MAWILab

Data set: 2013/07/26






Traffic Trace: 2013/07/26

Info: http://mawi.wide.ad.jp/mawi/samplepoint-F/2013/201307261400.html
tcpdump file: http://mawi.wide.ad.jp/mawi/samplepoint-F/2013/201307261400.dump.gz

Anomalous Traffic:

"Anomalous" and "Suspicious" labels (admd file): 20130726_anomalous_suspicious.xml
"Anomalous" and "Suspicious" labels (csv file): 20130726_anomalous_suspicious.csv

Overview of the anomalies:

Number of anomalies: 106
Proportion of anomalies in terms of occurrence:


Breakdown of the anomalies:

TaxonomyHeuristicLabelDetectors
network_scan_ACKHTTP trafficsuspicious Gamma
network_scan_ICMP_ecrq_ICMP_ecrp_du_rm_te_responsePing floodsuspicious Gamma
network_scan_UDP_UDP_responseOthersuspicious Gamma
point_to_point_port_scan_UDPOthersuspicious Gamma
network_scan_UDP_UDP_responseOthersuspicious Gamma
network_scan_UDP_UDP_responseOthersuspicious Gamma, KL
point_to_point_port_scan_UDPOthersuspicious KL
network_scan_UDP_UDP_responseOthersuspicious Gamma, KL, PCA
network_scan_UDP_UDP_responseOthersuspicious Gamma, KL, PCA
network_scan_UDP_UDP_responseOthersuspicious KL
point_to_point_denial_of_service_SYNSYN attacksuspicious KL
network_scan_UDPOthersuspicious KL
network_scan_UDPOthersuspicious KL
network_scan_ACKHTTP trafficsuspicious Gamma, KL, PCA
network_scan_ACKHTTPS trafficsuspicious Gamma, PCA
small_point_to_point_denial_of_service_SYNSYN attacksuspicious PCA
network_scan_ACKHTTPS trafficsuspicious PCA
network_scan_ACKHTTP trafficsuspicious PCA
network_scan_ACKHTTP trafficsuspicious PCA
network_scan_SYN_t_139_445SYN attackanomalous Hough
network_scan_SYN_tSYN attackanomalous Hough, KL
network_scan_SYN_tSYN attackanomalous Hough
network_scan_SYN_tSYN attackanomalous Hough
network_scan_SYN_tSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_ACKHTTP trafficanomalous Gamma, PCA
network_scan_ACKHTTP trafficanomalous Gamma, KL, PCA
network_scan_SYN_tSYN attackanomalous Hough, Gamma, KL, PCA
point_to_multipoint_HTTPHTTP trafficsuspicious Gamma
small_alpha_flowHTTP trafficsuspicious Gamma
small_alpha_flowHTTP trafficsuspicious Gamma
micro_alpha_flowHTTPS trafficsuspicious Gamma
small_alpha_flowHTTP trafficsuspicious Gamma
point_to_multipointOthersuspicious Gamma, KL
multipoint_to_point_HTTPHTTP trafficsuspicious KL
multipoint_to_pointOthersuspicious KL
multipoint_to_point_HTTPHTTP trafficsuspicious KL
multipoint_to_point_HTTPHTTP trafficsuspicious KL
multipoint_to_point_low_activitySYN attacksuspicious KL
multipoint_to_multipointHTTP trafficsuspicious Gamma, KL, PCA
multipoint_to_pointHTTPS trafficsuspicious KL
multipoint_to_pointOthersuspicious KL
alpha_flow_HTTPHTTP trafficsuspicious KL
alpha_flow_HTTPHTTP trafficsuspicious KL
multipoint_to_point_low_activityHTTPS trafficsuspicious KL
alpha_flowOthersuspicious KL
point_to_multipoint_HTTPPing floodsuspicious KL
point_to_multipointOthersuspicious Gamma, KL
point_to_multipoint_HTTPSYN attacksuspicious KL
multipoint_to_multipointSYN attacksuspicious KL
point_to_multipointRST attacksuspicious KL
multipoint_to_multipointHTTP trafficsuspicious Gamma, KL, PCA
alpha_flow_HTTPHTTP trafficsuspicious Gamma, PCA
multipoint_to_multipointHTTPS trafficsuspicious Gamma, PCA
small_alpha_flowHTTP trafficsuspicious PCA
ipv4_ipv6_tunnelOthersuspicious PCA
point_to_multipoint_low_activityOthersuspicious PCA
small_alpha_flowHTTP trafficsuspicious PCA
multipoint_to_multipointHTTP trafficsuspicious Gamma, PCA
multipoint_to_point_HTTPHTTP trafficsuspicious Gamma, PCA
alpha_flowHTTPS trafficsuspicious PCA
alpha_flowOthersuspicious PCA
alpha_flowOthersuspicious PCA
icmp_errorPing floodsuspicious Gamma, KL, PCA
multipoint_to_multipointHTTP trafficsuspicious Gamma, PCA
multipoint_to_point_low_activityHTTPS trafficsuspicious PCA
multipoint_to_multipointHTTP trafficsuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_multipointHTTP trafficsuspicious PCA
multipoint_to_multipointOthersuspicious Gamma, PCA
multipoint_to_multipointHTTPS trafficsuspicious Gamma, PCA
point_to_multipointHTTPS trafficsuspicious PCA
micro_alpha_flowOthersuspicious PCA
alpha_flow_HTTPHTTP trafficanomalous Gamma, PCA
point_to_multipoint_HTTPHTTP trafficanomalous Gamma, PCA
alpha_flow_HTTPHTTP trafficanomalous Gamma, PCA
multipoint_to_multipointOtheranomalous Gamma, KL
point_to_multipoint_low_activityOtheranomalous Gamma, KL
multipoint_to_multipointOtheranomalous Gamma, KL, PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, KL, PCA
multipoint_to_point_HTTPHTTP trafficanomalous Gamma, KL, PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, PCA
multipoint_to_point_HTTPHTTP trafficanomalous Gamma, KL, PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, KL, PCA
multipoint_to_point_HTTPHTTP trafficanomalous Gamma, PCA
multipoint_to_multipointOtheranomalous Gamma, KL, PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, PCA
multipoint_to_point_HTTPHTTP trafficanomalous Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
point_to_multipoint_HTTPHTTP trafficanomalous Gamma, KL, PCA
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownanomalous Hough
emptyUnknownanomalous Hough
emptyUnknownanomalous Hough
emptyUnknownanomalous Hough
emptyUnknownanomalous Hough
emptyUnknownanomalous Hough
emptyUnknownanomalous Hough
emptyUnknownanomalous Hough
emptyUnknownanomalous Hough
TaxonomyHeuristicLabelDetectors

Other:

"Notice" labels (admd file): 20130726_notice.xml
"Notice" labels (csv file): 20130726_notice.csv