MAWILab

Data set: 2023/04/23






Traffic Trace: 2023/04/23

Info: http://mawi.wide.ad.jp/mawi/samplepoint-F/2023/202304231400.html
tcpdump file: http://mawi.wide.ad.jp/mawi/samplepoint-F/2023/202304231400.pcap.gz

Anomalous Traffic:

"Anomalous" and "Suspicious" labels (admd file): 20230423_anomalous_suspicious.xml
"Anomalous" and "Suspicious" labels (csv file): 20230423_anomalous_suspicious.csv

Overview of the anomalies:

Number of anomalies: 178
Proportion of anomalies in terms of occurrence:


Breakdown of the anomalies:

TaxonomyHeuristicLabelDetectors
small_network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_UDP_otherOtheranomalous Hough, KL
network_scan_UDP_otherOtheranomalous Hough, Gamma, PCA
network_scan_SYNSYN attackanomalous Hough, PCA
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
small_network_scan_SYNSYN attackanomalous Hough
small_network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough, PCA
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
small_network_scan_SYNSYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough
distributed_denial_of_service_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous KL
network_scan_ICMP_ecrq_ICMP_ecrp_du_rm_te_responsePing floodanomalous Gamma, KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous KL
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_SYNSYN attackanomalous Hough, PCA
network_scan_SYNSYN attackanomalous Hough, Gamma, PCA
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_SYNSYN attackanomalous Hough, Gamma, PCA
network_scan_UDP_UDP_responseOtheranomalous Hough, Gamma, KL, PCA
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
small_network_scan_SYNSYN attacksuspicious Hough, PCA
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
network_scan_UDP_DNSOthersuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
network_scan_UDP_DNSOthersuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
network_scan_UDP_UDP_responseOthersuspicious KL, PCA
small_network_scan_SYNSYN attacksuspicious Hough, Gamma, PCA
network_scan_ICMP_ecrqPing floodsuspicious PCA
network_scan_SYNSYN attacksuspicious Gamma, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Gamma, KL, PCA
ipv4_gre_tunnelOtheranomalous Hough, Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, PCA
small_alpha_flowHTTPS trafficanomalous Hough
multipoint_to_multipointSYN attackanomalous Hough, Gamma, KL, PCA
multipoint_to_point_low_activityHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_pointOtheranomalous Hough, Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
point_to_multipoint_low_activityHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTP trafficanomalous Hough, Gamma, PCA
point_to_multipointHTTPS trafficanomalous Hough, PCA
ipv4_gre_tunnelOtheranomalous Hough, Gamma, PCA
multipoint_to_pointOtheranomalous Hough, Gamma, KL, PCA
multipoint_to_multipointSSH trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, PCA
host_outagePing floodanomalous Hough, Gamma, KL, PCA
alpha_flowOtheranomalous Hough, PCA
icmp_errorPing floodanomalous Hough, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, PCA
point_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_pointOtheranomalous Hough, Gamma, PCA
heavy_hitterSSH attacksuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
heavy_hitterSSH attacksuspicious Hough
heavy_hitterSSH attacksuspicious Hough
heavy_hitterSSH attacksuspicious Hough
heavy_hitterSSH attacksuspicious Hough
small_alpha_flowSSH trafficsuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Gamma
point_to_multipointOthersuspicious Gamma
alpha_flowSSH trafficsuspicious Gamma
point_to_multipointSYN attacksuspicious Gamma
point_to_multipointPing floodsuspicious Gamma
point_to_multipointSYN attacksuspicious Gamma
icmp_errorPing floodsuspicious Gamma
icmp_errorPing floodsuspicious Gamma
point_to_multipointSYN attacksuspicious Gamma
icmp_errorPing floodsuspicious Gamma
alpha_flowOthersuspicious Gamma
alpha_flowHTTPS trafficsuspicious Gamma
point_to_multipointSYN attacksuspicious Gamma
multipoint_to_pointPing floodsuspicious Gamma
alpha_flowSSH trafficsuspicious Gamma
point_to_multipoint_HTTPRST attacksuspicious Gamma
icmp_errorPing floodsuspicious Gamma
icmp_errorPing floodsuspicious Gamma
point_to_multipointSYN attacksuspicious Gamma, PCA
multipoint_to_pointOthersuspicious Gamma
point_to_multipointOthersuspicious Gamma, KL, PCA
multipoint_to_pointOthersuspicious Gamma, KL
multipoint_to_pointHTTPS trafficsuspicious Hough, Gamma, PCA
alpha_flowOthersuspicious Hough, PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
multipoint_to_point_low_activityHTTPS trafficsuspicious PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
icmp_errorPing floodsuspicious KL, PCA
point_to_multipointOthersuspicious Hough, Gamma, PCA
multipoint_to_point_low_activityOthersuspicious KL, PCA
point_to_multipointHTTPS trafficsuspicious PCA
alpha_flow_HTTPHTTP trafficsuspicious PCA
multipoint_to_multipointOthersuspicious Gamma, KL, PCA
multipoint_to_multipointHTTP trafficsuspicious Hough, Gamma, PCA
alpha_flowHTTPS trafficsuspicious PCA
point_to_multipointHTTPS trafficsuspicious PCA
point_to_multipoint_HTTPSYN attacksuspicious Gamma, PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
alpha_flowSSH trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
icmp_errorPing floodsuspicious Gamma, PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_multipointHTTPS trafficsuspicious Gamma, PCA
multipoint_to_multipointHTTPS trafficsuspicious PCA
multipoint_to_pointPing floodsuspicious PCA
multipoint_to_pointRST attacksuspicious Gamma, PCA
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma, KL, PCA
emptyUnknownsuspicious Gamma, KL, PCA
emptyUnknownsuspicious Gamma, KL, PCA
emptyUnknownsuspicious Hough, Gamma, KL, PCA
TaxonomyHeuristicLabelDetectors

Other:

"Notice" labels (admd file): 20230423_notice.xml
"Notice" labels (csv file): 20230423_notice.csv