Skip to main content
Powered by ShareScore

Find research datasets worth reusing

Search datasets from major research repositories and use ShareScore to quickly assess how well each record supports discovery, access, and reuse.

10

datasets available to search

ShareScore release 0.9.0

Reset

Dataset results

10 results for “cyber attack”

Learn how ShareScore rates datasets ↗
zenodo48/100

Dataset for Sandboxing use case SUC2 related to cyber attacks affecting Wide Area Protection

<p><span>This dataset is related to the operation of the second KIOS CoE sandboxing use case (SUC2) which inclused 3 scenarios (S1-S3) which examins the behavious a WAP scheme of power grids in case of a short circuit fault and in case of two types of cyber attacks. The description of the architecture of the University of Cyprus/ KIOS CoE sandboxing environmnet used for extracting these datasets along with the full list of scenarios and their detailed implementation are described in the supporting documents.</span></p> <p><span>Brief description of each of the 3 scenarios of this SUC2 are provided below.</span></p> <p><span>The datasets for the first scenario (S1) of SUC2</span><span> examines the operation of a wide area protection scheme in a transmission line which receives data sent from PMUs at the two ends of the lines, when a short-circuit fault occurred in the range of the transmission line between buses 7 and 8 of the system. More details about the scenario SUC2/S1 related to this scenario's dataset can be found in Section&nbsp;</span><span>1.3.1</span><span> of the SUC2 supporting document. </span><span><span>The dataset includes electrical measurements of the current flow in line 7-8 (of the IEEE 9-bus system), in both magnitude and sinusoidal form</span><span>.</span><span> The dataset is provided in the form of time-series measurements available as MATLAB (.mat) and CSV files, which were recorded with a 30-second and 40-second time resolution, respectively. The measurements of RMS values were recorded by the Typhoon controller as they were sent by the two PMUs, while the sine wave measurements were recorder through the OPAL-RT</span></span></p> <p><span>The datasets for second scenario (S2) of SUC2 investigates the operation of a wide area protection scheme which receives data sent from PMUs when a MITM FDI cyber-attack is conducted on the measurements of bus 7</span><span>, virtually implemented within the sandboxing, and introduces a multiplicative change to the current measurements before they are received by the Typhoon controller via IEEE C37.118 protocol</span><span>. Section 1.3.2 of the SUC2 supporting document provides more details about the scenario related to this dataset.&nbsp;</span><span>This dataset includes electrical measurements of the current flow, in magnitude and sinusoidal format, of the transmission line between buses 7 and 8 of the <span>digital twin of the IEEE 9-bus system.</span> The dataset is provided in the form of time-series measurements available as MATLAB (.mat) and CSV files which were recorded with a 30-second and 40-second time resolution, respectively. The measurements of magnitude values were recorded by the Typhoon controller, while the data from the sinusoidal waveform were recorder by OPAL-RT.&nbsp;</span></p> <p><span>Thie dataset of the SUC2/S3 examines the operation of a wide area protection scheme which receives data sent from PMUs when a combined MITM with DoS cyber-attack is conducted, as actual attack, in the isolated communication network of the sandboxing environment, disrupting the C37.118 UDP communication exchanged between OPAL-RT 5707, where the digital twin of IEEE 9-bus system was implemented, and Typhoon controller. More details about this scenario associated to this dataset can be found in Section </span><span>1.3.3<span></span></span><span> of the supporting document of SUC2.</span></p> <p><span>This dataset includes electrical measurements of current&rsquo;s flow magnitude of the transmission line between buses 7 and 8 of the <span>digital twin of the IEEE 9-bus system.</span> The dataset was recorded by the Typhoon controller, and it is provided in the form of time-series measurements available as MATLAB (.mat) and CSV files which were recorded with a 30-second and 40-second time resolution, respectively. In addition, the dataset includes network traffic packets captured as .pcapng<span>&nbsp; </span>and .csv files. <span>&nbsp;</span></span></p>

opencc-by-4.0Jul 2024View details →
zenodo48/100

Cyber-attack scenarios for super-heaters system

<p>Simulated cyber-attacks for super-heaters system. For detailed description refer to pdf file. Dataset is in the form of tab separated txt files.</p> <p>In case of any questions please contact michal.syfert@pw.edu.pl or anna.sztyber@pw.edu.pl.</p> <p>Please cite: Sztyber-Betley, A.; Syfert, M.; Kościelny, J.M.; G&oacute;recka, Z. Controller Cyber-Attack Detection and Isolation.&nbsp;<em>Sensors</em>&nbsp;<strong>2023</strong>,&nbsp;<em>23</em>, 2778. https://doi.org/10.3390/s23052778</p>

opencc-by-4.0Feb 2023View details →
zenodo44/100

Dataset for KIOS CoE Sandboxing use-case SUC4 corresponding to cyber attacks affecting the Coordinated Overcurrent Protection Scheme (IEC 61850 GOOSE)

<p><span>The datasets reflect on two main scenarios (S1-S2) related to SUC4 - corresponding to cyber attacks affecting the Coordinated Overcurrent Protection Scheme.&nbsp;</span><span>The first scenario explores the response of the coordinated overcurrent protection when circuit breakers (CBs) are healthy, under normal operation, i.e., SUC4/S1(without attack), and the under a FDI cyberattack on IEC 61850 - GOOSE communication protocol, i.e., SUC4/S1(with FDI attack).&nbsp;</span>Similarly, the second scenario investigates the response of the coordinated overcurrent protection when there a mechanical failure in the CB of the downstream feeder, under normal operation, i.e., SUC4/S2(without attack), and the under a message suppresion (MS) cyber-attack on GOOSE protocol, i.e., SUC4/S2(with MS attack). Details regarding the datasets captured during the execution of each scenario (with and without attacks), including electrical measurements and network traffic, are briefly rsummarized below, while the full details are provided in the supporting documents.</p> <ul> <li><span><strong>SUC4/S1(without attack) datasets/Normal operation (without cyber-attack on GOOSE) when CBs are healthy </strong>: This dataset is related to the operation of the sandboxing use case SUC4 described in this&nbsp;document, which examines operation of the protection scheme in a substation using&nbsp;overcurrent protective relays (IEDs) in the sandboxing environment, that communicate&nbsp;with each other via IEC6180/GOOSE protocol. Specifically, this dataset corresponds to the&nbsp;first scenario (S1) of SUC4, without any attack. More details about the scenario related to&nbsp;this dataset can be found in Section 1.3.1 of the SUC4 supporting document. The dataset includes electrical measurements of the upstream and downstream feeders of&nbsp;the substation, the status (stNum) and sequence (sqNum) numbers, along with the binary&nbsp;values in &ldquo;alldata&rdquo; field of the GOOSE messages of IED1 and IED2, as well as the status of&nbsp;the CB1 and CB2. The dataset is provided in the form of time-series measurements&nbsp;available as MATLAB (.mat) and CSV (.csv) files. The measurements were recorded with a&nbsp;0.5-millisecond time resolution by specific blocks in RT-Lab environment of the real time&nbsp;simulator. In addition, network traffic data as Packer CAPture files (.pcapng) are included&nbsp;in this database.</span></li> <li><span><strong>SUC4/S1(with FDI attack) datasets/FDI cyber-attack on GOOSE signals when CBs are healthy</strong>: &nbsp;This dataset corresponds to the first scenario (S1) of SUC4, where an FDI cyber-attack is conducted in the local network by an attacker model, in order to inject fake messages to&nbsp;deceive an IED to unnecessarily trip its CB during normal grid conditions (without a shortcircuit event) and cause a regional blackout. More details about the scenario related to this&nbsp;dataset can be found in Section 1.3.1 of the supporting document.&nbsp;The dataset includes electrical measurements of the upstream and downstream feeders of&nbsp;the substation, the status (stNum) and sequence (sqNum) numbers, along with the binary&nbsp;values in &ldquo;alldata&rdquo; field of the GOOSE messages of IED1 and IED2, as well as the status of&nbsp;the CB1 and CB2. The dataset is provided in the form of time-series measurements&nbsp;available as MATLAB (.mat) and CSV (.csv) files. The measurements were recorded with a&nbsp;0.5-millisecond time resolution by specific blocks in RT-Lab environment of the real time&nbsp;simulator. In addition, network traffic data as Packer CAPture files (.pcapng) are included&nbsp;in this database.<br></span></li> <li><span><strong>SUC4/S2(without attack) datasets/ Normal operation (without attack on GOOSE) when CB presents a failure</strong>: This dataset corresponds to the first scenario (S1) of SUC4, where an FDI cyber-attack is&nbsp;conducted in the local network by an attacker model, in order to inject fake messages to&nbsp;deceive an IED to unnecessarily trip its CB during normal grid conditions (without a shortcircuit event) and cause a regional blackout. More details about the scenario related to this&nbsp;dataset can be found in Section 1.3.1 of the supporting document.&nbsp;The dataset includes electrical measurements of the upstream and downstream feeders of&nbsp;the substation, the status (stNum) and sequence (sqNum) numbers, along with the binary&nbsp;values in &ldquo;alldata&rdquo; field of the GOOSE messages of IED1 and IED2, as well as the status of<br>the CB1 and CB2. The dataset is provided in the form of time-series measurements&nbsp;available as MATLAB (.mat) and CSV (.csv) files. The measurements were recorded with a&nbsp;0.5-millisecond time resolution by specific blocks in RT-Lab environment of the real time&nbsp;simulator. In addition, network traffic data as Packer CAPture files (.pcapng) are included&nbsp;in this database.<br></span></li> <li><span><strong>SUC4/S2(with MS attack) datasets/MS cyber-attack on GOOSE signals when CB presents a failure</strong>: This dataset corresponds to the second scenario (S2) of SUC4, where an MS cyber-attack is&nbsp;conducted in the local network in order prevent critical benign messages, such inter-trip&nbsp;messages requesting backup protection, to reach their destination (back-up IED) when a&nbsp;CB failure occurs during a short-circuit event. As a result, the duration of a short-circuit is&nbsp;prolonged or the protection scheme is not able to clear the short-circuit event, which can&nbsp;cause catastrophic failures to power system. More details about the scenario related to<br>this dataset can be found in Section 1.3.2 of the support document.&nbsp;The dataset includes electrical measurements of the upstream and downstream feeders of<br>the substation, the status (stNum) and sequence (sqNum) numbers, along with the binary&nbsp;values in &ldquo;alldata&rdquo; field of the GOOSE messages of IED1 and IED2, as well as the status of&nbsp;the CB1 and CB2. The dataset is provided in the form of time-series measurements&nbsp;available as MATLAB (.mat) and CSV (.csv) files. The measurements were recorded with a&nbsp;0.5-millisecond time resolution by specific blocks in RT-Lab environment of the real time&nbsp;simulator. In addition, network traffic data as Packer CAPture files (.pcapng) are included&nbsp;in this database.<br></span></li> </ul>

opencc-by-4.0Jul 2024View details →
zenodo44/100

Dataset for KIOS CoE Sandboxing use-case SUC5 corresponding to cyber attacks affecting the control of active distribution grids and microgrids

<p>These datasets&nbsp;<span> illustrate two primary scenarios (S1-S2) concerning the operation of the sandboxing use case SUC5 corresponding to cyber attacks affecting the control of active distribution grids and microgrids. These scenarios examine the functioning of an active distribution grid and microgrid system, along with the effects of certain cyber-attacks in this context. The demonstration of each scenario is detailed in selected time-series plots which were described in detail in Section </span><span>1.3 of the supporting document of SUC5 (</span><span>accompanied by an in-depth analysis of the processes and an impact assessment). A</span><span>ll data captured during the execution of each scenario was collected, including electrical measurements, reference and set-point signals.&nbsp;</span></p> <ul> <li><span><span><strong>SUC5/S1 datasets/<span>MITM with FDI</span> cyber-attack</strong><span><strong> in an active distribution grid (grid-connected)</strong>: This dataset is related to the operation of the fifth sandboxing use case (SUC5) of the KIOS CoE Sandboxing environment for cyber-physical analysis of EPES, which examines the operation of an active distribution grid, when the distribution grid is interconnected with the main grid. Specifically, this dataset corresponds to the first scenario (S1) of SUC5, where a MITM with FDI cyber-attack is virtually conducted within the sandboxing environment to introduce an offset deviation to the active power set-point allocated to BSS inverter controller from the secondary controller. More details about the scenario related to this dataset can be found in Section 1.3 of the supporting document. The dataset includes electrical measurements of the active power generated by the BSS inverter (connected at bus 2), and the active power set-point before and after the attack. The dataset is provided in the form of time-series measurements available as MATLAB (.mat) and CSV (.csv) files. The measurements were recorded from the real time simulator using the &ldquo;OpWrite&rdquo; block of the RT-LAB, with 1-millisecond time resolution. &nbsp;<br></span></span></span></li> <li><span><span><span><strong>SUC5/S2 datasets/MITM with FDI cyber-attack in a microgrid (islanding mode)</strong>: This dataset is related to the operation of the fifth sandboxing use case (SUC5) which investigates the operation of a microgrid during islanding mode. This dataset corresponds to the second scenario (S2) of SUC5, where a MITM with FDI cyber-attack is virtually conducted within the sandboxing environment to introduce an offset deviation to the frequency reference signal, exchanged between the higher-level controller (tertiary controller) and the microgrid local controller (secondary V-f controller). More details about the scenario related to this dataset can be found in Section 1.3 of this supporting document.&nbsp;The dataset includes electrical measurements of the microgrid frequency, the reference frequency value generated by the tertiary controller, as well as the attacked frequency reference value. The dataset is provided in the form of time-series measurements available as MATLAB (.mat) and CSV (.csv) files. The measurements were recorded from the real time simulator using the &ldquo;OpWrite&rdquo; block of the RT-LAB, with 1-millisecond time resolution. &nbsp;<br></span></span></span></li> </ul>

opencc-by-4.0Jul 2024View details →
zenodo40/100

Datasets for sandboxing use case SUC3 corresponding to cyber attacks affecting the differential protection scheme of a HV transformer

<p><span>These datasets reflect two main scenarios (S1-S2) associated to the operation of a sandboxing use case SUC3 corresponding to cyber attacks affecting the differential protection scheme of a HV transformer. Details about are illustrated in Section 1.3 of the supporting document. These scenarios analyse the operation of the digital twin of the IEEE 9-bus system and the differential protection scheme under healthy conditions, cyber-attack on communication channels of IEC 61850 Sample Values (SVs) protocol, and a fault in HV side of a transformer in the power system. The scenarios are presented with selected time-series plots in Section 1.3, accompanied a detailed analysis of the processes included and an impact assessment. Thus, d</span><span>uring execution of each scenario, data such as electrical measurements were captured and are collected</span> in the form of the datasets presented here.</p> <p>Specifically,&nbsp;</p> <ul> <li>SUC3/S1 <strong>Differential protection operation during transformer fault</strong> corresponds to the dataset of first scenario (S1) of the third sandboxing use case (SUC3) of the KIOS CoE Sandboxing for cyber-physical analysis of EPES, which examines the operation of differential protection scheme (implemented in Typhoon controller) for a HV/MV transformer. The protection scheme receives data sent through IEC 61850 SVs from the two sides of the transformer. Specifically, this dataset corresponds to the first scenario (S1) of SUC3, where a short-circuit occurred on the HV side of a HV/MV transformer of the system. More details about the scenario related to this dataset can be found in Section 1.3.1 of the supporting document. This dataset includes electrical measurements of the current flow, in RMS and sinusoidal format, from the HV and MV sides of HV/MV transformer of the digital twin of the IEEE 9-bus system. The dataset is provided in the form of time-series measurements available as MATLAB (.mat) and CSV files which were recorded with a 30-second and 40-second time resolution, respectively. The measurements of RMS values were recorded by the Typhoon controller, while the sinusoidal measurements were recorder by OPAL-RT.</li> <li>SUC3/S2 <strong>MITM with FDI cyber-attack in the SVs of HV transformer side</strong> corresponds to the dataset of the second scanario (S2) of the third sandboxing use case (SUC3) of the KIOS CoE Sandboxing for cyber-physical analysis of EPES, which&nbsp; examines a MITM with FDI cyber-attack is conducted on the measurements of the HV side of the transformer, virtually implemented within the&nbsp;sandboxing, and introduces a multiplicative change to the current measurements before&nbsp;they are received by the differential protection scheme via IEC 61850 protocol. Section&nbsp;1.3.1 of the supporting document provides more details about the scenario related to this<br>dataset.&nbsp;This dataset includes electrical measurements of the current flow, in RMS and sinusoidal&nbsp;format, from the HV and MV sides of HV/MV transformer of the digital twin of the IEEE 9-bus system. The dataset is provided in the form of time-series measurements available as&nbsp;MATLAB (.mat) and CSV files which were recorded with a 30-second and 40-second time&nbsp;resolution, respectively. The measurements of RMS values were recorded by the Typhoon&nbsp;controller, while the measurements from the sine waves were recorder by OPAL-RT.</li> </ul>

opencc-by-4.0Jul 2024View details →
zenodo40/100

L-TOWN simulated measurement without faults or cyber-attacks for scenarios with masking

<p>Additional resources for repository&nbsp;<a href="https://github.com/asztyber/wdn-simulation">asztyber/wdn-simulation</a></p> <p>Required to run scenarios with masking.</p>

opencc-by-4.0Apr 2023View details →
zenodo40/100

philip928lin/Flood-Risks-of-Cyber-physical-Attacks-in-a-Smart-Storm-Water-System: Flood Risks of Cyber-physical Attacks in a Smart Storm Water System

<p>This is the code archive for the publication "Flood Risks of Cyber-physical Attacks in a Smart Storm Water System" in Water Resources Research.</p>

opencc-by-4.0Oct 2023View details →
zenodo36/100

Cyber Attacks in the Ukrainian Conflict 2013-2020 Dataset

<p>Aggregated dataset on 76 cyberattacks conducted against Ukraine between late 2013 and 2020. The dataset is based on the following sources:</p> <p>Maness RC, Valeriano B, Hedgecock K, Jensen BM, Macias JM. Codebook for the Dyadic Cyber Incident and Campaign Dataset (DCID) Version 2.0. 2022.<br>Baezner M. Cyber and Information warfare in the Ukrainian conflict, Version 2. Z&uuml;rich: Center for Security Studies (CSS), ETH; 2018.<br>Passeri P. Hackmageddon - Information Security Timelines and Statistics. 2024. https://www.hackmageddon.com/.</p> <p>&nbsp;</p>

opencc-by-4.0Jun 2024View details →
zenodo20/100

Responses to AHP-style questionnaires regarding the publication "D-Score: An Expert-Based Method for Assessing the Detectability of IoT-Related Cyber-Attacks"

<p>In order to assess in advance&nbsp;the detectability of IoT-related cyber-attacks by anomaly-based network intrusion detection systems, we developed an expert-based method which relies on the AHP methodology.</p> <p>The online AHP-style questionnaire can be found here:&nbsp;https://bguprivacysurvey.limequery.com/537457</p> <p>The dataset which is hereby made public, includes the (anonymous) responses of 40 cyber-security researchers and practitioners, covering 4 IoT attack scenarios.</p> <p>The related publication is mentioned hereinafter; please be sure to cite it upon the use of this dataset.</p>

restrictedSep 2020View details →
zenodo12/100

Dataset of Thesis - Attacks on the Cloud: Unveiling Cyber Assaults on Cloud Infrastructure Through Honeypot Analysis

Open the record for dataset details and reuse information.

restrictedcc-by-4.0Nov 2024View details →

ScienceDex guides

Understand access before you commit

These curated guides explain access requirements, typical timelines, costs, and reuse considerations for widely used research datasets.

Compare curated datasets

Allen Brain Atlas

Allen Brain Atlas is an Allen Institute collection of brain map atlases, datasets, APIs, and analysis tools covering mouse, human, and non-human primate brain resources.

allen-brain-atlas
neuroscienceopenDocumentation, web resources, and API references are available online.
Last verified 2026-04-30Open record

Annotated Behaviour and Observability Dataset (ABODe)

ABODe is a University of Edinburgh DataShare dataset for behavior classification in group-housed mice using home-cage video, identities, bounding boxes, ground-plate positions, and annotator labels.

abode-home-cage
behavioral-neuroscienceopenThe DataShare record exposes download links for annotations, documentation, license text, and the zipped per-snippet data directory.
Last verified 2026-04-30Open record

DANDI Archive for NWB datasets

DANDI is a BRAIN Initiative archive for publishing and sharing neurophysiology data, including electrophysiology, optophysiology, and behavioral data packaged as NWB and related standards.

dandi-nwb
electrophysiologyopenPublished Dandiset metadata and archive endpoints are available through the production DANDI API.
Last verified 2026-04-30Open record

International Brain Laboratory public data

The International Brain Laboratory public data releases expose standardized mouse decision-making experiments, including Neuropixels recordings, widefield calcium imaging, behavior, and session metadata accessed through the ONE API.

ibl
behavioral-neuroscienceopenPublic sessions can be searched and loaded from the IBL public data server through ONE.
Last verified 2026-04-29Open record

OpenNeuro

OpenNeuro is a free, open platform for sharing neuroimaging datasets, with public search, dataset pages, and download paths for web, S3, DataLad, and the OpenNeuro CLI.

openneuro
neuroscienceopenPublished datasets are available on demand over the internet.
Last verified 2026-04-29Open record