Downloads provided by UsageCounts
We are publishing a dataset we created for designing a brute-force detector of attacks in HTTPS. The dataset consists of extended network flows that we captured with flow exporter Ipifixprobe. Apart from traditional fields like source and destination IP addresses and ports, each flow contains information (size, direction, inter-packet time, TCP flags) about up to the first 100 packets. The sizes of packets are taken from the transport layer (TCP, UPD); packets with zero payload (e.g., TCP ACKs) are ignored. We publish three files: flows.csv, which contains raw flow data. aggregated_flows.csv, which contains aggregated flows samples.csv, which contains samples with extracted features. This data can be used for training a machine-learning classification model. All IP addresses, source ports, TLS SNIs are sha256-hashed. Column CLASS is 0 for benign samples and 1 for brute-force samples. Brute-force data The brute-force data were generated with three popular attack tools - Ncrack, Thc-hydra, and Patator. Attacks were performed against these applications: WordPress Joomla MediaWiki Ghost Grafana Discourse PhpBB OpenCart Redmine Nginx Apache The SCENARIO columns indicate which tool and application were used to generate the sample. Benign data Bening data consists of eight captures from a backbone network. The SCENARIO column indicates individual captures.
Traffic analysis, Brute-force attacks, HTTPS, Flow monitoring, Encrypted traffic
Traffic analysis, Brute-force attacks, HTTPS, Flow monitoring, Encrypted traffic
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
| views | 65 | |
| downloads | 34 |

Views provided by UsageCounts
Downloads provided by UsageCounts