MAWILab

Data set: 2013/02/10






Traffic Trace: 2013/02/10

Info: http://mawi.wide.ad.jp/mawi/samplepoint-F/2013/201302101400.html
tcpdump file: http://mawi.wide.ad.jp/mawi/samplepoint-F/2013/201302101400.dump.gz

Anomalous Traffic:

"Anomalous" and "Suspicious" labels (admd file): 20130210_anomalous_suspicious.xml
"Anomalous" and "Suspicious" labels (csv file): 20130210_anomalous_suspicious.csv

Overview of the anomalies:

Number of anomalies: 131
Proportion of anomalies in terms of occurrence:


Breakdown of the anomalies:

TaxonomyHeuristicLabelDetectors
network_scan_SYN_tSYN attacksuspicious Hough
network_scan_SYN_tSYN attacksuspicious Hough
network_scan_UDP_UDP_responseOthersuspicious Hough, Gamma
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_UDP_UDP_responseOthersuspicious KL
distributed_denial_of_service_SYNSYN attacksuspicious KL
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_ACKHTTP trafficsuspicious Hough, Gamma, PCA
network_scan_ACKHTTP trafficsuspicious PCA
network_scan_UDP_UDP_responseOthersuspicious PCA
network_scan_ACKHTTP trafficanomalous Hough, Gamma
network_scan_ACKHTTP trafficanomalous Hough
network_scan_SYN_tSYN attackanomalous Hough, KL
network_scan_ACKHTTP trafficanomalous Hough, PCA
network_scan_SYN_tSYN attackanomalous Hough
network_scan_SYN_tSYN attackanomalous Hough, KL
network_scan_SYN_tSYN attackanomalous Hough, Gamma
network_scan_SYN_tSYN attackanomalous Hough
network_scan_TCP_RST_ACK_responseRST attackanomalous Hough, Gamma, PCA
network_scan_SYN_tSYN attackanomalous Hough, Gamma, PCA
network_scan_ACKHTTP trafficanomalous Gamma, PCA
network_scan_UDPOtheranomalous Hough, KL
network_scan_SYN_tSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_TCP_ICMP_du_responsePing floodanomalous Hough, Gamma, KL, PCA
network_scan_UDP_UDP_responseOtheranomalous KL
network_scan_UDP_UDP_responseOtheranomalous KL
point_to_point_denial_of_service_SYNSYN attackanomalous KL
point_to_point_port_scan_UDPOtheranomalous Hough, KL, PCA
point_to_point_denial_of_service_SYNSYN attackanomalous Hough, KL
network_scan_UDP_UDP_responseOtheranomalous KL, PCA
network_scan_UDP_UDP_responseOtheranomalous KL
network_scan_ACKHTTP trafficanomalous Hough, Gamma, KL, PCA
alpha_flowOthersuspicious Hough, PCA
small_alpha_flowOthersuspicious Hough
small_alpha_flowHTTP trafficsuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
alpha_flow_HTTPHTTP trafficsuspicious Hough
alpha_flow_HTTPHTTP trafficsuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
point_to_multipoint_low_activity_HTTPHTTP trafficsuspicious Hough
small_alpha_flowHTTP trafficsuspicious Hough
multipoint_to_point_low_activityOthersuspicious Hough
small_alpha_flowHTTP trafficsuspicious Hough
alpha_flow_HTTPHTTP trafficsuspicious Hough, KL
alpha_flowSSH trafficsuspicious Hough
point_to_multipointSYN attacksuspicious Hough
multipoint_to_point_HTTPHTTP trafficsuspicious Hough, Gamma
alpha_flow_HTTPHTTP trafficsuspicious Hough, Gamma
small_alpha_flowHTTP trafficsuspicious Gamma
small_alpha_flowHTTP trafficsuspicious Gamma
multipoint_to_point_low_activity_HTTPHTTP trafficsuspicious KL
icmp_errorPing floodsuspicious KL
multipoint_to_pointOthersuspicious KL
alpha_flowHTTPS trafficsuspicious KL
multipoint_to_pointOthersuspicious KL
multipoint_to_multipointRST attacksuspicious KL
small_alpha_flowOthersuspicious KL
multipoint_to_point_low_activityOthersuspicious KL
alpha_flow_HTTPHTTP trafficsuspicious KL
point_to_multipoint_low_activityHTTPS trafficsuspicious Hough, PCA
multipoint_to_multipointHTTP trafficsuspicious PCA
point_to_multipoint_HTTPHTTP trafficsuspicious Hough, PCA
point_to_multipoint_low_activityOthersuspicious PCA
multipoint_to_point_HTTPHTTP trafficsuspicious PCA
alpha_flow_HTTPHTTP trafficsuspicious PCA
alpha_flow_HTTPHTTP trafficsuspicious PCA
alpha_flow_HTTPHTTP trafficsuspicious PCA
multipoint_to_point_HTTPHTTP trafficsuspicious PCA
multipoint_to_multipointHTTP trafficsuspicious Gamma, PCA
multipoint_to_point_HTTPHTTP trafficsuspicious PCA
small_alpha_flowHTTP trafficsuspicious PCA
alpha_flow_HTTPHTTP trafficsuspicious PCA
small_alpha_flowHTTP trafficanomalous Hough
multipoint_to_multipointHTTP trafficanomalous Hough, PCA
point_to_multipointOtheranomalous Hough, PCA
point_to_multipoint_HTTPSYN attackanomalous Hough, Gamma, PCA
point_to_multipoint_low_activityOtheranomalous Hough
small_alpha_flowHTTP trafficanomalous Hough
point_to_multipoint_low_activity_HTTPHTTP trafficanomalous Hough, KL, PCA
small_alpha_flowHTTP trafficanomalous Hough
point_to_multipointSYN attackanomalous Hough
point_to_multipointRST attackanomalous Hough
point_to_multipoint_HTTPSYN attackanomalous Hough
point_to_multipoint_HTTPHTTP attackanomalous Hough, Gamma, KL
multipoint_to_point_HTTPHTTP trafficanomalous Hough
alpha_flowOtheranomalous Hough, Gamma
multipoint_to_point_HTTPHTTP trafficanomalous Gamma
multipoint_to_point_low_activity_HTTPHTTP trafficanomalous Hough, Gamma, PCA
multipoint_to_point_HTTPHTTP trafficanomalous Gamma, PCA
alpha_flowHTTPS trafficanomalous Hough, KL
multipoint_to_pointOtheranomalous Hough, KL
icmp_errorPing floodanomalous KL
heavy_hitterHTTP trafficanomalous Hough, KL
icmp_errorPing floodanomalous KL
multipoint_to_point_HTTPHTTP trafficanomalous KL
multipoint_to_point_HTTPHTTP trafficanomalous Hough, Gamma, KL
multipoint_to_point_low_activity_HTTPHTTP trafficanomalous KL
multipoint_to_point_low_activityOtheranomalous KL
point_to_multipoint_low_activity_HTTPHTTP trafficanomalous Gamma, PCA
point_to_multipoint_low_activityOtheranomalous Gamma, PCA
multipoint_to_point_HTTPHTTP trafficanomalous Gamma, KL, PCA
point_to_multipoint_low_activity_HTTPHTTP attackanomalous Hough, Gamma, KL, PCA
multipoint_to_point_HTTPHTTP trafficanomalous Gamma, KL, PCA
multipoint_to_point_HTTPHTTP trafficanomalous Gamma, KL, PCA
multipoint_to_point_HTTPHTTP trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_point_low_activity_HTTPHTTP attackanomalous Hough, Gamma, KL, PCA
multipoint_to_point_low_activityOtheranomalous Hough, Gamma, PCA
multipoint_to_point_HTTPHTTP trafficanomalous PCA
multipoint_to_point_HTTPHTTP trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, KL, PCA
ipv4_ipv6_tunnelOtheranomalous PCA
multipoint_to_point_low_activity_HTTPHTTP trafficanomalous PCA
alpha_flowHTTPS trafficanomalous Gamma, KL, PCA
multipoint_to_point_HTTPHTTP trafficanomalous PCA
alpha_flow_HTTPHTTP trafficanomalous PCA
alpha_flow_HTTPHTTP trafficanomalous PCA
multipoint_to_point_HTTPHTTP trafficanomalous Hough, Gamma, PCA
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
TaxonomyHeuristicLabelDetectors

Other:

"Notice" labels (admd file): 20130210_notice.xml
"Notice" labels (csv file): 20130210_notice.csv