MAWILab

Data set: 2022/01/02






Traffic Trace: 2022/01/02

Info: http://mawi.wide.ad.jp/mawi/samplepoint-F/2022/202201021400.html
tcpdump file: http://mawi.wide.ad.jp/mawi/samplepoint-F/2022/202201021400.pcap.gz

Anomalous Traffic:

"Anomalous" and "Suspicious" labels (admd file): 20220102_anomalous_suspicious.xml
"Anomalous" and "Suspicious" labels (csv file): 20220102_anomalous_suspicious.csv

Overview of the anomalies:

Number of anomalies: 136
Proportion of anomalies in terms of occurrence:


Breakdown of the anomalies:

TaxonomyHeuristicLabelDetectors
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
small_network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough, PCA
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough, KL, PCA
distributed_network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_TCP_RST_ACK_responseRST attackanomalous Gamma, KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous Hough, Gamma, KL, PCA
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_UDP_DNSOthersuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
small_network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
small_network_scan_SYNSYN attacksuspicious Hough
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Gamma, KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Gamma, KL
port_scan_UDPOthersuspicious Gamma, KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_du_rm_te_responsePing floodsuspicious Gamma, KL, PCA
multipoint_to_pointOtheranomalous Hough, Gamma, PCA
multipoint_to_multipointSYN attackanomalous Hough, Gamma, KL, PCA
point_to_multipointSYN attackanomalous Hough
point_to_multipointOtheranomalous Hough, Gamma, PCA
multipoint_to_multipointSYN attackanomalous Hough, Gamma, PCA
point_to_multipointSYN attackanomalous Hough
point_to_multipointOtheranomalous Hough, Gamma, KL, PCA
point_to_multipointOtheranomalous Hough
multipoint_to_pointRST attackanomalous Hough
ipv4_gre_tunnelOtheranomalous Hough, Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointSYN attackanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointOtheranomalous Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
small_alpha_flowHTTPS trafficanomalous Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointOtheranomalous Hough, Gamma, PCA
point_to_multipointSYN attackanomalous Hough, PCA
point_to_multipointSYN attackanomalous Hough, Gamma, KL, PCA
point_to_multipoint_low_activityHTTPS trafficanomalous Gamma, PCA
point_to_multipointSSH trafficanomalous Hough, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
alpha_flowHTTPS trafficanomalous PCA
multipoint_to_multipointHTTP trafficanomalous Hough, Gamma, KL, PCA
point_to_multipoint_HTTPHTTP trafficanomalous Gamma, PCA
point_to_multipointSYN attackanomalous Hough, Gamma, PCA
point_to_multipointHTTPS trafficanomalous Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, PCA
point_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
point_to_multipointHTTPS trafficanomalous Gamma, PCA
icmp_errorPing floodanomalous PCA
multipoint_to_pointOtheranomalous PCA
alpha_flowHTTPS trafficanomalous PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
alpha_flowHTTPS trafficanomalous PCA
alpha_flow_HTTPHTTP trafficanomalous PCA
alpha_flowHTTPS trafficanomalous PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, KL, PCA
multipoint_to_multipointHTTP trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, KL, PCA
multipoint_to_pointRST attacksuspicious Hough
micro_alpha_flowUnknownsuspicious Hough
point_to_multipoint_low_activityHTTPS trafficsuspicious Hough, Gamma
multipoint_to_multipointOthersuspicious Gamma, PCA
multipoint_to_pointRST attacksuspicious Gamma, PCA
heavy_hitterOthersuspicious Hough, Gamma
multipoint_to_multipointOthersuspicious Gamma, KL
point_to_multipointHTTPS trafficsuspicious Gamma, PCA
multipoint_to_point_low_activityOthersuspicious KL, PCA
point_to_multipointHTTPS trafficsuspicious PCA
heavy_hitterFIN attacksuspicious Gamma, PCA
multipoint_to_pointSMB attacksuspicious Hough, PCA
multipoint_to_point_low_activityOthersuspicious Gamma, PCA
multipoint_to_multipointOthersuspicious Gamma, KL, PCA
small_alpha_flowHTTPS trafficsuspicious PCA
point_to_multipoint_low_activityOthersuspicious PCA
point_to_multipointOthersuspicious Gamma, PCA
multipoint_to_multipointHTTPS trafficsuspicious Gamma, KL, PCA
alpha_flowHTTPS trafficsuspicious PCA
heavy_hitterHTTP trafficsuspicious Gamma, PCA
alpha_flowOthersuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_point_HTTPHTTP trafficsuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_multipointSYN attacksuspicious PCA
multipoint_to_pointSMB attacksuspicious PCA
alpha_flow_HTTPHTTP trafficsuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
emptyUnknownanomalous Hough, Gamma, KL, PCA
emptyUnknownanomalous Hough, Gamma, PCA
emptyUnknownanomalous Hough, Gamma, KL, PCA
emptyUnknownsuspicious Gamma, KL, PCA
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma, KL
emptyUnknownsuspicious Gamma, KL, PCA
TaxonomyHeuristicLabelDetectors

Other:

"Notice" labels (admd file): 20220102_notice.xml
"Notice" labels (csv file): 20220102_notice.csv