MAWILab

Data set: 2023/05/28






Traffic Trace: 2023/05/28

Info: http://mawi.wide.ad.jp/mawi/samplepoint-F/2023/202305281400.html
tcpdump file: http://mawi.wide.ad.jp/mawi/samplepoint-F/2023/202305281400.pcap.gz

Anomalous Traffic:

"Anomalous" and "Suspicious" labels (admd file): 20230528_anomalous_suspicious.xml
"Anomalous" and "Suspicious" labels (csv file): 20230528_anomalous_suspicious.csv

Overview of the anomalies:

Number of anomalies: 140
Proportion of anomalies in terms of occurrence:


Breakdown of the anomalies:

TaxonomyHeuristicLabelDetectors
small_network_scan_SYNSYN attacksuspicious Hough
small_network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
small_network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
small_network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
small_network_scan_SYNSYN attacksuspicious Hough
small_network_scan_SYNSYN attacksuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYN_139_445SYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_SYNSYN attacksuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_UDP_otherOthersuspicious Hough
network_scan_UDP_UDP_responseOthersuspicious Gamma, KL
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_UDP_UDP_ICMP_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_UDP_UDP_responseOthersuspicious Gamma, KL, PCA
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_TCP_TCP_ICMP_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_du_rm_te_responsePing floodsuspicious KL, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_UDP_UDP_responseOthersuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious KL
network_scan_SYNSYN attacksuspicious Hough, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodsuspicious PCA
network_scan_UDP_otherOtheranomalous Hough, PCA
network_scan_SYNSYN attackanomalous Hough, KL
network_scan_SYNSYN attackanomalous Hough, PCA
network_scan_UDP_otherOtheranomalous Hough, Gamma
network_scan_SYNSYN attackanomalous Hough, Gamma, PCA
network_scan_SYNSYN attackanomalous Hough, Gamma, PCA
network_scan_ICMP_ecrq_ICMP_ecrp_responsePing floodanomalous Gamma
network_scan_ICMP_ecrqPing floodanomalous Gamma
network_scan_UDP_UDP_responseOtheranomalous Gamma, KL, PCA
network_scan_UDP_otherOtheranomalous Hough, Gamma, KL, PCA
network_scan_UDP_UDP_responseOtheranomalous Gamma, KL, PCA
network_scan_SYNSYN attackanomalous Hough, Gamma, KL, PCA
alpha_flowHTTPS trafficsuspicious Hough
point_to_multipointHTTPS trafficsuspicious Hough, PCA
alpha_flow_HTTPHTTP trafficsuspicious Hough
heavy_hitterOthersuspicious Hough
point_to_multipointSYN attacksuspicious Hough
heavy_hitterOthersuspicious Hough
point_to_multipointSYN attacksuspicious Hough, PCA
point_to_multipointSYN attacksuspicious Hough
point_to_multipointOthersuspicious Hough
multipoint_to_pointRST attacksuspicious Hough
multipoint_to_pointOthersuspicious Hough, Gamma, KL, PCA
alpha_flowOthersuspicious Hough, Gamma
point_to_multipointOthersuspicious Hough, Gamma, PCA
multipoint_to_pointPing floodsuspicious Gamma
multipoint_to_point_low_activitySSH trafficsuspicious Gamma
point_to_multipoint_low_activitySYN attacksuspicious Gamma
icmp_errorPing floodsuspicious Gamma
icmp_errorPing floodsuspicious KL, PCA
heavy_hitterHTTPS trafficsuspicious KL
multipoint_to_point_low_activityOthersuspicious KL
multipoint_to_pointHTTPS trafficsuspicious Hough, PCA
alpha_flowOthersuspicious Hough, PCA
multipoint_to_multipointOthersuspicious Hough, KL, PCA
icmp_errorPing floodsuspicious KL, PCA
multipoint_to_multipointOthersuspicious Hough, Gamma, KL, PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious Gamma, PCA
point_to_multipointSYN attacksuspicious PCA
alpha_flowHTTPS trafficsuspicious PCA
ttl_errorPing floodsuspicious Gamma, PCA
multipoint_to_multipointHTTPS trafficsuspicious Hough, PCA
alpha_flowOthersuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_multipointHTTPS trafficsuspicious PCA
point_to_multipointHTTPS trafficsuspicious PCA
multipoint_to_multipointHTTP trafficsuspicious Hough, Gamma, PCA
multipoint_to_pointOthersuspicious PCA
multipoint_to_multipointHTTPS trafficsuspicious PCA
multipoint_to_pointHTTPS trafficsuspicious Gamma, KL, PCA
multipoint_to_multipointOthersuspicious Hough, PCA
multipoint_to_pointHTTPS trafficsuspicious PCA
multipoint_to_multipointHTTPS trafficsuspicious PCA
multipoint_to_multipointHTTPS trafficsuspicious Gamma, PCA
multipoint_to_multipointOthersuspicious Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficsuspicious Hough, PCA
multipoint_to_point_low_activityHTTPS trafficsuspicious PCA
multipoint_to_multipointSYN attackanomalous Hough, Gamma, KL, PCA
ipv4_gre_tunnelOtheranomalous Hough, Gamma, PCA
point_to_multipointSYN attackanomalous Hough, Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, KL, PCA
point_to_multipointHTTPS trafficanomalous Hough, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, PCA
multipoint_to_multipointHTTP trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_multipointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, KL, PCA
multipoint_to_pointRST attackanomalous Gamma, KL, PCA
multipoint_to_pointHTTPS trafficanomalous Hough, Gamma, PCA
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma
emptyUnknownsuspicious Gamma, KL, PCA
emptyUnknownsuspicious Gamma, KL, PCA
emptyUnknownsuspicious KL, PCA
emptyUnknownanomalous Hough, Gamma, KL, PCA
emptyUnknownanomalous Gamma, KL, PCA
emptyUnknownanomalous Hough, Gamma, KL, PCA
emptyUnknownanomalous Hough, Gamma, KL, PCA
TaxonomyHeuristicLabelDetectors

Other:

"Notice" labels (admd file): 20230528_notice.xml
"Notice" labels (csv file): 20230528_notice.csv