Research Datasets
Access high-quality datasets collected, processed, and validated for academic research and technology development purposes.
TCP FIN Flood and Zbassocflood Dataset
The Development of an Internet of Things (IoT) Network Traffic Dataset with Simulated Attack Data. Abstract— This research focuses on the requirements for and the creation of an intrusion detection system (IDS) dataset for an Internet of Things (IoT) network domain. A minimal requirements Internet of Things (IoT) network system was built to produce a dataset according to IDS testing needs for IoT security. Testing was performed with 12 scenarios and resulted in 24 datasets which consisted of normal, attack and combined normal-attack traffic data. Testing focused on three denial of service (DoS) and distributed denial of service (DDoS) attacks—“finish” (FIN) flood, User Datagram Protocol (UDP) flood, and Zbassocflood/association flood—using two communication protocols, IEEE 802.11 (WiFi) and IEEE 802.15.4 (ZigBee). A preprocessing test result obtained 95 attributes for the WiFi datasets and 64 attributes for the Xbee datasets . TCP FIN Flood Attack Pattern Recognition on Internet of Things with Rule Based Signature Analysis Abstract-Focus of this research is TCP FIN flood attack pattern recognition in Internet of Things (IoT) network using rule based signature analysis method. Dataset is taken based on three scenarios normal, attack and normal-attack. The process of identification and recognition of TCP FIN flood attack pattern is done based on observation and analysis of packet attribute from raw data (pcap) using a feature extraction and feature selection method. Further testing was conducted using snort as an IDS. The results of the confusion matrix detection rate evaluation against the snort as IDS show the average percentage of the precision level. Citing Citation data : "TCP FIN Flood Attack Pattern Recognition on Internet of Things with Rule Based Signature Analysis" - https://online-journals.org/index.php/i-joe/article/view/9848 @article{article, author = {Stiawan, Deris and Wahyudi, Dimas and Heryanto, Ahmad and Sahmin, Samsuryadi and Idris, Yazid and Muchtar, Farkhana and Alzahrani, Mohammed and Budiarto, Rahmat}, year = {2019}, month = {04}, pages = {124}, title = {TCP FIN Flood Attack Pattern Recognition on Internet of Things with Rule Based Signature Analysis}, volume = {15}, journal = {International Journal of Online and Biomedical Engineering (iJOE)}, doi = {10.3991/ijoe.v15i07.9848} } Features Extraction on IoT Intrusion Detection System Using Principal Components Analysis (PCA) Feature extraction solves the problem of finding the most efficient and comprehensive set of features. A Principle Component Analysis (PCA) feature extraction algorithm is applied to optimize the effectiveness of feature extraction to build an effective intrusion detection method. This paper uses the Principal Components Analysis (PCA) for features extraction on intrusion detection system with the aim to improve the accuracy and precision of the detection. The impact of features extraction to attack detection was examined. Experiments on a network traffic dataset created from an Internet of Thing (IoT) testbed network topology were conducted and the results show that the accuracy of the detection reaches 100 percent. Citing Citation data : "Features Extraction on IoT Intrusion Detection System Using Principal Components Analysis (PCA)" - https://ieeexplore.ieee.org/document/9251292 @inproceedings{inproceedings, author = {Sharipuddin, and Purnama, Benni and Kurniabudi, Kurniabudi and Winanto, Eko and Stiawan, Deris and Hanapi, Darmawiiovo and Idris, Mohd and Budiarto, Rahmat}, year = {2020}, month = {10}, pages = {114-118}, title = {Features Extraction on IoT Intrusion Detection System Using Principal Components Analysis (PCA)}, doi = {10.23919/EECSI50503.2020.9251292} }
Constrained Application Protocol (CoAP) Internet of Things Protocol Dataset
This study discusses the implementation of the Constrained Application Protocol (CoAP) using Constrained RESTful Environments (CoRE) on RFC 7252 which is used as a research parameter. The implementation of this Limited Application Protocol uses Internet of Things (IoT) technology. The testing technique is carried out offline and the device used is based on the constrained device. Network performance testing parameters in this study are UDP throughput, UDP delay, UDP packet loss and UDP packet delivery ratio. Testing network performance with LED and Buzzer output produces the largest average UDP throughput, namely 4.5737 Kbps while the smallest average throughput is 1.2293 Kbps, the largest average UDP delay result is 2 seconds and the smallest average is 0.6 seconds, then the average UDP packet loss yield is 0% while the average successful packet delivery ratio is 100%. From the results of this test, the Constrained Application Protocol (CoAP) has smaller network performance results than the HyperText Transfer Protocol (HTTP) to be implemented in Internet of Things (IoT) technology.
Message Queue Telemetry Transport (MQTT) Protocol on Internet of Thing Dataset
Internet of Things (IoT) is a system where devices are connected and allows information exchange among them. It also allows devices/objects to interact directly with other objects or commonly refers to Machine-to-Machine (M2M) communication. Message Queue Telemetry Transport (MQTT) is machine-to-machine connectivity protocol, which is designed as messages delivery service that gives different level of Quality of Service (QoS) i.e.: level 0, 1 and 2 for variety of use cases, provides architecture of publish/subscribe and supports multicasting message. The importance feature of MQTT is low overhead for efficient communication between devices. This work implements MQTT using Mosquito Broker, which has a function to regulate the delivery of messages between Publisher and Subscriber using poll system call to handle multiple network socket in one thread. With a scenario of increasing number of nodes at each experiment, MQTT Protocol has an average overall delay of 0.0029 seconds, an average throughput of 218 Kbps, average of packet loss of 0.2% and average of packet delivery ratio of 99.7%. Of experiment results obtained, the MQTT Protocol has potential to be able to meet the needs of the use of a limited bandwidth network, which can be adjusted with the level of service provided by the MQTT and low packet loss rate.
Dataset for Network Intrusion Detection System on SCADA IEC 60870-5-104
Security is the main challenge in Supervisory Control and Data Acquisition (SCADA) systems since SCADA systems must be connected to heterogeneous networks to save costs. SCADA devices such as RTUs have limited resources, so a small-scale cyber attack on a computer network will have a major impact on the SCADA system. This study discusses the SCADA system with the IEC 60870-5-104 protocol which is widely used in the power plant industry. A physical testbed is built to simulate the electrical distribution process. The SCADA system in the distribution section is more vulnerable than other parts because it is located directly in the community environment so that many holes can be entered by attackers. The purpose of this study is to obtain relevant datasets in the SCADA system. The simulation carried out in this study is a normal communication between the HMI and the RTU, then attacked to disrupt the communication. The attack activities carried out are port scan, brute force and DoS. DoS attacks carried out are ICMP flood, Syn flood, and IEC 104 flood. IEC 104 flood attack is a modified attack to attack RTU where RTU is flooded with an unknown typeid ASDU (Application Service Data Unit). Attacks are carried out using Kali Linux operating system. All scenarios are recorded and saved in pcap. To prove that there is attack data traffic on the IDS dataset Snort and Suricata are used to detect it. In this study, there are also intrusion detection performance results from Snort and Suricata
UDP Flood Attack Pattern on Internet of Things Network Dataset
UDP does not have mechanism for retransmission when a transmitting error happens, it makes this protocol to be used as a DDoS attack tool against Internet of Things (IoTs) networks. This research work attempts to analyze the UDP Flood attacks packets dataset captured from an Io|T testbed network by Wireshark. A feature extraction process on generated CSV file was performed and then the feature extraction result are examined to find patterns of UDP flood attack packet. Lastly, the patterns are visualized to provide easy pattern recognition.
Dataset Traffic Access On Website and Application in Online Gambling
Technological advancements and the widespread availability of internet access have fueled the rapid global expansion of online gambling. These platforms offer users the flexibility to play anytime and anywhere, coupled with the allure of substantial profits and immersive gameplay, which contributes to their rising popularity. However, beneath this appeal lie significant risks, including addiction, financial loss, and potential involvement in criminal activities. In Europe alone, online gambling revenue has grown by approximately 9% annually and is expected to represent 41% of the total gambling industry revenue by 2026. Moreover, online gambling is increasingly associated with cybercrimes such as theft, fraud, and defacement attacks targeting government and educational websites, often combined with black-hat SEO techniques to boost traffic to illicit gambling sites and tarnish institutional reputations. To better understand the infrastructure behind these activities, this study involved accessing several online gambling websites and applications through three one-hour gameplay sessions. The resulting dataset identifies various gambling-related IP addresses, the services they utilize, and their countries of origin, providing valuable insights into the digital and geographical landscape of online gambling operations.
Smart Home Attack Topology (IPv4)
Smart Home technology is an automation system designed to facilitate household activities through the Internet of Things (IoT). IoT technology enables everyday objects, such as sensors, cameras, and other smart devices, to connect to the Internet. As IoT technology advances, it becomes an attractive target for cyberattacks, including Distributed Denial of Service (DDoS), Denial of Service (DoS), and Man-in-the-Middle (MITM) attacks. The success of this study is demonstrated through the use of Information Security tools, such as CapLoader, Network Miner, Dynamite Lab, and the Snort IDS. Additionally, T-Shark plays a crucial role as a solution for extracting data from .pcap files into CSV format, enabling further analysis.
Malware Dataset on Android Applications
Android has become the most popular operating system on mobile devices, making it a prime target for threat actors in creating malware. The research conducted by the author aims to detect reverse TCP exploits in network traffic. The tools used are Metasploit for Android, Termux, PCAPdroid, Wireshark, OpenVPN, and Apktool in both terminal and application versions. The supporting devices for this research are hardware devices, namely a smartphone, VPS, Mikrotik Router, and laptop.
Ping Flood Attack Pattern Recognition on Internet of Things Network Dataset
This work investigates ping flood attack pattern recognition on Internet of Things (IoT) network. Experiments are conducted on WiFi communication with three different scenarios: normal traffic, attack traffic, and normal-attack combination traffic to create normal dataset, attack dataset, and normal attack (combined) dataset. The datasets are grouped into two clusters i.e.: (i) normal cluster and (ii) attack cluster. Clustering results using implemented K-Means algorithm show the average number of packets on the cluster of attack in total is 95,931 packets, and the average packets on normal cluster in total is 4,068 packets. Accuracy level of the clustering results then is calculated using confusion matrix equation. Based on the confusion matrix calculation, accuracy of clustering using implemented K-Means algorithm was 99.94%. The true negative rate reaches up to 98.62%, true positive rate is 100%, the false negative rate is 0%, and the false positive rate reaches 1.38%.
Smart Home Attack Topology (IPv6)
This dataset contains network traffic recordings from a smart home environment based on the IPv6 protocol, captured using Wireshark. The data collection was performed in three distinct scenarios: normal traffic, attack traffic, and a mixed scenario. The normal scenario involves routine smart home device activities without any disturbances, while the attack scenario simulates a DDoS attack using the THC-IPv6 tool with methods such as Router Advertisement Flooding and ICMPv6 Echo Request Flooding. The mixed scenario combines normal traffic and attack traffic, representing real-world conditions where the network experiences disturbances but still operates partially. The recordings were captured for five minutes in pcap or pcapng format to ensure consistency, and the dataset can be used for research in network security, intrusion detection systems (IDS), and machine learning model training for anomaly detection in IPv6-based smart home networks.
