| 2007 | 2008 | 2009 | 2010 | 2011 | 2012 | 2013 | 2014 | 2015 | 2016 | 2017 | 2018 | 2019 | 2020 | 2021 | 2022 | 2024 | 
| Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | 
Traffic Trace: 2022/01/11
Info: http://mawi.wide.ad.jp/mawi/samplepoint-F/2022/202201111400.htmltcpdump file: http://mawi.wide.ad.jp/mawi/samplepoint-F/2022/202201111400.pcap.gz
Anomalous Traffic:
"Anomalous" and "Suspicious" labels (admd file): 20220111_anomalous_suspicious.xml"Anomalous" and "Suspicious" labels (csv file): 20220111_anomalous_suspicious.csv
Overview of the anomalies:
	Number of anomalies: 168
    Proportion of anomalies in terms of occurrence:
	
Breakdown of the anomalies:
| Taxonomy | Heuristic | Label | Detectors | 
|---|---|---|---|
| network_scan_UDP_other | Other | suspicious | Hough, KL | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_UDP_other | Other | suspicious | Hough, KL | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_UDP_other | Other | suspicious | Hough, KL | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_UDP_other | Other | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN_139_445 | SYN attack | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough, PCA | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough, KL | 
| network_scan_SYN | SYN attack | suspicious | Hough, PCA | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_ICMP_ecrq | Ping flood | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN_139_445 | SYN attack | suspicious | Hough | 
| small_network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN_139_445 | SYN attack | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN_139_445 | SYN attack | suspicious | Hough | 
| network_scan_SYN_139_445 | SYN attack | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN | Other | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough, KL | 
| network_scan_SYN_139_445 | SYN attack | suspicious | Hough | 
| network_scan_SYN_139_445 | SYN attack | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_UDP_other | Other | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_SYN | SYN attack | suspicious | Hough | 
| network_scan_UDP_other | Other | suspicious | Hough | 
| network_scan_UDP_other | Other | suspicious | Hough | 
| network_scan_UDP_other | Other | suspicious | Hough | 
| network_scan_TCP_RST_ACK_response | RST attack | suspicious | Gamma | 
| network_scan_TCP_TCP_ICMP_response | Ping flood | suspicious | Gamma | 
| network_scan_UDP_UDP_response | Other | suspicious | Gamma, KL | 
| network_scan_SYN | SYN attack | suspicious | Gamma, PCA | 
| network_scan_SYN | SYN attack | suspicious | PCA | 
| small_network_scan_SYN | SYN attack | suspicious | PCA | 
| small_network_scan_SYN | SYN attack | suspicious | PCA | 
| network_scan_SYN | SYN attack | suspicious | PCA | 
| network_scan_ICMP_ecrq_ICMP_ecrp_response | Ping flood | suspicious | Gamma, PCA | 
| small_network_scan_SYN | SYN attack | suspicious | PCA | 
| small_network_scan_SYN | SYN attack | suspicious | PCA | 
| network_scan_UDP_DNS | Other | suspicious | PCA | 
| distributed_denial_of_service_ICMP | Ping flood | suspicious | Gamma, PCA | 
| network_scan_SYN | SYN attack | anomalous | Hough, PCA | 
| network_scan_SYN | SYN attack | anomalous | Hough, Gamma, KL, PCA | 
| network_scan_SYN | SYN attack | anomalous | Hough, Gamma, KL, PCA | 
| network_scan_ICMP_ecrq_ICMP_ecrp_response | Ping flood | anomalous | Hough, KL, PCA | 
| network_scan_UDP_other | Other | anomalous | Hough, PCA | 
| network_scan_UDP_other | Other | anomalous | Hough, KL, PCA | 
| multipoint_to_point_low_activity | HTTPS traffic | suspicious | Hough | 
| ipv4_gre_tunnel | Other | suspicious | Hough, PCA | 
| small_alpha_flow | HTTPS traffic | suspicious | Hough | 
| alpha_flow | Other | suspicious | Hough | 
| point_to_multipoint | HTTPS traffic | suspicious | Hough, Gamma, PCA | 
| multipoint_to_multipoint | Other | suspicious | Hough, PCA | 
| point_to_multipoint | HTTPS traffic | suspicious | Hough, PCA | 
| multipoint_to_point | RST attack | suspicious | Hough | 
| point_to_multipoint | Other | suspicious | Hough | 
| point_to_multipoint | RST attack | suspicious | Hough | 
| point_to_multipoint | SYN attack | suspicious | Hough | 
| point_to_multipoint | Other | suspicious | Hough | 
| point_to_multipoint | Other | suspicious | Hough | 
| point_to_multipoint | SYN attack | suspicious | Hough | 
| point_to_multipoint | Other | suspicious | Hough | 
| point_to_multipoint | SYN attack | suspicious | Hough | 
| point_to_multipoint | RST attack | suspicious | Hough | 
| multipoint_to_point | RST attack | suspicious | Hough | 
| multipoint_to_point | RST attack | suspicious | Hough | 
| multipoint_to_point | RST attack | suspicious | Hough | 
| multipoint_to_point | RST attack | suspicious | Hough | 
| multipoint_to_multipoint | Other | suspicious | Hough | 
| multipoint_to_point | HTTPS traffic | suspicious | Gamma | 
| small_alpha_flow | HTTPS traffic | suspicious | Gamma | 
| multipoint_to_point_low_activity | HTTPS traffic | suspicious | Gamma | 
| alpha_flow | HTTPS traffic | suspicious | Hough, PCA | 
| point_to_multipoint | HTTPS traffic | suspicious | Gamma, PCA | 
| alpha_flow | HTTPS traffic | suspicious | Gamma, PCA | 
| point_to_multipoint | HTTPS traffic | suspicious | Hough, Gamma, PCA | 
| multipoint_to_multipoint | HTTP traffic | suspicious | Hough, Gamma, KL, PCA | 
| point_to_multipoint | HTTPS traffic | suspicious | PCA | 
| alpha_flow | HTTPS traffic | suspicious | KL, PCA | 
| multipoint_to_multipoint | HTTPS traffic | suspicious | PCA | 
| point_to_multipoint | HTTPS traffic | suspicious | PCA | 
| point_to_multipoint | HTTPS traffic | suspicious | PCA | 
| ipv4_gre_tunnel | Other | suspicious | PCA | 
| point_to_multipoint_low_activity | HTTPS traffic | suspicious | PCA | 
| multipoint_to_point | HTTPS traffic | suspicious | Gamma, PCA | 
| alpha_flow | Other | suspicious | PCA | 
| multipoint_to_point | HTTPS traffic | suspicious | PCA | 
| point_to_multipoint | SYN attack | suspicious | PCA | 
| point_to_multipoint_low_activity | HTTPS traffic | suspicious | PCA | 
| point_to_multipoint | HTTPS traffic | suspicious | PCA | 
| point_to_multipoint | SYN attack | suspicious | PCA | 
| point_to_multipoint | SYN attack | suspicious | PCA | 
| multipoint_to_point | HTTPS traffic | suspicious | PCA | 
| multipoint_to_multipoint | HTTPS traffic | suspicious | PCA | 
| multipoint_to_point | HTTPS traffic | suspicious | PCA | 
| alpha_flow | HTTPS traffic | suspicious | Hough, Gamma, KL, PCA | 
| micro_alpha_flow | Other | suspicious | PCA | 
| multipoint_to_point | HTTPS traffic | suspicious | PCA | 
| point_to_multipoint_low_activity | HTTPS traffic | suspicious | PCA | 
| point_to_multipoint_HTTP | HTTP traffic | suspicious | PCA | 
| multipoint_to_point | HTTPS traffic | suspicious | PCA | 
| alpha_flow | HTTPS traffic | suspicious | PCA | 
| alpha_flow | HTTPS traffic | suspicious | PCA | 
| alpha_flow | HTTPS traffic | suspicious | PCA | 
| multipoint_to_point | HTTPS traffic | suspicious | PCA | 
| multipoint_to_multipoint | HTTPS traffic | suspicious | PCA | 
| point_to_multipoint_low_activity | HTTPS traffic | suspicious | PCA | 
| multipoint_to_point | HTTPS traffic | suspicious | PCA | 
| multipoint_to_multipoint | HTTPS traffic | suspicious | Gamma, PCA | 
| multipoint_to_point | HTTPS traffic | suspicious | PCA | 
| multipoint_to_point | HTTPS traffic | suspicious | PCA | 
| multipoint_to_multipoint | HTTP traffic | suspicious | PCA | 
| multipoint_to_point | HTTPS traffic | suspicious | PCA | 
| multipoint_to_point_low_activity_HTTP | HTTP traffic | suspicious | PCA | 
| alpha_flow_HTTP | HTTP traffic | suspicious | PCA | 
| multipoint_to_point_low_activity | HTTPS traffic | suspicious | PCA | 
| alpha_flow_HTTP | HTTP traffic | suspicious | PCA | 
| multipoint_to_point | HTTPS traffic | suspicious | PCA | 
| multipoint_to_multipoint | HTTPS traffic | suspicious | Gamma, PCA | 
| multipoint_to_point | Other | anomalous | Hough, Gamma, KL, PCA | 
| multipoint_to_point | HTTPS traffic | anomalous | Gamma | 
| point_to_multipoint | SYN attack | anomalous | Hough, Gamma, KL, PCA | 
| point_to_multipoint | HTTPS traffic | anomalous | Hough, Gamma, PCA | 
| multipoint_to_point | HTTPS traffic | anomalous | Hough, Gamma, PCA | 
| point_to_multipoint_HTTP | HTTP traffic | anomalous | Hough, Gamma, PCA | 
| point_to_multipoint | Other | anomalous | Hough, PCA | 
| multipoint_to_point_low_activity | HTTPS traffic | anomalous | Gamma, PCA | 
| multipoint_to_multipoint | Other | anomalous | Hough, Gamma, KL, PCA | 
| point_to_multipoint | HTTPS traffic | anomalous | Gamma, PCA | 
| multipoint_to_point | HTTPS traffic | anomalous | Gamma, KL, PCA | 
| point_to_multipoint | HTTPS traffic | anomalous | Hough, Gamma, KL, PCA | 
| multipoint_to_multipoint | HTTPS traffic | anomalous | Hough, Gamma, KL, PCA | 
| multipoint_to_multipoint | HTTPS traffic | anomalous | Hough, Gamma, PCA | 
| multipoint_to_multipoint | HTTPS traffic | anomalous | Gamma, PCA | 
| multipoint_to_multipoint | HTTPS traffic | anomalous | Gamma, KL, PCA | 
| multipoint_to_multipoint | HTTPS traffic | anomalous | Hough, Gamma, KL, PCA | 
| point_to_multipoint | HTTPS traffic | anomalous | Hough, Gamma, KL, PCA | 
| multipoint_to_multipoint | HTTPS traffic | anomalous | Hough, Gamma, PCA | 
| multipoint_to_multipoint | HTTPS traffic | anomalous | Hough, Gamma, KL, PCA | 
| multipoint_to_multipoint | HTTPS traffic | anomalous | Hough, Gamma, KL, PCA | 
| multipoint_to_point | HTTPS traffic | anomalous | Gamma, PCA | 
| multipoint_to_point | Other | anomalous | Hough, PCA | 
| multipoint_to_point | HTTPS traffic | anomalous | Hough, Gamma, PCA | 
| multipoint_to_point | HTTPS traffic | anomalous | Hough, Gamma, PCA | 
| point_to_multipoint | HTTPS traffic | anomalous | Hough, Gamma, PCA | 
| multipoint_to_multipoint | HTTPS traffic | anomalous | Gamma, PCA | 
| point_to_multipoint | SYN attack | anomalous | Hough, Gamma, PCA | 
| multipoint_to_point | SSH traffic | anomalous | KL, PCA | 
| multipoint_to_multipoint | HTTPS traffic | anomalous | Hough, KL, PCA | 
| empty | Unknown | suspicious | Gamma | 
| empty | Unknown | suspicious | Gamma | 
| empty | Other | suspicious | Gamma | 
| empty | Unknown | suspicious | Gamma | 
| empty | Unknown | suspicious | Gamma | 
| Taxonomy | Heuristic | Label | Detectors | 
Other:
"Notice" labels (admd file): 20220111_notice.xml"Notice" labels (csv file): 20220111_notice.csv