CESNET-MINER22-TS: Periodic Behavior Features of Cryptomining Communication
<p><strong>CESNET-MINER22-TS: Periodic Behavior Features of Cryptomining Communication</strong></p><p>Datasets were created for the paper: Enhancing DeCrypto: Finding Cryptocurrency Miners Based on Periodic Behavior -- Josef Koumar, Richard Plný, Tomáš Čejka -- which was published at The 19th International Conference on Network and Service Management (CNSM) 2023. Please cite usage of our datasets as:<br> </p><blockquote><p>J. Koumar, R. Plný and T. Čejka, "Enhancing DeCrypto: Finding Cryptocurrency Miners Based on Periodic Behavior," <i>2023 19th International Conference on Network and Service Management (CNSM)</i>, Niagara Falls, ON, Canada, 2023, pp. 1-7, doi: 10.23919/CNSM59352.2023.10327904.</p></blockquote><p> </p><p>The files <i>cesnet_miner22_design_with_FTS_proba.zip</i> and <i>cesnet_miner22_evaluation_with_FTS_proba.zip</i> contain one .csv file with IP flows. The IP flows were taken from the CESNET-MINER22 dataset [1], which was created by monitoring national research and educational network CESNET2. Furthermore, we add two features ID_DEPENDENCY (string) and PERIODICITY_PROBA (double). ID_DEPENDENCY is an ID of a network dependency (see the article [2]) and the PERIODICITY_PROBA is the predicted probability by FTS analysis. The files from periodicity_features.zip contain periodic behavior features for Machine Learning. The files names are in format <i>"{evaluation/design}.periodicity_features.{TIME_INTERVAL}.{SIG_SPACE}.{PER_LEVEL}.csv"</i> and have the following format of columns:</p><ul><li><strong>id_dependency</strong> -- Identification of a network dependency observed as a Flow time series (FTS).</li><li><strong>label</strong> -- The labels ("Miner" or "Other") of periodic FTS.</li><li><strong>packet_value</strong> -- Value of Clear periodic behavior of the metric packet.</li><li><strong>packet_value_x</strong> -- Value of the interval's lower value of Sinusoidal periodic behavior of the metric packets.</li><li><strong>packet_value_y</strong> -- Value of the interval's upper value of Sinusoidal periodic behavior of the metric packets.</li><li><strong>packet_mean</strong> -- Mean value of the metric packet.</li><li><strong>packet_std</strong> -- Standard deviation value of the metric packet.</li><li><strong>packet_skewness</strong> -- Skewness value of the metric packet.</li><li><strong>packet_kurtosis</strong> -- Kurtosis value of the metric packet.</li><li><strong>bytes_value</strong> -- Value of Clear periodic behavior of the metric bytes.</li><li><strong>bytes_value_x</strong> -- Value of the interval's lower value of Sinusoidal periodic behavior of the metric bytes.</li><li><strong>bytes_value_y</strong> -- Value of the interval's upper value of Sinusoidal periodic behavior of the metric bytes.</li><li><strong>bytes_mean</strong> -- Mean value of the metric bytes.</li><li><strong>bytes_std</strong> -- Standard deviation value of the metric bytes.</li><li><strong>bytes_skewness</strong> -- Skewness value of the metric bytes.</li><li><strong>bytes_kurtosis</strong> -- Kurtosis value of the metric bytes.</li><li><strong>duration_value</strong> -- Value of Clear periodic behavior of the metric duration.</li><li><strong>duration_value_x</strong> -- Value of the interval's lower value of Sinusoidal periodic behavior of the metric duration.</li><li><strong>duration_value_y</strong> -- Value of the interval's upper value of Sinusoidal periodic behavior of the metric duration.</li><li><strong>duration_mean</strong> -- Mean value of the metric duration.</li><li><strong>duration_std</strong> -- Standard deviation value of the metric duration.</li><li><strong>duration_skewness</strong> -- Skewness value of the metric duration.</li><li><strong>duration_kurtosis</strong> -- Kurtosis value of the metric duration.</li><li><strong>difftimes_value</strong> -- Value of Clear periodic behavior of the metric difftimes.</li><li><strong>difftimes_value_x</strong> -- Value of the interval's lower value of Sinusoidal periodic behavior of the metric difftimes.</li><li><strong>difftimes_value_y</strong> -- Value of the interval's upper value of Sinusoidal periodic behavior of the metric difftimes.</li><li><strong>difftimes_mean</strong> -- Mean value of the metric difftimes.</li><li><strong>difftimes_std</strong> -- Standard deviation value of the metric difftimes.</li><li><strong>difftimes_skewness</strong> -- Skewness value of the metric difftimes.</li><li><strong>difftimes_kurtosis</strong> -- Kurtosis value of the metric difftimes.</li><li><strong>max_power</strong> -- Represent the maximum power of the LS periodogram.</li><li><strong>max_frequency</strong> -- Describe the frequency of the maximum power of the LS periodogram.</li><li><strong>min_power</strong> -- Represent the minimum power of the LS periodogram.</li><li><strong>min_frequency</strong> -- Describe the frequency of the minimum power of the LS periodogram.</li><li><strong>spectral_energy</strong> -- Represents the total energy present at all frequencies in LS periodogram.</li><li><strong>spectral_entropy</strong> -- The degree of randomness or disorder in the LS periodogram.</li><li><strong>spectral_kurtosis</strong> -- Indicates a nonstationary or non-Gaussian behavior in the power spectrum.</li><li><strong>spectral_skewness</strong> -- The measure of peakedness or flatness of power spectrum.</li><li><strong>spectral_rolloff</strong> -- It is defined as frequency below 85% of the distribution power.</li><li><strong>spectral_cetroid</strong> -- Indicates at which frequency the energy of a spectrum is centered upon.</li><li><strong>spectral_spread</strong> -- It is the difference between the highest and lowest frequency in the power spectrum.</li><li><strong>spectral_slope</strong> -- The slope of the power spectrum trend in a given frequency range.</li><li><strong>spectral_crest</strong> -- Refers to the rate of shift of the sign of a wave, which is the rate of change from negative to positive or the reverse.</li><li><strong>spectral_flux</strong> -- The rate of change of periodogram power with increasing frequency.</li><li><strong>spectral_bandwidth</strong> -- Describes the difference between upper and lower frequencies at which spectral energy is half its maximum value.</li></ul><p> </p><p>The files from <i>time_series.zip</i> contain FTS of used time interval. The file names are in format <i>"{evaluation/design}.time_series.{TIME_INTERVAL}.csv"</i> and have the following format of columns:</p><ul><li><strong>ID_DEPENDENCY</strong> -- Identification of a network dependency observed as a FTS.</li><li><strong>N_FLOWS</strong> -- Number of flows in time series, i.e., number of data points.</li><li><strong>N_PACKETS</strong> -- Number of packets in time series, i.e., the sum of metric PACKETS.</li><li><strong>N_BYTES</strong> -- Number of bytes in time series, i.e., the sum of metric PACKETS.</li><li><strong>PACKETS</strong> -- The array containing the time series metric number of packets in the IP flow.</li><li><strong>BYTES</strong> -- The array containing the time series metric number of bytes in the IP flow.</li><li><strong>START_TIMES</strong> -- The array containing the time series time axis of the flows starts.</li><li><strong>END_TIMES</strong> -- The array containing the time series time axis of the flows ends.</li><li><strong>LABELS</strong> -- The array of labels ("Miner" of "Other") of each datapoint.</li></ul><p> </p><p>[1] Richard Plný et al. CESNET-MINER22: Datasets of Cryptomining Communication. Zenodo, October 2022.</p><p>[2] Koumar, Josef, and Tomáš Čejka. "Network traffic classification based on periodic behavior detection." <i>2022 18th International Conference on Network and Service Management (CNSM)</i>. IEEE, 2022.</p>
opencc-by-4.0Jun 2023View details →