MAWILab

Data set: 2002/01/25






Traffic Trace: 2002/01/25

Info: http://mawi.wide.ad.jp/mawi/samplepoint-B/2002/200201251400.html
tcpdump file: http://mawi.wide.ad.jp/mawi/samplepoint-B/2002/200201251400.dump.gz

Anomalous Traffic:

"Anomalous" and "Suspicious" labels (admd file): 200201251400_anomalous_suspicious.xml

Overview of the anomalies:

# of anomalies: 6
# of anomalies as function of the # of alarms and # of detectors reporting the alarms:


Breakdown of the anomalies:

CategoryLabelDetectors
SYN scanAnomalous Hough, Gamma, PCA
HTTPAnomalous Gamma, KL, PCA
HTTPAnomalous Hough, Gamma, KL, PCA
UnknownAnomalous Hough, Gamma, PCA
UnknownAnomalous Hough, Gamma, PCA
UnknownAnomalous Hough, Gamma, KL, PCA
CategoryLabelDetectors

Other:

"Notice" labels (admd file): 200201251400_notice.xml