MAWILab

Data set: 2023/04/08






Traffic Trace: 2023/04/08

Info: http://mawi.wide.ad.jp/mawi/samplepoint-F/2023/202304081400.html
tcpdump file: http://mawi.wide.ad.jp/mawi/samplepoint-F/2023/202304081400.pcap.gz

Anomalous Traffic:

"Anomalous" and "Suspicious" labels (admd file): 20230408_anomalous_suspicious.xml
"Anomalous" and "Suspicious" labels (csv file): 20230408_anomalous_suspicious.csv

Overview of the anomalies:

Number of anomalies: 107
Proportion of anomalies in terms of occurrence:


Breakdown of the anomalies:

TaxonomyHeuristicLabelDetectors
point_to_point_denial_of_service_SYNSYN attacksuspicious Hough
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough, Gamma
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_TCP_TCP_ICMP_responsePing floodsuspicious Gamma, KL, PCA
network_scan_SYNSYN attacksuspicious Gamma, KL, PCA
network_scan_SYNSYN attacksuspicious Hough, Gamma, PCA
small_network_scan_SYNSYN attackanomalous Hough
small_network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
small_network_scan_SYNSYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
small_network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough, Gamma
network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough
small_network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough, Gamma
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough, Gamma, PCA
network_scan_UDP_otherOtheranomalous Hough, Gamma
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
point_to_point_denial_of_service_SYNSYN attackanomalous KL
network_scan_SYNSYN attackanomalous Hough, PCA
network_scan_SYNSYN attackanomalous Hough, Gamma, PCA
small_network_scan_SYNSYN attackanomalous Gamma, PCA
alpha_flowOthersuspicious Hough, Gamma
alpha_flowOthersuspicious Hough
point_to_multipointOthersuspicious Hough, Gamma, PCA
icmp_errorPing floodsuspicious Gamma, KL
point_to_multipointHTTPS trafficsuspicious Hough, PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_point_HTTPHTTP trafficsuspicious Hough, PCA
multipoint_to_point_HTTPHTTP trafficsuspicious Hough, PCA
micro_alpha_flowHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious Gamma, PCA
alpha_flowHTTPS trafficsuspicious Hough, PCA
heavy_hitterHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious KL, PCA
multipoint_to_point_HTTPHTTP trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
point_to_multipointHTTPS trafficsuspicious PCA
alpha_flowOtheranomalous Hough, KL, PCA
multipoint_to_multipointSYN attackanomalous Hough, Gamma, KL, PCA
point_to_multipointSYN attackanomalous Hough
multipoint_to_pointRST attackanomalous Hough
multipoint_to_pointOtheranomalous Hough, Gamma, KL, PCA
ipv4_gre_tunnelOtheranomalous Hough, Gamma, PCA
multipoint_to_multipointSYN attackanomalous Hough, Gamma, PCA
point_to_pointRST attackanomalous KL
multipoint_to_multipointSYN attackanomalous Hough, Gamma, KL, PCA
point_to_multipointHTTPS trafficanomalous Hough, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointSYN attackanomalous Hough, Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointOtheranomalous Hough, Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
point_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, PCA
multipoint_to_pointOtheranomalous Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTP trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointHTTP trafficanomalous Hough, Gamma, PCA
emptyUnknownsuspicious Hough, Gamma, KL
emptyUnknownsuspicious Gamma, KL, PCA
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma, PCA
emptyUnknownsuspicious Gamma, KL, PCA
emptyUnknownsuspicious Gamma, KL, PCA
emptyUnknownanomalous Hough, Gamma, KL, PCA
emptyUnknownanomalous Hough, Gamma, KL, PCA
emptyUnknownanomalous Hough, Gamma, PCA
emptyUnknownanomalous Hough, Gamma, KL, PCA
emptyUnknownanomalous Hough, Gamma, KL, PCA
TaxonomyHeuristicLabelDetectors

Other:

"Notice" labels (admd file): 20230408_notice.xml
"Notice" labels (csv file): 20230408_notice.csv