MAWILab

Data set: 2023/02/19






Traffic Trace: 2023/02/19

Info: http://mawi.wide.ad.jp/mawi/samplepoint-F/2023/202302191400.html
tcpdump file: http://mawi.wide.ad.jp/mawi/samplepoint-F/2023/202302191400.pcap.gz

Anomalous Traffic:

"Anomalous" and "Suspicious" labels (admd file): 20230219_anomalous_suspicious.xml
"Anomalous" and "Suspicious" labels (csv file): 20230219_anomalous_suspicious.csv

Overview of the anomalies:

Number of anomalies: 354
Proportion of anomalies in terms of occurrence:


Breakdown of the anomalies:

TaxonomyHeuristicLabelDetectors
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
small_network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough, Gamma
network_scan_UDP_otherOthersuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
network_scan_ICMP_ecrqPing floodsuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
network_scan_ICMP_ecrqPing floodsuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
network_scan_ICMP_ecrqPing floodsuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Gamma, KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Gamma, KL
reflection_attack_DNSOthersuspicious Gamma, KL, PCA
distributed_denial_of_service_UDPOthersuspicious Hough, Gamma, PCA
network_scan_ICMP_ecrqPing floodsuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
network_scan_TCP_TCP_ICMP_responsePing floodsuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
network_scan_UDP_UDP_responseSSH trafficsuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
network_scan_TCP_TCP_ICMP_responsePing floodsuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Gamma, KL, PCA
network_scan_ICMP_ecrqPing floodanomalous Hough
small_network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
small_network_scan_SYNSYN attackanomalous Hough
small_network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough, Gamma, PCA
point_to_point_denial_of_service_SYNSYN attackanomalous Hough
network_scan_ICMP_ecrqPing floodanomalous Hough, PCA
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
small_network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_ICMP_ecrqPing floodanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Gamma, KL, PCA
point_to_point_denial_of_service_SYNSYN attackanomalous Hough, KL
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
point_to_point_port_scan_UDPOtheranomalous Hough, Gamma, KL, PCA
network_scan_SYNSYN attackanomalous Hough, Gamma, PCA
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_SYNSYN attackanomalous Gamma, KL, PCA
reflection_attack_UDPHTTPS trafficanomalous PCA
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_SYNSYN attackanomalous Gamma, KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous Gamma, KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous PCA
small_alpha_flowHTTPS trafficsuspicious Hough
point_to_multipoint_low_activityOthersuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
small_alpha_flowOthersuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
small_alpha_flowSSH trafficsuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
heavy_hitterHTTP trafficsuspicious Hough
point_to_multipointFIN attacksuspicious Hough
point_to_multipointOthersuspicious Hough
point_to_multipointOthersuspicious Hough
point_to_multipointOthersuspicious Hough
multipoint_to_pointOthersuspicious Hough
multipoint_to_pointRST attacksuspicious Hough
multipoint_to_pointOthersuspicious Hough
multipoint_to_pointRST attacksuspicious Hough
icmp_errorPing floodsuspicious Gamma
icmp_errorPing floodsuspicious Gamma
small_alpha_flowHTTPS trafficsuspicious Gamma
icmp_errorPing floodsuspicious Gamma
point_to_multipointSYN attacksuspicious Gamma
point_to_multipointSYN attacksuspicious Gamma
icmp_errorPing floodsuspicious Gamma
icmp_errorPing floodsuspicious Gamma
icmp_errorPing floodsuspicious Gamma
point_to_multipoint_low_activityHTTPS trafficsuspicious Gamma
small_alpha_flowHTTPS trafficsuspicious Gamma
multipoint_to_multipointSYN attacksuspicious Gamma, PCA
icmp_errorPing floodsuspicious Gamma
icmp_errorPing floodsuspicious Gamma
alpha_flowOthersuspicious Gamma
point_to_multipoint_low_activityHTTPS trafficsuspicious Gamma
point_to_multipoint_low_activityHTTPS trafficsuspicious Gamma
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
multipoint_to_pointPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
multipoint_to_multipointPing floodsuspicious Gamma, KL
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
multipoint_to_pointPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
point_to_multipointOthersuspicious PCA
icmp_errorPing floodsuspicious KL, PCA
multipoint_to_multipointSYN attacksuspicious Gamma, PCA
multipoint_to_pointOthersuspicious Gamma, KL, PCA
alpha_flowHTTPS trafficsuspicious PCA
point_to_multipointHTTPS trafficsuspicious PCA
point_to_multipointSYN attacksuspicious PCA
point_to_multipointSYN attacksuspicious PCA
point_to_multipointSYN attacksuspicious PCA
point_to_multipoint_low_activityHTTPS trafficsuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious Gamma, KL, PCA
point_to_multipointSYN attacksuspicious Gamma, PCA
alpha_flowHTTPS trafficsuspicious PCA
multipoint_to_point_low_activityOthersuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
alpha_flowSSH trafficsuspicious PCA
alpha_flowOthersuspicious PCA
alpha_flowOthersuspicious PCA
multipoint_to_point_low_activityHTTPS trafficsuspicious PCA
multipoint_to_multipointHTTPS trafficsuspicious Gamma, PCA
multipoint_to_point_low_activityHTTPS trafficsuspicious PCA
multipoint_to_multipointPing floodsuspicious Gamma, KL, PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious Gamma, KL, PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointPing floodsuspicious PCA
multipoint_to_point_HTTPHTTP trafficsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_point_HTTPOthersuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointPing floodsuspicious PCA
multipoint_to_pointPing floodsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious Gamma, PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_point_low_activityOthersuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious Gamma, PCA
multipoint_to_pointPing floodsuspicious PCA
multipoint_to_point_HTTPHTTP trafficsuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_point_low_activityOthersuspicious Gamma, PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointSSH trafficsuspicious Gamma, PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_point_HTTPOthersuspicious PCA
multipoint_to_point_HTTPOthersuspicious PCA
multipoint_to_point_HTTPOthersuspicious PCA
multipoint_to_point_HTTPOthersuspicious PCA
multipoint_to_point_HTTPOthersuspicious PCA
multipoint_to_point_HTTPOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_multipointSYN attacksuspicious Gamma, PCA
multipoint_to_point_HTTPOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_point_HTTPOthersuspicious PCA
multipoint_to_point_low_activityOthersuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointSSH trafficsuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointSSH trafficsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointSSH trafficsuspicious PCA
multipoint_to_pointSSH trafficsuspicious PCA
multipoint_to_pointOthersuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
small_alpha_flowHTTPS trafficsuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
multipoint_to_multipointHTTPS trafficsuspicious PCA
alpha_flowOthersuspicious PCA
alpha_flowHTTPS trafficanomalous Hough
point_to_multipointOtheranomalous Hough
point_to_multipointOtheranomalous Hough
point_to_multipointOtheranomalous Hough
point_to_multipointOtheranomalous Hough
point_to_multipointOtheranomalous Hough
point_to_multipointOtheranomalous Hough
point_to_multipoint_HTTPSYN attackanomalous Hough
point_to_multipointOtheranomalous Hough
point_to_multipointOtheranomalous Hough
point_to_multipointOtheranomalous Hough
point_to_multipointOtheranomalous Hough
point_to_multipointSYN attackanomalous Hough
point_to_multipointOtheranomalous Hough
multipoint_to_pointRST attackanomalous Hough
multipoint_to_pointRST attackanomalous Hough
multipoint_to_pointRST attackanomalous Hough
multipoint_to_pointRST attackanomalous Hough
multipoint_to_pointRST attackanomalous Hough
multipoint_to_pointRST attackanomalous Hough
multipoint_to_pointOtheranomalous Hough, Gamma, KL, PCA
point_to_multipointOtheranomalous Hough, Gamma, PCA
alpha_flow_HTTPHTTP trafficanomalous Gamma, PCA
multipoint_to_multipointHTTP trafficanomalous Hough, Gamma, PCA
icmp_errorPing floodanomalous Gamma
multipoint_to_pointHTTPS trafficanomalous Hough, KL, PCA
icmp_errorPing floodanomalous KL, PCA
icmp_errorPing floodanomalous KL, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, KL, PCA
icmp_errorPing floodanomalous Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
alpha_flowHTTPS trafficanomalous Gamma, PCA
multipoint_to_pointPing floodanomalous Hough, KL, PCA
point_to_multipointOtheranomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
alpha_flowHTTPS trafficanomalous Hough, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointHTTP trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointPing floodanomalous Gamma, KL, PCA
ipv4_gre_tunnelOtheranomalous Hough, Gamma, PCA
alpha_flow_HTTPHTTP trafficanomalous PCA
multipoint_to_multipointOtheranomalous Hough, PCA
alpha_flowHTTPS trafficanomalous PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
point_to_pointHTTPS trafficanomalous PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_point_low_activity_HTTPHTTP trafficanomalous Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
icmp_errorPing floodanomalous PCA
multipoint_to_pointHTTPS trafficanomalous PCA
icmp_errorPing floodanomalous PCA
multipoint_to_pointHTTPS trafficanomalous PCA
multipoint_to_multipointOtheranomalous Gamma, KL, PCA
multipoint_to_multipointOtheranomalous Hough, PCA
multipoint_to_point_low_activityOtheranomalous PCA
multipoint_to_point_low_activityHTTPS trafficanomalous PCA
multipoint_to_multipointSYN attackanomalous Hough, Gamma, PCA
multipoint_to_pointPing floodanomalous Gamma, KL, PCA
multipoint_to_pointOtheranomalous PCA
alpha_flowSSH trafficanomalous PCA
icmp_errorPing floodanomalous PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma, KL, PCA
emptyUnknownsuspicious Gamma, KL, PCA
emptyUnknownsuspicious Gamma, PCA
emptyUnknownsuspicious Gamma, PCA
emptyUnknownsuspicious Gamma, KL, PCA
emptyUnknownsuspicious Gamma, PCA
emptyUnknownanomalous Gamma, KL, PCA
emptyUnknownanomalous Gamma, KL, PCA
emptyUnknownanomalous Hough, Gamma, PCA
emptyUnknownanomalous Hough, Gamma, PCA
emptyUnknownanomalous Hough, Gamma, KL, PCA
TaxonomyHeuristicLabelDetectors

Other:

"Notice" labels (admd file): 20230219_notice.xml
"Notice" labels (csv file): 20230219_notice.csv