Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Dataset . 2026
License: CC BY
Data sources: ZENODO
ZENODO
Dataset . 2026
License: CC BY
Data sources: Datacite
ZENODO
Dataset . 2026
License: CC BY
Data sources: Datacite
versions View all 2 versions
addClaim

Annotated Encrypted Network Traffic Dataset for Application, OS, and Malware Identification

Authors: Rysavy, Ondrej;

Annotated Encrypted Network Traffic Dataset for Application, OS, and Malware Identification

Abstract

This dataset provides an annotated collection of encrypted network communication intended for research on application identification, operating system fingerprinting, and malware detection in encrypted traffic. It combines network traffic captured in controlled sandbox environments executing selected Windows applications with malware-related communication obtained from automated malware analysis reports. In addition to application and malware traffic, the dataset includes background operating system communication generated by the capture environment, enabling comprehensive and realistic modeling of host behavior. The dataset is publicly provided as Apache Parquet files containing preprocessed representations of the raw network traffic. The underlying raw packet capture data (PCAP files) are not publicly distributed but are available upon justified request. The Parquet files include extracted features and structured annotations suitable for direct use in data analysis and machine learning workflows. The format and structure of the Parquet files, including field definitions and annotation schemas, are documented in the accompanying README.md file. The dataset is versioned and designed to be incrementally extended with additional applications, operating systems, and malware samples, supporting reproducible research and long-term reuse in encrypted traffic analysis and network security studies.

Version 1.0.0 contains an initial set of data files. This dataset is organized into three complementary collections. SOHO traffic, capturing real-world TLS flows from a small-office/home-office network with diverse devices and applications. This collection contains 108,036 TLS connections stored in 104 Parquet files (≈ 12.8 MB) and covers the period 2024-07-16 to 2024-11-22. Malware traffic, consisting of TLS connections generated during sandboxed execution of malware and benign samples, with ground-truth labels such as malware family, severity, and sandbox operating system. It includes 828,171 TLS connections across 916 Parquet files (≈ 63.4 MB), collected between 2025-09-10 and 2025-09-30. Windows applications traffic, containing TLS connections from controlled executions of known Windows applications in a sandbox environment, with application-level ground truth. This collection comprises 29,526 TLS connections in 5,892 Parquet files (≈ 63.2 MB) and spans 2025-09-26 to 2025-10-01.

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
0
Average
Average
Average