MAWILab

Data set: 2023/05/27






Traffic Trace: 2023/05/27

Info: http://mawi.wide.ad.jp/mawi/samplepoint-F/2023/202305271400.html
tcpdump file: http://mawi.wide.ad.jp/mawi/samplepoint-F/2023/202305271400.pcap.gz

Anomalous Traffic:

"Anomalous" and "Suspicious" labels (admd file): 20230527_anomalous_suspicious.xml
"Anomalous" and "Suspicious" labels (csv file): 20230527_anomalous_suspicious.csv

Overview of the anomalies:

Number of anomalies: 267
Proportion of anomalies in terms of occurrence:


Breakdown of the anomalies:

TaxonomyHeuristicLabelDetectors
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_ICMP_ecrqPing floodanomalous Hough
distributed_denial_of_service_SYNSYN attackanomalous Hough, KL
distributed_denial_of_service_SYNSYN attackanomalous Hough, KL, PCA
network_scan_ICMP_ecrqPing floodanomalous Hough
network_scan_ICMP_ecrqPing floodanomalous Hough, PCA
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough, KL, PCA
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough, PCA
small_network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough, KL
network_scan_SYNSYN attackanomalous Hough
network_scan_SYN_139_445SYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough, Gamma
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_SYNSYN attackanomalous Hough
network_scan_UDP_otherOtheranomalous Hough
small_network_scan_SYNSYN attackanomalous Gamma
small_network_scan_SYNSYN attackanomalous Gamma
network_scan_SYNSYN attackanomalous Gamma
network_scan_SYNSYN attackanomalous Hough, KL, PCA
network_scan_SYNSYN attackanomalous Hough, PCA
network_scan_UDP_UDP_responseOtheranomalous Hough, Gamma, KL
distributed_denial_of_service_SYNSYN attackanomalous Hough, KL, PCA
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_SYNSYN attackanomalous Hough, Gamma, PCA
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
network_scan_SYNSYN attackanomalous Gamma, KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous Gamma, KL, PCA
network_scan_ICMP_ecrqPing floodanomalous PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous Gamma, KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous PCA
network_scan_UDP_UDP_responseOtheranomalous Hough, Gamma, PCA
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_ICMP_ecrqPing floodsuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Gamma, KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Hough, Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Gamma
small_network_scan_SYNSYN attacksuspicious Gamma
port_scan_SYNSYN attacksuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_SYNSYN attacksuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_SYNSYN attacksuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_SYNSYN attacksuspicious KL
network_scan_SYNSYN attacksuspicious KL
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_du_rm_te_responsePing floodsuspicious Hough, Gamma, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL, PCA
small_network_scan_SYNSYN attacksuspicious PCA
reflection_attack_UDPHTTPS trafficsuspicious PCA
network_scan_SYNSYN attacksuspicious Gamma, PCA
network_scan_SYNSYN attacksuspicious PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, PCA
alpha_flowHTTPS trafficanomalous Hough
alpha_flowHTTPS trafficanomalous Hough
alpha_flowHTTPS trafficanomalous Hough
alpha_flowHTTPS trafficanomalous Hough
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, PCA
ipv4_gre_tunnelOtheranomalous Hough, Gamma, PCA
point_to_multipoint_low_activityOtheranomalous Hough, KL, PCA
point_to_multipointFIN attackanomalous Hough
point_to_multipointSYN attackanomalous Hough
point_to_multipointSYN attackanomalous Hough
multipoint_to_pointSYN attackanomalous Hough
multipoint_to_pointRST attackanomalous Hough
multipoint_to_pointOtheranomalous Hough, Gamma, PCA
multipoint_to_pointOtheranomalous Hough, Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
point_to_multipointSYN attackanomalous Gamma
multipoint_to_pointHTTPS trafficanomalous Gamma
icmp_errorPing floodanomalous Gamma
icmp_errorPing floodanomalous Gamma
icmp_errorPing floodanomalous Gamma
small_alpha_flowHTTPS trafficanomalous Gamma
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
point_to_multipoint_HTTPSYN attackanomalous Hough, Gamma, PCA
multipoint_to_multipointSYN attackanomalous Hough, Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
ipv4_gre_tunnelOtheranomalous Hough, Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointSYN attackanomalous Hough, Gamma, PCA
multipoint_to_point_HTTPHTTP trafficanomalous PCA
multipoint_to_pointOtheranomalous Gamma, PCA
point_to_multipointOtheranomalous Hough, Gamma, PCA
point_to_multipointOtheranomalous Hough, PCA
multipoint_to_multipointHTTPS trafficanomalous Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous PCA
alpha_flowHTTPS trafficanomalous PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
point_to_multipointOtheranomalous Gamma, PCA
alpha_flowOtheranomalous PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous PCA
multipoint_to_pointHTTPS trafficanomalous PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous Gamma, PCA
multipoint_to_multipointHTTP trafficanomalous Gamma, PCA
multipoint_to_pointHTTPS trafficanomalous PCA
point_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointSYN attackanomalous Gamma, PCA
point_to_multipointOtheranomalous Hough, Gamma, KL, PCA
alpha_flowHTTPS trafficsuspicious Hough
alpha_flowOthersuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
alpha_flowOthersuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
alpha_flowOthersuspicious Hough
alpha_flowOthersuspicious Hough
alpha_flowOthersuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
alpha_flowOthersuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
alpha_flowOthersuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
alpha_flowOthersuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
micro_alpha_flowHTTPS trafficsuspicious Hough
alpha_flowOthersuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
micro_alpha_flowHTTPS trafficsuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
small_alpha_flowHTTPS trafficsuspicious Hough
alpha_flow_HTTPHTTP trafficsuspicious Hough
alpha_flowHTTPS trafficsuspicious Hough
multipoint_to_pointHTTPS trafficsuspicious Hough
multipoint_to_point_low_activityOthersuspicious Hough
point_to_multipointSYN attacksuspicious Hough
multipoint_to_pointSSH attacksuspicious Hough
point_to_pointOthersuspicious Hough, Gamma
multipoint_to_point_low_activityOthersuspicious Gamma
multipoint_to_point_HTTPPing floodsuspicious Gamma
multipoint_to_pointOthersuspicious Gamma
multipoint_to_pointPing floodsuspicious Gamma
small_alpha_flowSSH trafficsuspicious Gamma
micro_alpha_flowHTTPS trafficsuspicious Gamma
multipoint_to_pointPing floodsuspicious Gamma
multipoint_to_point_HTTPHTTP trafficsuspicious Gamma
point_to_multipoint_low_activitySYN attacksuspicious Gamma
icmp_errorPing floodsuspicious Gamma
multipoint_to_pointOthersuspicious Gamma
multipoint_to_pointSYN attacksuspicious Gamma
point_to_multipointSYN attacksuspicious Gamma
small_alpha_flowOthersuspicious KL
point_to_multipointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious Gamma, PCA
multipoint_to_pointHTTPS trafficsuspicious Hough, PCA
point_to_multipoint_HTTPHTTP trafficsuspicious PCA
point_to_multipoint_low_activityHTTPS trafficsuspicious PCA
point_to_multipoint_low_activity_HTTPHTTP trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
point_to_multipoint_HTTPHTTP trafficsuspicious PCA
small_alpha_flowHTTPS trafficsuspicious PCA
point_to_pointSYN attacksuspicious PCA
multipoint_to_multipointHTTP trafficsuspicious Gamma, PCA
point_to_multipointOthersuspicious Gamma, PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
icmp_errorPing floodsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_point_HTTPHTTP trafficsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
icmp_errorPing floodsuspicious PCA
small_alpha_flowHTTPS trafficsuspicious PCA
multipoint_to_multipointOthersuspicious Gamma, PCA
multipoint_to_pointOthersuspicious PCA
point_to_multipointSYN attacksuspicious Gamma, PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_pointSMB attacksuspicious PCA
multipoint_to_point_low_activityOthersuspicious PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_point_low_activityHTTPS trafficsuspicious PCA
heavy_hitterHTTPS trafficsuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
emptyUnknownanomalous Hough, Gamma, KL, PCA
emptyUnknownanomalous Gamma
emptyUnknownanomalous Gamma
emptyUnknownanomalous Gamma, KL, PCA
emptyUnknownanomalous Gamma, PCA
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Hough
emptyUnknownsuspicious Gamma, KL
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
TaxonomyHeuristicLabelDetectors

Other:

"Notice" labels (admd file): 20230527_notice.xml
"Notice" labels (csv file): 20230527_notice.csv