To request access this dataset you will need to login with an IMPACT account. Accounts are free. If you don't have one please register.
This dataset is no longer available and has a current status of 'Withdrawn'.
Please see the catalog for a listing of currently available datasets.

Summary

DS-0693
DDOS_Chargen_2016
Dataset
Merit Network, Inc.
Merit Network, Inc.
11/25/2016
11/26/2016
38 (lowest rank is 56)

Category & Restrictions

Traffic Flow Data
Quasi-Restricted
true

Description


Internet traffic data containing a DDoS attack based on UDP Chargen protocol

This is a real-world DDoS attack captured at Merit's border router in SFPOP. It's a reflection and amplification Distributed Denial of Service attack (DDoS) that is based on the CHARGEN protocol (over UDP). Data are organized into 4 folders, namely WSUa, WSUb, WSUc and WSUd (all folders contain data from the same site; due to traffic load balancing, we have 4 collection folders). The attack starts around 11:59am (Eastern Timezone) and hits destination IP 35.7.72.0 (all our IPs are anonymized by zeroing the last 11 bits). Data format: flow-tools

Additional Details

67.1GB
true
false
2016, merit, network, ddos, chargen, ddos_chargen_2016, 693, anonymized, merit network, inc., attack, traffic, based, protocol, udp, folders, flow, distributed, format, bits, real, ips, hits, amplification, balancing, site, service, zeroing, organized, reflection, eastern, captured, traffic flow data, timezone, 59am, destination, tools, router, load, sfpop, wsud, starts, wsuc, wsub, wsua, border, denial