MAWILab

Data set: 2023/03/18






Traffic Trace: 2023/03/18

Info: http://mawi.wide.ad.jp/mawi/samplepoint-F/2023/202303181400.html
tcpdump file: http://mawi.wide.ad.jp/mawi/samplepoint-F/2023/202303181400.pcap.gz

Anomalous Traffic:

"Anomalous" and "Suspicious" labels (admd file): 20230318_anomalous_suspicious.xml
"Anomalous" and "Suspicious" labels (csv file): 20230318_anomalous_suspicious.csv

Overview of the anomalies:

Number of anomalies: 228
Proportion of anomalies in terms of occurrence:


Breakdown of the anomalies:

TaxonomyHeuristicLabelDetectors
network_scan_SYNSYN attackanomalous Hough, KL, PCA
network_scan_ICMP_ecrqPing floodanomalous Hough, PCA
network_scan_SYNSYN attackanomalous Hough, Gamma
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
distributed_network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_UDP_UDP_responseOtheranomalous Hough, Gamma, KL, PCA
network_scan_ACKHTTP trafficanomalous Hough, Gamma, KL, PCA
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
small_network_scan_SYNSYN attacksuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
small_network_scan_SYNSYN attacksuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough, PCA
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
small_network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Gamma, KL
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_point_to_point_denial_of_service_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
point_to_point_port_scan_UDPOthersuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
network_scan_ICMP_ecrqPing floodsuspicious Gamma
network_scan_UDP_otherOthersuspicious Gamma
network_scan_UDP_otherOthersuspicious Gamma
network_scan_TCP_RST_ACK_responseRST attacksuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_SYNSYN attacksuspicious KL
network_scan_SYNSYN attacksuspicious KL
port_scan_SYNSYN attacksuspicious KL, PCA
network_scan_SYNSYN attacksuspicious Hough
network_scan_TCP_RST_ACK_responseRST attacksuspicious Gamma, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
network_scan_UDP_UDP_responseOthersuspicious Gamma, PCA
point_to_point_denial_of_service_SYNSYN attacksuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
ipv4_gre_tunnelOtheranomalous Hough, Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_pointOtheranomalous Hough, Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointOtheranomalous Hough, Gamma, PCA
point_to_multipointOtheranomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_pointRST attackanomalous Hough, Gamma, PCA
point_to_multipointSYN attackanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
point_to_multipointSYN attackanomalous Hough, Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
multipoint_to_pointOtheranomalous Hough, Gamma, PCA
point_to_multipointSYN attacksuspicious Hough
point_to_multipointOthersuspicious Hough, PCA
alpha_flowOthersuspicious Hough, PCA
alpha_flowOthersuspicious Hough
point_to_multipointOthersuspicious Hough
point_to_multipointOthersuspicious Hough
point_to_multipointFIN attacksuspicious Hough
point_to_multipointOthersuspicious Hough
point_to_multipointOthersuspicious Hough
multipoint_to_multipointOthersuspicious Hough, PCA
point_to_multipointOthersuspicious Hough
point_to_multipointOthersuspicious Hough, PCA
point_to_multipointOthersuspicious Hough
point_to_multipointOthersuspicious Hough
point_to_multipointOthersuspicious Hough
point_to_multipointOthersuspicious Hough
point_to_multipointOthersuspicious Hough
point_to_multipointOthersuspicious Hough
point_to_multipointOthersuspicious Hough
multipoint_to_pointRST attacksuspicious Hough
multipoint_to_pointRST attacksuspicious Hough
multipoint_to_pointRST attacksuspicious Hough
multipoint_to_pointRST attacksuspicious Hough
multipoint_to_pointRST attacksuspicious Hough
multipoint_to_pointRST attacksuspicious Hough
multipoint_to_pointRST attacksuspicious Hough
point_to_multipoint_low_activitySMB attacksuspicious Gamma, PCA
point_to_multipointPing floodsuspicious Gamma
icmp_errorPing floodsuspicious Gamma, PCA
icmp_errorPing floodsuspicious Gamma, PCA
point_to_multipointSSH trafficsuspicious Gamma
point_to_multipointSYN attacksuspicious Gamma
point_to_multipointSYN attacksuspicious Gamma
point_to_multipointSYN attacksuspicious Gamma
small_alpha_flowSSH trafficsuspicious Gamma
small_alpha_flowSSH trafficsuspicious Gamma
small_alpha_flowHTTPS trafficsuspicious Gamma, PCA
point_to_multipoint_low_activity_HTTPHTTP trafficsuspicious Gamma
point_to_multipointSSH trafficsuspicious Gamma
icmp_errorPing floodsuspicious Gamma
point_to_multipointSYN attacksuspicious Gamma
point_to_multipointOthersuspicious Gamma
icmp_errorPing floodsuspicious Gamma
multipoint_to_pointPing floodsuspicious Gamma
icmp_errorPing floodsuspicious Gamma
small_alpha_flowSSH trafficsuspicious Gamma
point_to_multipoint_low_activityOthersuspicious Gamma
multipoint_to_pointSYN attacksuspicious KL
point_to_multipointSYN attacksuspicious KL
multipoint_to_point_low_activityOthersuspicious KL
point_to_multipointOthersuspicious KL, PCA
multipoint_to_pointOthersuspicious Gamma, PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
icmp_errorPing floodsuspicious PCA
point_to_multipointHTTPS trafficsuspicious PCA
point_to_multipoint_low_activityHTTPS trafficsuspicious PCA
point_to_multipoint_low_activityHTTPS trafficsuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
multipoint_to_multipointHTTP trafficsuspicious PCA
point_to_multipointHTTPS trafficsuspicious Hough, PCA
alpha_flowHTTPS trafficsuspicious PCA
point_to_multipointHTTPS trafficsuspicious Gamma, PCA
multipoint_to_multipointOthersuspicious Gamma, PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious Gamma, PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_multipointHTTPS trafficsuspicious Hough, Gamma, PCA
multipoint_to_multipointPing floodsuspicious Gamma, PCA
multipoint_to_pointHTTPS trafficsuspicious Hough, Gamma, PCA
point_to_multipointHTTPS trafficsuspicious PCA
multipoint_to_multipointHTTPS trafficsuspicious Gamma, PCA
icmp_errorPing floodsuspicious PCA
alpha_flowOthersuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_multipointHTTPS trafficsuspicious Gamma, PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_multipointHTTPS trafficsuspicious Gamma, PCA
icmp_errorPing floodsuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
multipoint_to_point_low_activityHTTPS attacksuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious Hough, PCA
icmp_errorPing floodsuspicious Gamma, PCA
multipoint_to_pointOthersuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointSSH trafficsuspicious PCA
multipoint_to_multipointSSH trafficsuspicious Gamma, PCA
point_to_multipointHTTPS trafficsuspicious Hough, Gamma, PCA
multipoint_to_pointHTTPS trafficsuspicious Gamma, PCA
point_to_multipoint_HTTPHTTP trafficsuspicious PCA
small_alpha_flowOthersuspicious PCA
emptyUnknownanomalous Gamma
emptyUnknownanomalous Gamma
emptyUnknownanomalous Hough, Gamma, PCA
emptyUnknownanomalous Gamma, KL, PCA
emptyUnknownanomalous Hough, Gamma, KL, PCA
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma, PCA
emptyUnknownsuspicious Gamma, PCA
emptyUnknownsuspicious Hough, Gamma, PCA
TaxonomyHeuristicLabelDetectors

Other:

"Notice" labels (admd file): 20230318_notice.xml
"Notice" labels (csv file): 20230318_notice.csv