Skip to main content

Datasets

Standard Dataset

DNS Over HTTPS network traffic

Citation Author(s):
Kamil Jeřábek
Samuel Stuchlý
Submitted by:
Kamil Jerabek
Last updated:
DOI:
10.21227/96ea-2055
Data Format:
1340 views
Categories:
Keywords:
Average: 5 (1 vote)

Abstract

Dataset contains generated traffic from single requests towards DNS and DNS over Encryption servers as well as network traffic generated by browsers towards multiple DNS over HTTPS servers. The dataset contains also logs and csv files with queried domains. The IP addresses of the DoH servers are provided in the readme so that users can easily label the data extracted from pcap files. The dataset may be used for Machine Learning purposes (DNS over HTTPS identification).

Instructions:

Contains captured traffic with request/response queried by Firefox and minority part by Chrome browser.

Queries are generated by different DoH settings in Firefox for purpose of page load time measurement, together with logs.

Different DoH servers in dataset can be identified by ip adresses:

- pi-dns - 88.198.91.187

- google - 8.8.8.8, 8.8.4.4

- cloudflare - 104.16.249.249, 104.16.248.249

- mozilla-cloudflare - 104.16.249.249, 104.16.248.249

- opendns - 146.112.41.2, 146.112.41.3

- cz-nic - 185.43.135.1

- dnslify - 185.235.81.1

- dnsoverhttps-net - 104.236.178.232

- ffmuc - 195.30.94.28, 5.1.66.255

- blahdns - 159.69.198.101

- dnsforge - 176.9.93.198, 176.9.1.117

- other DoH IPs - 104.22.72.65, 104.22.73.65

The dataset also contains traffic generated by Firefox browser repeated 3 times (the same websites were loaded 3 times the same way) .