This is a non-IMPACT record, meaning that access to the data is not controlled by IMPACT. For access, see the directions below.

Disclaimer:
This Resource is offered and provided outside of the IMPACT mediation framework. IMPACT and the IMPACT Coordination Council/Blackfire Technology, Inc. expressly disclaim all conditions, representations and warranties including but not limited to Resource availability, quality, accuracy, non-infringement, and non-interference. All Resource information and access is controlled by entities and under terms that are external to the IMPACT legal framework.

Summary

DS-1260
Aktaion Dataset
External Dataset
External Data Source
University of Arizona
Unknown
Unknown
56 (lowest rank is 56)

Category & Restrictions

Other
intrusion detection, cyber defense, network data, traffic flow data
Unrestricted
true

Description


This collection contains labeled network traffic data in ARFF format. The original purpose was to train ransomware detection in the Aktaion IDS.

Data was collected from multiple sources, most notably contagiodump.blogspot.com and malware-traffic-analysis.net as PCAP data.    Due to license restrictions, the shared data is limited to the example data, which is in ARFF format, and derived from the raw PCAP data in two steps: PCAP to Bro format conversion, and then feature extraction (microbehaviors) to ARFF (using Aktaion).

Aktaion is a lightweight Java virtual machine based project for detecting exploits (and more generally attack behaviors). The project is meant to be a learning/teaching tool on how to blend multiple security signals and behaviors into an expressive framework for intrusion detection. The key abstraction we wanted to prototype is the idea of a micro behavior. This concept helps to provide an expressive mechanism to add high level IOCs such as timing behavior of a certain malware family in parallel to simple statistics, rules or anything relevant to building a programmatic description of a sequential evolving set of adverse behaviors.

Additional Details

14.6KB
false
Unknown
aktaion, dataset, aktaion dataset, 1260, source, external, inferlink corporation, external data source, corporation, inferlink, arff, format, detection, traffic, ransomware, train, original, purpose, network, ids, labeled, pcap, behaviors, malware, multiple, project, expressive, behavior, programmatic, security, parallel, lightweight, attack, feature, teaching, microbehaviors, exploits, mechanism, derived, adverse, family, machine, micro, evolving, intrusion, framework, prototype, abstraction, limited, meant, conversion, key, statistics, learning, analysis, contagiodump, raw, restrictions, iocs, timing, notably, level, based, add, bro, net, java, building, rules, simple, extraction, steps, tool, description, concept, sequential, idea, blend, sources, other, virtual, shared, helps, blogspot, detecting, provide, signals, license, relevant, collected