MAWILab

Data set: 2008/12/26






Traffic Trace: 2008/12/26

Info: http://mawi.wide.ad.jp/mawi/samplepoint-F/2008/200812261400.html
tcpdump file: http://mawi.wide.ad.jp/mawi/samplepoint-F/2008/200812261400.dump.gz

Anomalous Traffic:

"Anomalous" and "Suspicious" labels (admd file): 20081226_anomalous_suspicious.xml
"Anomalous" and "Suspicious" labels (csv file): 20081226_anomalous_suspicious.csv

Overview of the anomalies:

Number of anomalies: 137
Proportion of anomalies in terms of occurrence:


Breakdown of the anomalies:

TaxonomyHeuristicLabelDetectors
network_scan_UDPOtheranomalous Hough, Gamma, KL
network_scan_ICMP_ecrq_ICMP_ecrp_du_rm_te_responsePing floodanomalous Hough, Gamma, PCA
network_scan_UDP_UDP_responseOtheranomalous Hough, KL
network_scan_SYN_tSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_SYN_tSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_UDPOtheranomalous Gamma, KL, PCA
network_scan_UDPOtheranomalous Hough, Gamma
network_scan_UDP_UDP_responseOtheranomalous Hough, KL
network_scan_TCP_TCP_ICMP_responseOtheranomalous Hough, Gamma, KL, PCA
network_scan_UDP_UDP_responseOtheranomalous Hough, KL
network_scan_UDPOtheranomalous KL, PCA
network_scan_UDP_UDP_responseOthersuspicious Hough
network_scan_UDP_UDP_responseOthersuspicious Hough
network_scan_UDPNetbios attacksuspicious Hough
network_scan_SYN_t_139_445SYN attacksuspicious Hough
network_scan_SYN_t_139_445SYN attacksuspicious Hough
network_scan_SYN_t_139_445SYN attacksuspicious Hough
network_scan_SYN_tSYN attacksuspicious Hough
network_scan_UDP_UDP_responseOthersuspicious Hough
network_scan_TCP_RST_ACK_responseRST attacksuspicious Hough
network_scan_UDP_UDP_responseOthersuspicious Hough
network_scan_UDP_UDP_responseOthersuspicious Hough
network_scan_UDP_UDP_responseOthersuspicious Hough
network_scan_UDP_UDP_responseOthersuspicious Hough
network_scan_UDP_UDP_responseOthersuspicious Hough
network_scan_UDP_UDP_responseOthersuspicious Hough
network_scan_UDP_UDP_responseOthersuspicious Hough
network_scan_UDP_UDP_responseOthersuspicious Hough
network_scan_SYN_tSYN attacksuspicious Hough
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_UDP_UDP_responseOthersuspicious Gamma, KL
network_scan_TCP_TCP_ICMP_responsePing floodsuspicious Hough, Gamma, KL, PCA
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_UDP_UDP_responseOthersuspicious KL
point_to_point_port_scan_UDPOthersuspicious KL
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_UDP_UDP_responseOthersuspicious KL
point_to_multipoint_HTTPHTTP trafficanomalous Hough, PCA
point_to_multipointOtheranomalous Gamma, KL, PCA
multipoint_to_point_HTTPOtheranomalous Hough, Gamma, KL
multipoint_to_multipointHTTP trafficanomalous Hough, Gamma, KL, PCA
point_to_multipoint_HTTPHTTP trafficanomalous Gamma, PCA
multipoint_to_point_HTTPHTTP trafficanomalous Hough, Gamma, KL, PCA
alpha_flow_HTTPHTTP trafficanomalous Gamma, PCA
point_to_multipoint_HTTPHTTP trafficanomalous Gamma, PCA
multipoint_to_point_HTTPHTTP trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_point_low_activity_HTTPHTTP trafficanomalous Hough, Gamma, PCA
point_to_multipoint_low_activity_HTTPHTTP trafficanomalous Gamma, PCA
multipoint_to_point_low_activity_HTTPHTTP trafficanomalous Gamma, PCA
point_to_multipoint_HTTPHTTP trafficanomalous Gamma, PCA
multipoint_to_point_low_activity_HTTPHTTP trafficanomalous Gamma, PCA
alpha_flow_HTTPHTTP trafficanomalous Gamma, PCA
alpha_flow_HTTPHTTP trafficanomalous Gamma
alpha_flow_HTTPHTTP trafficanomalous Gamma, PCA
point_to_multipointOtheranomalous Gamma, KL, PCA
multipoint_to_point_HTTPHTTP trafficanomalous Hough, KL
multipoint_to_point_HTTPHTTP trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointOtheranomalous Gamma, KL, PCA
multipoint_to_pointOtheranomalous Hough, Gamma, KL, PCA
multipoint_to_multipointPing floodanomalous Hough, Gamma, KL, PCA
alpha_flow_HTTPHTTP trafficanomalous Hough, PCA
point_to_multipoint_HTTPHTTP trafficanomalous Hough, Gamma, KL, PCA
point_to_multipoint_HTTPHTTP trafficanomalous Gamma, PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, PCA
multipoint_to_point_low_activity_HTTPHTTP trafficanomalous Gamma, PCA
alpha_flow_HTTPHTTP trafficanomalous Hough, PCA
alpha_flow_HTTPHTTP trafficanomalous Gamma, PCA
point_to_multipointOtheranomalous Hough, Gamma, KL, PCA
heavy_hitterFTP attackanomalous PCA
multipoint_to_point_low_activityHTTPS trafficanomalous Hough, KL, PCA
point_to_multipoint_HTTPHTTP trafficanomalous Hough, PCA
point_to_multipoint_low_activity_HTTPHTTP trafficanomalous PCA
multipoint_to_point_low_activity_HTTPHTTP trafficsuspicious PCA
alpha_flowOthersuspicious Hough
point_to_multipoint_HTTPHTTP trafficsuspicious Gamma
small_alpha_flowHTTP trafficsuspicious Gamma
small_alpha_flowHTTP trafficsuspicious Gamma
alpha_flowOthersuspicious Gamma
point_to_multipoint_low_activityOthersuspicious Gamma, KL
point_to_pointHTTP trafficsuspicious Gamma
multipoint_to_pointOthersuspicious Gamma, KL
small_alpha_flowOthersuspicious Gamma, KL
alpha_flowOthersuspicious KL
multipoint_to_pointOthersuspicious KL
multipoint_to_pointOthersuspicious KL
alpha_flow_HTTPHTTP trafficsuspicious KL
multipoint_to_multipointOthersuspicious KL
multipoint_to_pointOthersuspicious KL
multipoint_to_point_low_activityOthersuspicious KL
multipoint_to_pointSMB attacksuspicious Gamma, KL
alpha_flowHTTPS trafficsuspicious KL
multipoint_to_multipointOthersuspicious Hough, KL
alpha_flow_HTTPHTTP trafficsuspicious PCA
point_to_multipoint_HTTPHTTP trafficsuspicious PCA
alpha_flow_HTTPHTTP trafficsuspicious Gamma, PCA
point_to_multipointOthersuspicious PCA
point_to_multipoint_HTTPHTTP trafficsuspicious PCA
point_to_multipoint_low_activity_HTTPHTTP trafficsuspicious Gamma, PCA
point_to_multipoint_low_activity_HTTPHTTP trafficsuspicious PCA
alpha_flow_HTTPHTTP trafficsuspicious PCA
alpha_flowOthersuspicious PCA
alpha_flow_HTTPHTTP trafficsuspicious Hough, PCA
multipoint_to_point_low_activity_HTTPHTTP trafficsuspicious PCA
alpha_flow_HTTPHTTP trafficsuspicious PCA
multipoint_to_point_low_activity_HTTPHTTP trafficsuspicious PCA
multipoint_to_point_low_activity_HTTPHTTP trafficsuspicious Gamma, PCA
small_alpha_flowHTTP trafficsuspicious PCA
multipoint_to_point_low_activity_HTTPHTTP trafficsuspicious PCA
alpha_flowOthersuspicious PCA
alpha_flowOthersuspicious PCA
point_to_multipoint_low_activityOthersuspicious PCA
alpha_flow_HTTPHTTP trafficsuspicious Hough, PCA
multipoint_to_point_low_activity_HTTPHTTP trafficsuspicious Gamma, PCA
multipoint_to_multipointHTTP trafficsuspicious PCA
alpha_flow_HTTPHTTP trafficsuspicious PCA
alpha_flow_HTTPHTTP trafficsuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
multipoint_to_point_low_activity_HTTPHTTP trafficsuspicious PCA
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
TaxonomyHeuristicLabelDetectors

Other:

"Notice" labels (admd file): 20081226_notice.xml
"Notice" labels (csv file): 20081226_notice.csv