This is a non-IMPACT record, meaning that access to the data is not controlled by IMPACT. For access, see the directions below.

This Resource is offered and provided outside of the IMPACT mediation framework. IMPACT and the IMPACT Coordination Council/Blackfire Technology, Inc. expressly disclaim all conditions, representations and warranties including but not limited to Resource availability, quality, accuracy, non-infringement, and non-interference. All Resource information and access is controlled by entities and under terms that are external to the IMPACT legal framework.


Aktaion Dataset
External Dataset
External Data Source
University of Arizona
56 (lowest rank is 56)

Category & Restrictions

intrusion detection, cyber defense, network data, traffic flow data


This collection contains labeled network traffic data in ARFF format. The original purpose was to train ransomware detection in the Aktaion IDS.

Data was collected from multiple sources, most notably and as PCAP data.    Due to license restrictions, the shared data is limited to the example data, which is in ARFF format, and derived from the raw PCAP data in two steps: PCAP to Bro format conversion, and then feature extraction (microbehaviors) to ARFF (using Aktaion).

Aktaion is a lightweight Java virtual machine based project for detecting exploits (and more generally attack behaviors). The project is meant to be a learning/teaching tool on how to blend multiple security signals and behaviors into an expressive framework for intrusion detection. The key abstraction we wanted to prototype is the idea of a micro behavior. This concept helps to provide an expressive mechanism to add high level IOCs such as timing behavior of a certain malware family in parallel to simple statistics, rules or anything relevant to building a programmatic description of a sequential evolving set of adverse behaviors.

Additional Details

aktaion, dataset, aktaion dataset, 1260, source, external, inferlink corporation, external data source, corporation, inferlink, arff, format, detection, traffic, ransomware, train, original, purpose, network, ids, labeled, pcap, behaviors, malware, multiple, project, expressive, behavior, programmatic, security, parallel, lightweight, attack, feature, teaching, microbehaviors, exploits, mechanism, derived, adverse, family, machine, micro, evolving, intrusion, framework, prototype, abstraction, limited, meant, conversion, key, statistics, learning, analysis, contagiodump, raw, restrictions, iocs, timing, notably, level, based, add, bro, net, java, building, rules, simple, extraction, steps, tool, description, concept, sequential, idea, blend, sources, other, virtual, shared, helps, blogspot, detecting, provide, signals, license, relevant, collected