BCAST IDS dataset

Citation Author(s):
Javier
Gombao
Submitted by:
Javier Gombao
Last updated:
Wed, 09/25/2024 - 08:33
DOI:
10.21227/kdnn-yp02
License:
0
0 ratings - Please login to submit your rating.

Abstract 

This unlabeled dataset reflects the network activity of a real branch office with 29 active machines connected to the same broadcast domain for four hours. To achieve this, a Network Intrusion Detection System (NIDS) called BCAST IDS listened to network traffic every 10 seconds. During this time, various types of activities were carried out (browsing, emailing, file transfers, etc.) on each machine to ensure the dataset reflected a wide range of benign behavior. Moreover, automated IP address scanning, local network reconnaissance, and Denial of Service (DoS) attacks were performed by another machine using nmap, netdiscover, and arp-scan commands to generate anomalies in the captured data.

Instructions: 

Each feature of the dataset has the following meaning.

  • MAC: Identifier of the MAC Address.
  • UCAST: Total amount of Unicast traffic generated by the MAC address.
  • MCAST: Total amount of Multicast traffic generated by the MAC address.
  • BCAST: Total amount of Broadcast traffic generated by the MAC address.
  • ARP: Total amount of ARP Requests, ARP Probe, ARP Announcements and Gratuitous ARP traffic generated by the MAC address.
  • IPF: Total amount of ARP Requests generated from the MAC address to an IP address that exists in the network segment.
  • IP_ICMP: Total amount of IP ICMP traffic generated by the MAC address.
  • IP_UDP: Total amount of IP UDP traffic generated from a specific MAC address.
  • IP_TCP: Total amount of IP TCP traffic generated by the MAC address.
  • IP_RESTO: Other traffic generated from a specific MAC address.
  • IPv6: Total amount of IPv6 traffic by the MAC address.
  • ETH_RESTO: Total amount of Ethernet traffic generated by the MAC address.
  • ARP_noIP: Total amount of ARP Requests generated by the MAC address to an IP address that does not exist in the network segment.
  • SSDP: Total amount of SSDP traffic generated by the MAC address.
  • ICMPv6: Total amount of ICMPv6 traffic generated by the MAC address.

The data were normalized by dividing each value by the total number of packets generated for each individual MAC address.

Comments

need access to database to replicate an experiment

Submitted by ARYAN PADIYAL on Tue, 09/24/2024 - 15:30