showing how the attack was executed. Finally, it is noteworthy that the network flow from both CICFlowMeter and Custom IEC 60870-5-104 Python Parser in each CSV file are <strong>labelled</strong> based on the IEC 60870-5-104 cyberattacks executed for the generation of this dataset. The description of these attacks is given in the following section, while the various features from CICFlowMeter and Custom IEC 60870-5-104 Python Parser are presented in Section 5.</p> <p>4.Testbed &amp; IEC 60870-5-104 Attacks</p> <p>The testbed created for generating this dataset is composed of five virtual RTU devices emulated by IEC TestServer and two real RTU devices. Moreover, there is another workstation which plays the role of Master Terminal Unit (MTU) and HMI, sending legitimate IEC 60870-5-104 commands to the corresponding RTUs. For this purpose, the workstation uses QTester104. In addition, there are three attackers that act as malicious insiders executing the following cyberattacks against the aforementioned RTUs. Finally, the network traffic data of each entity/device was captured through tshark.</p> <p>Table 1: IEC 60870-5-104 Cyberattacks Description</p> <table> <tbody> <tr> <td> <p><strong>IEC 60870-5-104 Cyberattack Description</strong></p> </td> <td> <p><strong>Description</strong></p> </td> <td> <p><strong>Dataset Files</strong></p> </td> </tr> <tr> <td> <p>MITM Drop</p> </td> <td> <p>During this attack, the cyberattacker is placed between two endpoints, thus monitoring and dropping the network traffic exchanged.</p> </td> <td> <p>20200608_UOWM_IEC104_Dataset_mitm_drop.7z</p> </td> </tr> <tr> <td> <p>C_CI_NA_1</p> </td> <td> <p>The C_CI_NA_1 is a Counter Interrogation command in the control direction. This cyberattack sends unauthorised IEC 60870-5-104 C_CI_NA_1 packets to the target system.</p> </td> <td> <p>20200426_UOWM_IEC104_Dataset_c_ci_na_1.7z</p> </td> </tr> <tr> <td> <p>C_SC_NA_1</p> </td> <td> <p>The C_SC_NA_1 command is a single command. This cyberattack sends unauthorised C_SC_NA_1 60870-5-104 packets to the target system</p> </td> <td> <p>20200428_UOWM_IEC104_Dataset_c_sc_na_1.7z</p> </td> </tr> <tr> <td> <p>C_SE_NA_1</p> </td> <td> <p>The C_SE_NA_1 command is a set-point command with normalised values. This cyberattack sends unauthorised IEC 60870-5-104 C_SE_NA_1 packets to the target system.</p> </td> <td> <p>20200427_UOWM_IEC104_Dataset_c_se_na_1.7z</p> </td> </tr> <tr> <td> <p>C_RD_NA_1</p> </td> <td> <p>The C_RD_NA_1 command is a read command. This cyberattack sends unauthorised IEC 60870-5-104 C_RD_NA_1 packets to the target system.</p> </td> <td> <p>20200605_UOWM_IEC104_Dataset_c_rd_na_1.7z</p> </td> </tr> <tr> <td> <p>C_RP_NA_1</p> </td> <td> <p>The C_RP_NA_1 command is a reset command. This cyberattack sends unauthorised IEC 60870-5-104 C_RP_NA_1 packets to the target system.</p> </td> <td> <p>20200606_UOWM_IEC104_Dataset_c_rp_na_1.7z</p> </td> </tr> <tr> <td> <p>M_SP_NA_1_DoS</p> </td> <td> <p>This attack floods the target system with IEC 60870-5-104 M_SP_NA_1 packets.</p> </td> <td> <p>20200425_UOWM_IEC104_Dataset_m_sp_na_1_DoS.7z</p> </td> </tr> <tr> <td> <p>C_CI_NA_1_DoS</p> </td> <td> <p>This attack floods the target system with IEC 60870-5-104 C_CI_NA_1 packets.</p> </td> <td> <p>20200426_UOWM_IEC104_Dataset_c_ci_na_1_DoS.7z</p> </td> </tr> <tr> <td> <p>C_SE_NA_1_DoS</p> </td> <td> <p>This attack floods the target system with IEC 60870-5-104 C_SE_NA_1 packets.</p> </td> <td> <p>20200428_UOWM_IEC104_Dataset_c_se_na_1_DoS.7z</p> </td> </tr> <tr> <td> <p>C_SC_NA_1_DoS</p> </td> <td> <p>This attack floods the target system with IEC 60870-5-104 C_SC_NA_1 packets.</p> </td> <td> <p>20200429_UOWM_IEC104_Dataset_c_sc_na_1_DoS.7z</p> </td> </tr> <tr> <td> <p>C_RD_NA_1_DoS</p> </td> <td> <p>This attack floods the target system with IEC 60870-5-104 C_RD_NA_1 packets.</p> </td> <td> <p>20200605_UOWM_IEC104_Dataset_c_rd_na_1_DoS.7z</p> </td> </tr> <tr> <td> <p>C RP NA 1 DoS</p> </td> <td> <p>This attack floods the target system with IEC 60870-5-104 C_RP_NA_1 packets.</p> </td> <td> <p>20200606_UOWM_IEC104_Dataset_c_rp_na_1_DoS.7z</p> </td> </tr> </tbody> </table> <p>5.Features</p> <p>The TCP/IP network flow statistics generated by CICFlowMeter are summarised below. <strong>It is worth mentioning that the TCP/IP network flows and their statistics generated by </strong><strong>CICFlowMeter are labelled based on the IEC 60870-5-104 attacks described above, thus allowing the training of ML/DL models.</strong></p> <p>Table 2: CICFlowMeter TCP/IP Network Flow Statistics - Features</p> <table> <tbody> <tr> <td> <p><strong>Feature</strong></p> </td> <td> <p><strong>Description</strong></p> </td> </tr> <tr> <td> <p>Flow ID</p> </td> <td> <p>ID of the flow</p> </td> </tr> <tr> <td> <p>Src IP</p> </td> <td> <p>Source IP address</p> </td> </tr> <tr> <td> <p>Src Port</p> </td> <td> <p>Source TCP/UDP port</p> </td> </tr> <tr> <td> <p>Dst IP</p> </td> <td> <p>Destination IP address</p> </td> </tr> <tr> <td> <p>Dst Port</p> </td> <td> <p>Destination TCP/UDP port</p> </td> </tr> <tr> <td> <p>Protocol</p> </td> <td> <p>The protocol related to the corresponding flow</p> </td> </tr> <tr> <td> <p>Timestamp</p> </td> <td> <p>Flow timestamp</p> </td> </tr> <tr> <td> <p>Flow Duration</p> </td> <td> <p>Duration of the flow in Microsecond</p> </td> </tr> <tr> <td> <p>Tot Fwd Pkts</p> </td> <td> <p>Total packets in the forward direction</p> </td> </tr> <tr> <td> <p>Tot Bwd Pkts</p> </td> <td> <p>Total packets in the backward direction</p> </td> </tr> <tr> <td> <p>TotLen Fwd Pkts</p> </td> <td> <p>Total size of packets in forward direction</p> </td> </tr> <tr> <td> <p>TotLen Bwd Pkts</p> </td> <td> <p>Total size of packets in backward direction</p> </td> </tr> <tr> <td> <p>Fwd Pkt Len Max</p> </td> <td> <p>Maximum size of packet in forward direction</p> </td> </tr> <tr> <td> <p>Fwd Pkt Len Min</p> </td> <td> <p>Minimum size of packet in forward direction</p> </td> </tr> <tr> <td> <p>Fwd Pkt Len Mean</p> </td> <td> <p>Mean size of packet in forward direction</p> </td> </tr> <tr> <td> <p>Fwd Pkt Len Std</p> </td> <td> <p>Standard deviation size of packet in forward direction</p> </td> </tr> <tr> <td> <p>Bwd Pkt Len Max</p> </td> <td> <p>Maximum size of packet in backward direction</p> </td> </tr> <tr> <td> <p>Bwd Pkt Len Min</p> </td> <td> <p>Minimum size of packet in backward direction</p> </td> </tr> <tr> <td> <p>Bwd Pkt Len Mean</p> </td> <td> <p>Mean size of packet in backward direction</p> </td> </tr> <tr> <td> <p>Bwd Pkt Len Std</p> </td> <td> <p>Standard deviation size of packet in backward direction</p> </td> </tr> <tr> <td> <p>Flow Byts/s</p> </td> <td> <p>Number of flow bytes per second</p> </td> </tr> <tr> <td> <p>Flow Pkts/s</p> </td> <td> <p>Number of flow packets per second</p> </td> </tr> <tr> <td> <p>Flow IAT Mean</p> </td> <td> <p>Mean time between two packets sent in the flow</p> </td> </tr> <tr> <td> <p>Flow IAT Std</p> </td> <td> <p>Standard deviation time between two packets sent in the flow</p> </td> </tr> <tr> <td> <p>Flow IAT Max</p> </td> <td> <p>Maximum time between two packets sent in the flow</p> </td> </tr> <tr> <td> <p>Flow IAT Min</p> </td> <td> <p>Minimum time between two packets sent in the flow</p> </td> </tr> <tr> <td> <p>Fwd IAT Tot</p> </td> <td> <p>Total time between two packets sent in the forward direction</p> </td> </tr> <tr> <td> <p>Fwd IAT Mean</p> </td> <td> <p>Mean time between two packets sent in the forward direction</p> </td> </tr> <tr> <td> <p>Fwd IAT Std</p> </td> <td> <p>Standard deviation time between two packets sent in the forward direction</p> </td> </tr> <tr> <td> <p>Fwd IAT Max</p> </td> <td> <p>Maximum time between two packets sent in the forward direction</p> </td> </tr> <tr> <td> <p>Fwd IAT Min</p> </td> <td> <p>Minimum time between two packets sent in the forward direction</p> </td> </tr> <tr> <td> <p>Bwd IAT Tot</p> </td> <td> <p>Total time between two packets sent in the backward direction</p> </td> </tr> <tr> <td> <p>Bwd IAT Mean</p> </td> <td> <p>Mean time between two packets sent in the backward direction</p> </td> </tr> <tr> <td> <p>Bwd IAT Std</p> </td> <td> <p>Standard deviation time between two packets sent in the backward direction</p> </td> </tr> <tr> <td> <p>Bwd IAT Max</p> </td> <td> <p>Maximum time between two packets sent in the backward direction</p> </td> </tr> <tr> <td> <p>Bwd IAT Min</p> </td> <td> <p>Minimum time between two packets sent in the backward direction</p> </td> </tr> <tr> <td> <p>Fwd PSH Flags</p> </td> <td> <p>Number of times the PSH flag was set in packets travelling in the forward direction (0 for UDP)</p> </td> </tr> <tr> <td> <p>Bwd PSH Flags</p> </td> <td> <p>Number of times the PSH flag was set in packets travelling in the backward direction (0 for UDP)</p> </td> </tr> <tr> <td> <p>Fwd URG Flags</p> </td> <td> <p>Number of times the URG flag was set in packets travelling in the forward direction (0 for UDP)</p> </td> </tr> <tr> <td> <p>Bwd URG Flags</p> </td> <td> <p>Number of times the URG flag was set in packets travelling in the backward direction (0</p> <p>for UDP)</p> </td> </tr> <tr> <td> <p>Fwd Header Len</p> </td> <td> <p>Total bytes used for headers in the forward direction</p> </td> </tr> <tr> <td> <p>Bwd Header Len</p> </td> <td> <p>Total bytes used for headers in the backward direction</p> </td> </tr> <tr> <td> <p>Fwd Pkts/s</p> </td> <td> <p>Number of forward packets per second</p> </td> </tr> <tr> <td> <p>Bwd Pkts/s</p> </td> <td> <p>Number of backward packets per second</p> </td> </tr> <tr> <td> <p>Pkt Len Min</p> </td> <td> <p>Minimum length of a packet</p> </td> </tr> <tr> <td> <p>Pkt Len Max</p> </td> <td> <p>Maximum length of a packet</p> </td> </tr> <tr> <td> <p>Pkt Len Mean</p> </td> <td> <p>Mean length of a packet</p> </td> </tr> <tr> <td> <p>Pkt Len Std</p> </td> <td> <p>Standard deviation length of a packet</p> </td> </tr> <tr> <td> <p>Pkt Len Var</p> </td> <td> <p>Variance length of a packet</p> </td> </tr> <tr> <td> <p>FIN Flag Cnt</p> </td> <td> <p>Number of packets with FIN</p> </td> </tr> <tr> <td> <p>SYN Flag Cnt</p> </td> <td> <p>Number of packets with SYN</p> </td> </tr> <tr> <td> <p>RST Flag Cnt</p> </td> <td> <p>Number of packets with RST</p> </td> </tr> <tr> <td> <p>PSH Flag Cnt</p> </td> <td> <p>Number of packets with PUSH</p> </td> </tr> <tr> <td> <p>ACK Flag Cnt</p> </td> <td> <p>Number of packets with ACK</p> </td> </tr> <tr> <td> <p>URG Flag Cnt</p> </td> <td> <p>Number of packets with URG</p> </td> </tr> <tr> <td> <p>CWE Flag Count</p> </td> <td> <p>Number of packets with CWE</p> </td> </tr> <tr> <td> <p>ECE Flag Cnt</p> </td> <td> <p>Number of packets with ECE</p> </td> </tr> <tr> <td> <p>Down/Up Ratio</p> </td> <td> <p>Download and upload ratio</p> </td> </tr> <tr> <td> <p>Pkt Size Avg</p> </td> <td> <p>Average size of packet</p> </td> </tr> <tr> <td> <p>Fwd Seg Size Avg</p> </td> <td> <p>Average size observed in the forward direction</p> </td> </tr> <tr> <td> <p>Bwd Seg Size Avg</p> </td> <td> <p>Average size observed in the backward direction</p> </td> </tr> <tr> <td> <p>Fwd Byts/b Avg</p> </td> <td> <p>Average number of bytes bulk rate in the forward direction</p> </td> </tr> <tr> <td> <p>Fwd Pkts/b Avg</p> </td> <td> <p>Average number of packets bulk rate in the forward direction</p> </td> </tr> <tr> <td> <p>Fwd Blk Rate Avg</p> </td> <td> <p>Average number of bulk rate in the forward direction</p> </td> </tr> <tr> <td> <p>Bwd Byts/b Avg</p> </td> <td> <p>Average number of bytes bulk rate in the backward direction</p> </td> </tr> <tr> <td> <p>Bwd Pkts/b Avg</p> </td> <td> <p>Average number of packets bulk rate in the backward direction</p> </td> </tr> <tr> <td> <p>Bwd Blk Rate Avg</p> </td> <td> <p>Average number of bulk rate in the backward direction</p> </td> </tr> <tr> <td> <p>Subflow Fwd Pkts</p> </td> <td> <p>The average number of packets in a sub flow in the forward direction</p> </td> </tr> <tr> <td> <p>Subflow Fwd Byts</p> </td> <td> <p>The average number of bytes in a sub flow in the forward direction</p> </td> </tr> <tr> <td> <p>Subflow Bwd Pkts</p> </td> <td> <p>The average number of packets in a sub flow in the backward direction</p> </td> </tr> <tr> <td> <p>Subflow Bwd Byts</p> </td> <td> <p>The average number of bytes in a sub flow in the backward direction</p> </td> </tr> <tr> <td> <p>Init Fwd Win Byts</p> </td> <td> <p>The total number of bytes sent in initial window in the forward direction</p> </td> </tr> <tr> <td> <p>Init Bwd Win Byts</p> </td> <td> <p>The total number of bytes sent in initial window in the backward direction</p> </td> </tr> <tr> <td> <p>Fwd Act Data Pkts</p> </td> <td> <p>Count of packets with at least 1 byte of TCP data payload in the forward direction</p> </td> </tr> <tr> <td> <p>Fwd Seg Size Min</p> </td> <td> <p>Minimum segment size observed in the forward direction</p> </td> </tr> <tr> <td> <p>Active Mean</p> </td> <td> <p>Mean time a flow was active before becoming idle</p> </td> </tr> <tr> <td> <p>Active Std</p> </td> <td> <p>Standard deviation time a flow was active before becoming idle</p> </td> </tr> <tr> <td> <p>Active Max</p> </td> <td> <p>Maximum time a flow was active before becoming idle</p> </td> </tr> <tr> <td> <p>Active Min</p> </td> <td> <p>Minimum time a flow was active before becoming idle</p> </td> </tr> <tr> <td> <p>Idle Mean</p> </td> <td> <p>Mean time a flow was idle before becoming active</p> </td> </tr> <tr> <td> <p>Idle Std</p> </td> <td> <p>Standard deviation time a flow was idle before becoming active</p> </td> </tr> <tr> <td> <p>Idle Max</p> </td> <td> <p>Maximum time a flow was idle before becoming active</p> </td> </tr> <tr> <td> <p>Idle Min</p> </td> <td> <p>Minimum time a flow was idle before becoming active</p> </td> </tr> <tr> <td> <p>Label</p> </td> <td> <p>Attack label</p> </td> </tr> </tbody> </table> <p>The IEC 60870-5-104 flow statistics generated by IEC 60870-5-104 Python Parser are summarised below. <strong>It is worth mentioning that the IEC 60870-5-104 flows and their statistics generated by </strong><strong>IEC 60870-5-104 Python Parser are labelled based on the IEC 60870-5-104 attacks described above, thus allowing the training of ML/DL models.</strong></p> <p>Table 3: IEC 60870-5-104 Flow Statistics &ndash; Features</p> <table> <tbody> <tr> <td> <p><strong>Feature</strong></p> </td> <td> <p><strong>Field description</strong></p> </td> </tr> <tr> <td> <p>flow id</p> </td> <td> <p>ID of the flow</p> </td> </tr> <tr> <td> <p>protocol</p> </td> <td> <p>The relevant protocol of the flow. It equals IEC 60870-5-104</p> </td> </tr> <tr> <td> <p>src ip</p> </td> <td> <p>The source IP address of the flow. It is defined with the first relevant packet.</p> </td> </tr> <tr> <td> <p>dst ip</p> </td> <td> <p>The destination IP address of the flow.</p> </td> </tr> <tr> <td> <p>src port</p> </td> <td> <p>The source TCP/UDP port.</p> </td> </tr> <tr> <td> <p>dst port</p> </td> <td> <p>The destination TCP/UDP port.</p> </td> </tr> <tr> <td> <p>flow idle time max</p> </td> <td> <p>The maximum time where the flow was idle</p> </td> </tr> <tr> <td> <p>flow idle time min</p> </td> <td> <p>The minimum time where the flow was idle</p> </td> </tr> <tr> <td> <p>flow idle time mean</p> </td> <td> <p>The time mean where the flow was idle</p> </td> </tr> <tr> <td> <p>flow idle time std</p> </td> <td> <p>The time standard deviation where the flow was idle</p> </td> </tr> <tr> <td> <p>flow idle time variance</p> </td> <td> <p>The time variance where the flow was idle</p> </td> </tr> <tr> <td> <p>flow active time max</p> </td> <td> <p>The maximum time where the flow was active</p> </td> </tr> <tr> <td> <p>flow active time min</p> </td> <td> <p>The minimum time where the flow was active</p> </td> </tr> <tr> <td> <p>flow active time mean</p> </td> <td> <p>The time mean where the flow was active</p> </td> </tr> <tr> <td> <p>flow active time std</p> </td> <td> <p>The time standard deviation where the flow was active</p> </td> </tr> <tr> <td> <p>flow active time variance</p> </td> <td> <p>The time variance where the flow was active</p> </td> </tr> <tr> <td> <p>flow IAT max</p> </td> <td> <p>The maximum interarrival time</p> </td> </tr> <tr> <td> <p>fw IAT max</p> </td> <td> <p>The maximum interarrival time in the forward direction</p> </td> </tr> <tr> <td> <p>bw IAT max</p> </td> <td> <p>The maximum interarrival time in the backyard direction</p> </td> </tr> <tr> <td> <p>flow IAT min</p> </td> <td> <p>The minimum interarrival time</p> </td> </tr> <tr> <td> <p>fw IAT min</p> </td> <td> <p>The minimum interarrival time in the forward direction</p> </td> </tr> <tr> <td> <p>bw IAT min</p> </td> <td> <p>The minimum interarrival time in the backyard direction</p> </td> </tr> <tr> <td> <p>flow IAT mean</p> </td> <td> <p>The mean of the interarrival time</p> </td> </tr> <tr> <td> <p>fw IAT mean</p> </td> <td> <p>The mean of the interarrival time in the forward direction</p> </td> </tr> <tr> <td> <p>bw IAT mean</p> </td> <td> <p>The mean of the interarrival time in the backyard direction</p> </td> </tr> <tr> <td> <p>flow IAT std</p> </td> <td> <p>The standard deviation of the inter arrival time</p> </td> </tr> <tr> <td> <p>fw IAT std</p> </td> <td> <p>The standard deviation of the inter arrival time in the forward direction</p> </td> </tr> <tr> <td> <p>bw IAT std</p> </td> <td> <p>The standard deviation of the inter arrival time in the backyard direction</p> </td> </tr> <tr> <td> <p>flow IAT tot</p> </td> <td> <p>The total number of the interarrival times</p> </td> </tr> <tr> <td> <p>fw iAT tot</p> </td> <td> <p>The total number of the interarrival times in the forward direction</p> </td> </tr> <tr> <td> <p>bw IAT tot</p> </td> <td> <p>The total number of the interarrival times in the backyard direction</p> </td> </tr> <tr> <td> <p>flow iec104 packts/s</p> </td> <td> <p>The number of IEC 60870-51-04 packets per second</p> </td> </tr> <tr> <td> <p>fw iec104 packts/s</p> </td> <td> <p>The number of IEC 60870-51-04 packets per second in the forward direction</p> </td> </tr> <tr> <td> <p>bw iec104 packts/s</p> </td> <td> <p>The number of IEC 60870-51-04 packets per second in the backyard direction</p> </td> </tr> <tr> <td> <p>flow iec104 bytes/s</p> </td> <td> <p>The sum of APDU lengths per second</p> </td> </tr> <tr> <td> <p>fw iec104 bytes/s</p> </td> <td> <p>The sum of APDU lengths per second in the forward direction</p> </td> </tr> <tr> <td> <p>bw iec104 bytes/s</p> </td> <td> <p>The sum of APDU lengths per second in the backyard direction</p> </td> </tr> <tr> <td> <p>flow packet APDU length max</p> </td> <td> <p>The maximum value of the APDU lengths</p> </td> </tr> <tr> <td> <p>flow packet APDU length min</p> </td> <td> <p>The minimum value of the APDU lengths</p> </td> </tr> <tr> <td> <p>flow packet APDU length mean</p> </td> <td> <p>Mean of the APDU lengths</p> </td> </tr> <tr> <td> <p>flow packet APDU length std</p> </td> <td> <p>The standard deviation of the APDU lengths</p> </td> </tr> <tr> <td> <p>flow packet APDU length var</p> </td> <td> <p>Variance of the APDU lengths</p> </td> </tr> <tr> <td> <p>fw packet APDU length max</p> </td> <td> <p>The maximum value of the APDU lengths in the forward direction</p> </td> </tr> <tr> <td> <p>fw packet APDU length min</p> </td> <td> <p>The minimum value of the APDU lengths in the forward direction</p> </td> </tr> <tr> <td> <p>fw packet APDU length mean</p> </td> <td> <p>Mean of the APDU lengths in the forward direction</p> </td> </tr> <tr> <td> <p>fw packet APDU length std</p> </td> <td> <p>The standard deviation of the APDU lengths in the forward direction</p> </td> </tr> <tr> <td> <p>fw packet APDU length var</p> </td> <td> <p>The variance of the APDU lengths in the forward direction</p> </td> </tr> <tr> <td> <p>bw packet APDU length max</p> </td> <td> <p>The maximum value of the APDU lengths in the backyard direction</p> </td> </tr> <tr> <td> <p>bw packet APDU length min</p> </td> <td> <p>The minimum value of the APDU lengths in the backyard direction</p> </td> </tr> <tr> <td> <p>bw packet APDU length mean</p> </td> <td> <p>Mean of the APDU lengths in the backyard direction</p> </td> </tr> <tr> <td> <p>bw packet APDU length std</p> </td> <td> <p>The standard deviation of the APDU lengths in the backyard direction</p> </td> </tr> <tr> <td> <p>bw packet APDU length var</p> </td> <td> <p>The variance of the APDU lengths in the backyard direction</p> </td> </tr> <tr> <td> <p>total flow packets</p> </td> <td> <p>Total flow packets</p> </td> </tr> <tr> <td> <p>total fw packets</p> </td> <td> <p>Total flow packets in the forward direction</p> </td> </tr> <tr> <td> <p>total bw packets</p> </td> <td> <p>Total flow packets in the backyard direction</p> </td> </tr> <tr> <td> <p>flow packets APDU total length</p> </td> <td> <p>The sum of all APDU lengths</p> </td> </tr> <tr> <td> <p>fw packets APDU total length</p> </td> <td> <p>The sum of all APDU lengths in the forward direction</p> </td> </tr> <tr> <td> <p>bw packets APDU total length</p> </td> <td> <p>The sum of all APDU lengths in the backyard direction</p> </td> </tr> <tr> <td> <p>flow duration</p> </td> <td> <p>Flow duration in seconds</p> </td> </tr> <tr> <td> <p>flow down/up ratio</p> </td> <td> <p>The fraction between the IEC 60870-5-104 packets in the backyard direction and the IEC 60870-5-104 packets in the forward direction</p> </td> </tr> <tr> <td> <p>flow total IEC104_I_Message_SeqIOA packets</p> </td> <td> <p>The total number of the I-format APCI packets that have more than one information objects</p> </td> </tr> <tr> <td> <p>fw total IEC104_I_Message_SeqIOA packets</p> </td> <td> <p>The total number of the I-format APCI packets that have more than one information objects in the forward direction</p> </td> </tr> <tr> <td> <p>bw total IEC104_I_Message_SeqIOA packets</p> </td> <td> <p>The total number of the I-format APCI packets that have more than one information objects in the backyard direction</p> </td> </tr> <tr> <td> <p>flow total IEC104_I_Message_SingleIOA packets</p> </td> <td> <p>The total number of the I-format APCI packets that have one information object in ASDU</p> </td> </tr> <tr> <td> <p>fw total IEC104_I_Message_SingleIOA packets</p> </td> <td> <p>The total number of the I-format APCI packets that have one information object in ASDU in the forward direction</p> </td> </tr> <tr> <td> <p>bw total IEC104_I_Message_SingleIOA packets</p> </td> <td> <p>The total number of the I-format APCI packets that have one information object in ASDU in the backyard direction</p> </td> </tr> <tr> <td> <p>flow total IEC104_S_Message packets</p> </td> <td> <p>The total number of the S-format APCI packets</p> </td> </tr> <tr> <td> <p>fw total IEC104_S_Message packets</p> </td> <td> <p>The total number of the S-format APCI packets in the forward direction</p> </td> </tr> <tr> <td> <p>bw total IEC104_S_Message packets</p> </td> <td> <p>The total number of the S-format APCI packets in the backyard direction</p> </td> </tr> <tr> <td> <p>flow total IEC104_U_Message packets</p> </td> <td> <p>The total number of the U-format APCI packets</p> </td> </tr> <tr> <td> <p>fw total IEC104_U_Message packets</p> </td> <td> <p>The total number of the U-format APCI packets in the forward direction</p> </td> </tr> <tr> <td> <p>bw total IEC104_U_Message packets</p> </td> <td> <p>The total number of the U-format APCI packets in the backyard direction</p> </td> </tr> <tr> <td> <p>fw URG flag amount</p> </td> <td> <p>The number of the URG flags in the forward direction</p> </td> </tr> <tr> <td> <p>fw PSH flag amount</p> </td> <td> <p>The number of the PSH flags in the forward direction</p> </td> </tr> <tr> <td> <p>bw URG flag amount</p> </td> <td> <p>The number of the URG flags in the backyard direction</p> </td> </tr> <tr> <td> <p>bw PSH flag amount</p> </td> <td> <p>The number of the PSH flags in the backyard direction</p> </td> </tr> <tr> <td> <p>flow SYN flag count</p> </td> <td> <p>The number of the TCP SYN packets</p> </td> </tr> <tr> <td> <p>flow RST flag count</p> </td> <td> <p>The number of the TCP RST packets</p> </td> </tr> <tr> <td> <p>flow PSH flag count</p> </td> <td> <p>The number of the TCP PSH packets</p> </td> </tr> <tr> <td> <p>flow ACK flag count</p> </td> <td> <p>The number of the TCP ACK packets</p> </td> </tr> <tr> <td> <p>flow URG flag count</p> </td> <td> <p>The number of the TCP URG packets</p> </td> </tr> <tr> <td> <p>flow CWE flag count</p> </td> <td> <p>The number of the TCP CWE packets</p> </td> </tr> <tr> <td> <p>flow ECE flag count</p> </td> <td> <p>The number of the TCP ECE packets</p> </td> </tr> <tr> <td> <p>fw_subflow_packets</p> </td> <td> <p>The average number of packets in a sub flow in the forward direction</p> </td> </tr> <tr> <td> <p>bw_subflow_packets</p> </td> <td> <p>The average number of packets in a sub flow in the backward direction</p> </td> </tr> <tr> <td> <p>fw_subflow_bytes</p> </td> <td> <p>The average number of bytes in a sub flow in the forward direction</p> </td> </tr> <tr> <td> <p>bw_subflow_bytes</p> </td> <td> <p>The average number of bytes in a sub flow in the backward direction</p> </td> </tr> <tr> <td> <p>flow start timestamp</p> </td> <td> <p>The timestamp of the flow. It is defined with the first relevant packet.</p> </td> </tr> <tr> <td> <p>fw avg bytes/bulk</p> </td> <td> <p>Average number of bytes bulk rate in the forward direction</p> </td> </tr> <tr> <td> <p>bw avg bytes/bulk</p> </td> <td> <p>Average number of bytes bulk rate in the backyard direction</p> </td> </tr> <tr> <td> <p>fw avg bulk rate</p> </td> <td> <p>Average number of bulk rate in the forward direction</p> </td> </tr> <tr> <td> <p>bw avg bulk rate</p> </td> <td> <p>Average number of bulk rate in the backyard direction</p> </td> </tr> <tr> <td> <p>fw avg packets/bulk</p> </td> <td> <p>Average number of packets bulk rate in the forward direction</p> </td> </tr> <tr> <td> <p>bw avg packets/bulk</p> </td> <td> <p>Average number of packets bulk rate in the backyard direction</p> </td> </tr> <tr> <td> <p>init fw window bytes</p> </td> <td> <p>The window size of the first packet in the forward direction</p> </td> </tr> <tr> <td> <p>init bw window bytes</p> </td> <td> <p>The window size of the first packet in the backyard direction</p> </td> </tr> <tr> <td> <p>fw TCP total header length</p> </td> <td> <p>The length of the TCP headers in the forward direction</p> </td> </tr> <tr> <td> <p>bw TCP total header length</p> </td> <td> <p>The length of the TCP headers in the backyard direction</p> </td> </tr> <tr> <td> <p>cot=1</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where COT = 1 (periodic,cyclic)</p> </td> </tr> <tr> <td> <p>cot=2</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where COT = 2 (background interrogation)</p> </td> </tr> <tr> <td> <p>cot=3</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where COT = 3 (spontaneous)</p> </td> </tr> <tr> <td> <p>cot=4</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where COT = 4 (initialized)</p> </td> </tr> <tr> <td> <p>cot=5</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where COT = 5 (interrogation)</p> </td> </tr> <tr> <td> <p>cot=6</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where COT = 6 (activation)</p> </td> </tr> <tr> <td> <p>cot=7</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where COT = 7 (confirmation activation)</p> </td> </tr> <tr> <td> <p>cot=8</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where COT = 8 (deactivation)</p> </td> </tr> <tr> <td> <p>cot=9</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where COT = 9 (confirmation deactivation)</p> </td> </tr> <tr> <td> <p>cot=10</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where COT = 10 (termination activation)</p> </td> </tr> <tr> <td> <p>cot=11</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where COT = 11 (feedback, caused by distant command)</p> </td> </tr> <tr> <td> <p>cot=12</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where COT = 12 (feedback, caused by local command)</p> </td> </tr> <tr> <td> <p>cot=13</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where COT = 13 (COT data transmission)</p> </td> </tr> <tr> <td> <p>cot=20</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where COT = 20 (interrogated by general interrogation)</p> </td> </tr> <tr> <td> <p>type_id_process_information_in_monitor_direction</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where TypeID is in the range 1-40</p> </td> </tr> <tr> <td> <p>type_id_process_information_in_control_direction</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where TypeID is in the range 45-51</p> </td> </tr> <tr> <td> <p>type_id_system_information_in_monitor_direction</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where TypeID is in the range 70</p> </td> </tr> <tr> <td> <p>type_id_system_information_in_control_direction</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where TypeID is in the range 100-106</p> </td> </tr> <tr> <td> <p>type_id_parameter_in_control_direction</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where TypeID is in the range 110-113</p> </td> </tr> <tr> <td> <p>type_id_file_transfer</p> </td> <td> <p>The total number of the IEC 60870-5-104 packets where TypeID is in the range 120-126</p> </td> </tr> <tr> <td> <p>Label</p> </td> <td> <p>Attack label</p> </td> </tr> </tbody> </table> <p>6.Citation</p> <p>Please cite the following paper when using this dataset:</p> <p><em>P. Radoglou-Grammatikis, K. Rompolos, P. Sarigiannidis, V. Argyriou, T. Lagkas, A. Sarigiannidis, S. Goudos and S. Wan, &quot;Modeling, Detecting, and Mitigating Threats Against Industrial Healthcare Systems: A Combined Software Defined Networking and Reinforcement Learning Approach&quot;, in IEEE Transactions on Industrial Informatics, vol. 18, no. 3, pp. 2041-2052, March 2022, doi: 10.1109/TII.2021.3093905.</em></p> <p><a href="https://ieeexplore.ieee.org/document/9470933"><em>https://ieeexplore.ieee.org/document/9470933</em></a></p> <p>7.Acknowledgment</p> <p>This project has received funding from the European Union&rsquo;s Horizon 2020 research and innovation programme under grant agreements No 101021936 (ELECTRON) and No 833955 (SDN-microSENSE).</p> <p>References</p> <ol> <li>P. Radoglou-Grammatikis, K. Rompolos, P. Sarigiannidis, V. Argyriou, T. Lagkas, A. Sarigiannidis, S. Goudos and S. Wan, &quot;Modeling, Detecting, and Mitigating Threats Against Industrial Healthcare Systems: A Combined Software Defined Networking and Reinforcement Learning Approach&quot;, in IEEE Transactions on Industrial Informatics, vol. 18, no. 3, pp. 2041-2052, March 2022, doi: 10.1109/TII.2021.3093905.</li> <li>A. Gharib, I. Sharafaldin, A. H. Lashkari and A. A. Ghorbani, &quot;An Evaluation Framework for Intrusion Detection Dataset,&quot; 2016 International Conference on Information Science and Security (ICISS), 2016, pp. 1-6, doi: 10.1109/ICISSEC.2016.7885840.</li> </ol> <p>&nbsp;</p> <p><a href="#_ftnref1">[1]</a> IEC TestServer - https://sourceforge.net/projects/iecserver/</p> <p><a href="#_ftnref2">[2]</a> QTester104 - https://sourceforge.net/projects/qtester104/</p> <p><a href="#_ftnref3">[3]</a> Kali Linux - https://www.kali.org/</p> <p><a href="#_ftnref4">[4]</a> Metasploit - https://www.metasploit.com/</p> <p><a href="#_ftnref5">[5]</a> OpenMUC j60870 - https://www.openmuc.org/iec-60870-5-104/</p> <p><a href="#_ftnref6">[6]</a> Ettercap - https://www.ettercap-project.org/</p> <p><a href="#_ftnref7">[7]</a> CICFlowMeter - https://github.com/ahlashkari/CICFlowMeter</p> <p><a href="#_ftnref8">[8]</a> This parser is provided after a communication with the authors.</p> <p><a href="#_ftnref9">[9]</a> Scapy - https://scapy.net/</p>

opencc-by-4.0Dec 2021View details →
zenodo32/100

The dataset for the manuscript entitled "Seawater intrusion inhibits nitrate removal in tidal marsh aquifers"

<p>This is the dataset for the manuscript entitled "Seawater intrusion inhibits nitrate removal in tidal marsh aquifers".</p>

opencc-by-4.0May 2024View details →

ScienceDex guides

Understand access before you commit

These curated guides explain access requirements, typical timelines, costs, and reuse considerations for widely used research datasets.

Compare curated datasets

Allen Brain Atlas

Allen Brain Atlas is an Allen Institute collection of brain map atlases, datasets, APIs, and analysis tools covering mouse, human, and non-human primate brain resources.

allen-brain-atlas
neuroscienceopenDocumentation, web resources, and API references are available online.
Last verified 2026-04-30Open record

Annotated Behaviour and Observability Dataset (ABODe)

ABODe is a University of Edinburgh DataShare dataset for behavior classification in group-housed mice using home-cage video, identities, bounding boxes, ground-plate positions, and annotator labels.

abode-home-cage
behavioral-neuroscienceopenThe DataShare record exposes download links for annotations, documentation, license text, and the zipped per-snippet data directory.
Last verified 2026-04-30Open record

DANDI Archive for NWB datasets

DANDI is a BRAIN Initiative archive for publishing and sharing neurophysiology data, including electrophysiology, optophysiology, and behavioral data packaged as NWB and related standards.

dandi-nwb
electrophysiologyopenPublished Dandiset metadata and archive endpoints are available through the production DANDI API.
Last verified 2026-04-30Open record

International Brain Laboratory public data

The International Brain Laboratory public data releases expose standardized mouse decision-making experiments, including Neuropixels recordings, widefield calcium imaging, behavior, and session metadata accessed through the ONE API.

ibl
behavioral-neuroscienceopenPublic sessions can be searched and loaded from the IBL public data server through ONE.
Last verified 2026-04-29Open record

OpenNeuro

OpenNeuro is a free, open platform for sharing neuroimaging datasets, with public search, dataset pages, and download paths for web, S3, DataLad, and the OpenNeuro CLI.

openneuro
neuroscienceopenPublished datasets are available on demand over the internet.
Last verified 2026-04-29Open record