This paper introduces a comprehensive dataset specifically designed for the analysis and detection of various cyberattacks within network traffic. The dataset encompasses detailed network traffic features, protocol indicators, connection states, and labeled attack categories. Key attributes such as ‘dttl’, ‘swin’, ‘dwin’, ‘tcprtt’, ‘synack’, and ‘ackdat’ pro- vide critical TCP/IP header information and connection metrics. Additionally, the dataset specifies protocol types (‘proto_tcp’, ‘proto_udp’) and service types (‘service_dns’), aiding in the identification of protocol-specific and service-specific patterns. Connection states (‘state_CON’, ‘state_FIN’) offer valuable context for understanding the flow and termination of network connections. The labeled attackcategories(‘attack_cat_Analysis’,‘attack_cat_DoS’, ‘attack_cat_Exploits’, ‘attack_cat_Normal’) facilitate multi-class classifi- cation, enabling the distinction between normal and various malicious activities. This comprehensive dataset is ideal for training machine learning models aimed to enhance intrusion detection systems (IDS), advancing cybersecurity research, and improving network monitoring solutions. By leveraging these features and labels, the dataset supports the development of robust mechanisms for detecting and categorizing network-based threats.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Advanced Machine Learning for Cybersecurity: A Robust Dataset and Evaluation of IDS Algorithms

  • Mansour Lmkaiti,
  • Youness Belaadel,
  • Houda Moudni,
  • Hicham Mouncif

摘要

This paper introduces a comprehensive dataset specifically designed for the analysis and detection of various cyberattacks within network traffic. The dataset encompasses detailed network traffic features, protocol indicators, connection states, and labeled attack categories. Key attributes such as ‘dttl’, ‘swin’, ‘dwin’, ‘tcprtt’, ‘synack’, and ‘ackdat’ pro- vide critical TCP/IP header information and connection metrics. Additionally, the dataset specifies protocol types (‘proto_tcp’, ‘proto_udp’) and service types (‘service_dns’), aiding in the identification of protocol-specific and service-specific patterns. Connection states (‘state_CON’, ‘state_FIN’) offer valuable context for understanding the flow and termination of network connections. The labeled attackcategories(‘attack_cat_Analysis’,‘attack_cat_DoS’, ‘attack_cat_Exploits’, ‘attack_cat_Normal’) facilitate multi-class classifi- cation, enabling the distinction between normal and various malicious activities. This comprehensive dataset is ideal for training machine learning models aimed to enhance intrusion detection systems (IDS), advancing cybersecurity research, and improving network monitoring solutions. By leveraging these features and labels, the dataset supports the development of robust mechanisms for detecting and categorizing network-based threats.