MAWILab

Data set: 2022/01/09






Traffic Trace: 2022/01/09

Info: http://mawi.wide.ad.jp/mawi/samplepoint-F/2022/202201091400.html
tcpdump file: http://mawi.wide.ad.jp/mawi/samplepoint-F/2022/202201091400.pcap.gz

Anomalous Traffic:

"Anomalous" and "Suspicious" labels (admd file): 20220109_anomalous_suspicious.xml
"Anomalous" and "Suspicious" labels (csv file): 20220109_anomalous_suspicious.csv

Overview of the anomalies:

Number of anomalies: 308
Proportion of anomalies in terms of occurrence:


Breakdown of the anomalies:

TaxonomyHeuristicLabelDetectors
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
small_network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
point_to_point_port_scan_UDPOthersuspicious Hough, Gamma, KL, PCA
network_scan_UDP_UDP_responseOthersuspicious Gamma
network_scan_TCP_TCP_ICMP_responsePing floodsuspicious Gamma
port_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_point_to_point_denial_of_service_SYNSYN attacksuspicious Gamma
network_scan_TCP_TCP_ICMP_responsePing floodsuspicious Gamma
point_to_point_port_scan_UDPOthersuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Gamma
network_scan_TCP_TCP_ICMP_responsePing floodsuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
network_scan_UDP_UDP_responseOthersuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Gamma, KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Hough, KL
network_scan_UDP_UDP_responseOthersuspicious Gamma, KL
network_scan_UDP_UDP_responseOthersuspicious Gamma, KL, PCA
small_network_scan_SYNSYN attacksuspicious PCA
small_network_scan_SYNSYN attacksuspicious PCA
network_scan_SYNSYN attacksuspicious PCA
network_scan_TCP_RST_ACK_responseRST attacksuspicious PCA
small_point_to_point_denial_of_service_SYNSYN attacksuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL, PCA
network_scan_SYNSYN attackanomalous Hough
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous Hough
network_scan_SYNSYN attackanomalous Hough, Gamma, PCA
network_scan_SYNSYN attackanomalous Hough, PCA
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
distributed_network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough, KL
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_UDP_UDP_ICMP_responsePing floodanomalous Hough, Gamma, KL
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_SYNSYN attackanomalous Hough, Gamma, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous KL, PCA
small_network_scan_SYNSYN attackanomalous PCA
network_scan_UDP_UDP_responseOtheranomalous Gamma, PCA
network_scan_SYNSYN attackanomalous Gamma, PCA
network_scan_SYNSYN attackanomalous PCA
network_scan_UDP_otherOtheranomalous Hough, Gamma, PCA
distributed_denial_of_service_UDPOtheranomalous PCA
micro_alpha_flowHTTPS trafficsuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
micro_alpha_flowHTTPS trafficsuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
alpha_flowOthersuspicious Hough
alpha_flowOthersuspicious Hough
alpha_flowOthersuspicious Hough
alpha_flow_HTTPHTTP trafficsuspicious Hough
micro_alpha_flowHTTP trafficsuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
multipoint_to_pointRST attacksuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
point_to_multipointRST attacksuspicious Hough
point_to_multipointRST attacksuspicious Hough
multipoint_to_pointRST attacksuspicious Hough
point_to_multipoint_low_activitySYN attacksuspicious Hough
point_to_multipoint_low_activityOthersuspicious Gamma, PCA
multipoint_to_point_HTTPHTTP trafficsuspicious Hough, Gamma
alpha_flowOthersuspicious Gamma
multipoint_to_pointHTTPS trafficsuspicious Gamma, PCA
multipoint_to_point_low_activityHTTPS trafficsuspicious Gamma, KL
multipoint_to_multipointOthersuspicious Gamma, PCA
point_to_multipoint_HTTPSYN attacksuspicious Gamma
point_to_multipoint_low_activityOthersuspicious Gamma
point_to_multipointSYN attacksuspicious Gamma
small_alpha_flowOthersuspicious Gamma
multipoint_to_point_low_activity_HTTPHTTP trafficsuspicious Gamma
small_alpha_flowOthersuspicious Gamma
alpha_flow_HTTPHTTP trafficsuspicious Gamma
multipoint_to_multipointOthersuspicious Gamma, PCA
multipoint_to_point_low_activityHTTPS trafficsuspicious Gamma
point_to_multipointOthersuspicious Gamma
alpha_flowOthersuspicious Gamma
alpha_flowOthersuspicious Gamma
small_alpha_flowHTTPS trafficsuspicious Gamma
multipoint_to_point_low_activitySYN attacksuspicious Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
multipoint_to_pointPing floodsuspicious Gamma
multipoint_to_point_HTTPHTTP trafficsuspicious Gamma
micro_alpha_flowOthersuspicious Gamma
micro_alpha_flowHTTPS trafficsuspicious Gamma
multipoint_to_point_low_activityHTTP trafficsuspicious Gamma
small_alpha_flowHTTPS trafficsuspicious Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
small_alpha_flowHTTPS trafficsuspicious Gamma
multipoint_to_pointOthersuspicious Gamma
multipoint_to_point_low_activityHTTPS trafficsuspicious Gamma
multipoint_to_pointOthersuspicious Gamma
small_alpha_flowOthersuspicious Gamma
multipoint_to_pointPing floodsuspicious Gamma
point_to_multipointOthersuspicious Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
multipoint_to_multipointHTTPS trafficsuspicious Gamma
small_alpha_flowHTTP trafficsuspicious Gamma
multipoint_to_multipointPing floodsuspicious Gamma, KL, PCA
point_to_multipoint_low_activityOthersuspicious Hough, Gamma, KL
alpha_flowHTTPS trafficsuspicious Gamma
multipoint_to_multipointSYN attacksuspicious Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
multipoint_to_multipointPing floodsuspicious Gamma, KL
multipoint_to_pointPing floodsuspicious Gamma
alpha_flowOthersuspicious Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
multipoint_to_point_low_activityHTTPS trafficsuspicious Gamma
multipoint_to_point_low_activityHTTPS trafficsuspicious Gamma
small_alpha_flowHTTPS trafficsuspicious Gamma
alpha_flowOthersuspicious Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
multipoint_to_pointSMB attacksuspicious Gamma
host_outagePing floodsuspicious Gamma
multipoint_to_pointPing floodsuspicious Gamma
multipoint_to_pointPing floodsuspicious Gamma
multipoint_to_pointOthersuspicious Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
micro_alpha_flowOthersuspicious Gamma
multipoint_to_pointPing floodsuspicious Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
multipoint_to_pointOthersuspicious Gamma
multipoint_to_pointSYN attacksuspicious Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
small_alpha_flowHTTPS trafficsuspicious Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
small_alpha_flowHTTPS trafficsuspicious Gamma
multipoint_to_point_low_activityHTTPS trafficsuspicious Gamma
multipoint_to_pointSYN attacksuspicious Hough, KL
alpha_flowOthersuspicious Gamma, KL, PCA
small_alpha_flowHTTPS trafficsuspicious PCA
point_to_multipoint_low_activityHTTPS trafficsuspicious Gamma, PCA
point_to_multipoint_low_activityHTTPS trafficsuspicious PCA
point_to_multipointOthersuspicious Gamma, PCA
point_to_multipoint_low_activitySSH trafficsuspicious PCA
point_to_multipoint_low_activityOthersuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
point_to_multipoint_low_activityHTTPS trafficsuspicious PCA
multipoint_to_point_low_activityHTTPS trafficsuspicious PCA
multipoint_to_point_low_activityHTTPS trafficsuspicious PCA
alpha_flowOthersuspicious Gamma, PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
small_alpha_flowFIN attacksuspicious PCA
multipoint_to_point_low_activityOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_multipointHTTPS trafficsuspicious Gamma, PCA
multipoint_to_point_low_activityOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
alpha_flow_HTTPHTTP trafficsuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
alpha_flowOthersuspicious PCA
alpha_flowHTTPS trafficsuspicious Gamma, PCA
multipoint_to_pointOthersuspicious Gamma, KL
ipv4_gre_tunnelOtheranomalous Hough, Gamma, PCA
multipoint_to_point_low_activityOtheranomalous Hough, Gamma
point_to_multipointSYN attackanomalous Hough
point_to_multipointOtheranomalous Hough
point_to_multipointSYN attackanomalous Hough
point_to_multipointOtheranomalous Hough
multipoint_to_multipointOtheranomalous Hough, Gamma, KL, PCA
multipoint_to_pointSYN attackanomalous Hough
multipoint_to_pointRST attackanomalous Hough
multipoint_to_multipointSSH attackanomalous Hough, Gamma, PCA
multipoint_to_pointOtheranomalous Hough
multipoint_to_pointRST attackanomalous Hough
point_to_multipoint_low_activitySYN attackanomalous Hough
point_to_multipoint_low_activitySYN attackanomalous Hough
multipoint_to_multipointOtheranomalous Hough, Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
multipoint_to_point_low_activityHTTPS trafficanomalous Hough, Gamma, KL, PCA
small_alpha_flowHTTPS trafficanomalous Gamma, PCA
multipoint_to_pointOtheranomalous Gamma, PCA
icmp_errorPing floodanomalous Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
point_to_multipointSYN attackanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointOtheranomalous Hough, Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
point_to_multipointOtheranomalous Gamma, PCA
point_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_point_low_activity_HTTPHTTP trafficanomalous Hough, PCA
point_to_multipointSYN attackanomalous Gamma, KL, PCA
multipoint_to_multipointOtheranomalous Hough, Gamma, PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, PCA
small_alpha_flowHTTPS trafficanomalous Hough, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_point_HTTPHTTP trafficanomalous Gamma, PCA
alpha_flowHTTPS trafficanomalous Hough, PCA
point_to_multipoint_low_activityHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous PCA
multipoint_to_multipointSSH trafficanomalous Gamma, KL, PCA
multipoint_to_multipointSSH trafficanomalous Gamma, KL, PCA
point_to_multipoint_HTTPHTTP trafficanomalous Gamma, PCA
multipoint_to_point_low_activityHTTPS trafficanomalous Hough, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, KL, PCA
alpha_flowHTTPS trafficanomalous PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, KL, PCA
multipoint_to_point_low_activityOtheranomalous Gamma, KL, PCA
small_alpha_flowHTTPS trafficanomalous PCA
alpha_flowHTTPS trafficanomalous Hough, Gamma, KL, PCA
point_to_multipointHTTPS trafficanomalous Gamma, PCA
point_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointHTTP trafficanomalous Hough, Gamma, KL, PCA
point_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
point_to_multipoint_HTTPHTTP trafficanomalous Hough, Gamma, PCA
alpha_flowHTTPS trafficanomalous Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, KL, PCA
point_to_multipoint_low_activityOtheranomalous PCA
ttl_errorPing floodanomalous PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
alpha_flowOtheranomalous PCA
small_alpha_flowHTTPS trafficanomalous PCA
small_alpha_flowHTTPS trafficanomalous PCA
point_to_multipointOtheranomalous Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
alpha_flowOtheranomalous PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
alpha_flowHTTPS trafficanomalous PCA
alpha_flow_HTTPHTTP trafficanomalous PCA
multipoint_to_point_low_activityHTTPS trafficanomalous PCA
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma, KL, PCA
emptyUnknownsuspicious Gamma, KL, PCA
emptyUnknownanomalous Gamma
emptyUnknownanomalous Gamma
emptyUnknownanomalous Hough, Gamma, KL, PCA
emptyUnknownanomalous Hough, Gamma, KL, PCA
emptyUnknownanomalous Hough, Gamma, PCA
emptyUnknownanomalous Gamma, KL, PCA
TaxonomyHeuristicLabelDetectors

Other:

"Notice" labels (admd file): 20220109_notice.xml
"Notice" labels (csv file): 20220109_notice.csv