Skip to main content

Datasets

Standard Dataset

SDN-SlowRate-DDoS dataset

Citation Author(s):
Noe M. Yungaicela-Naula (Tecnologico de Monterrey)
Cesar Vargas-Rosales (Tecnologico de Monterrey)
Jesus Arturo Pérez-Díaz (Tecnologico de Monterrey)
Eduardo Jacob (University of the Basque Country UPV/EHU)
Carlos Martinez-Cagnazzo (LACNIC)
Submitted by:
Noe Yungaicela-Naula
Last updated:
DOI:
10.21227/amrt-8y98
Data Format:
No Ratings Yet

Abstract

Slow-rate DDoS attacks are recent threats targeting next-generation networks such as IoT, 5G, etc. Unlike conventional high-rate DDoS, slow-rate DDoS have not been deeply studied, mainly due to the limited number of existing datasets with real traces. The SDN-SlowRate-DDoS dataset captures traffic from a physical testbed deployed on the European Experimental Facility Smart Networks for Industry (SN4I, https://i2t.ehu.eus/en/resources/sn4i). A Software Defined Network (SDN)-based datacenter topology was deployed, and multiple experiments of slow-rate DDoS attacks (slow HTTP read) were performed varying the number of victims and attackers.

Instructions:

To create the SDN-SlowRate-DDoS dataset, we deployed SDN-based datacenter topology with two spine switches and four leaf switches using physical equipment from SN4I. Furthermore, ONOS controller was used. The SDN-SlowRate-DDoS dataset contains 23 experiments for slow HTTP read attack, varying the number of attackers (1-4 attackers) and victims (1-3 victims). Slowhttptest (https://www.kali.org/tools/slowhttptest/) was used to attack the victim servers. For each experiment, a least one of the following resources is provided: (i) pcap files containing the raw packets of the network captured using tcpdump, and (ii) csv files containing flow-based features. The flow-based features involve: (1) Device ID (switch ID), (2) Flow ID, (3) IP Src, (4) IP Dst, (5) Mac Src, (6) Mac Dst, (7) Port Src, (8) Port Dst, (9) Protocol, (10) Bytes, (11) Packets, (12) Life, and (13) TimeStamp.The total size of the dataset is 388 GB.

Funding Agency
Red temática Ciencia y Tecnología para el desarrollo (CYTED)
Grant Number
519RT0580