vix.ing · top · new · best · stats

A survey of network-based intrusion detection data sets

2019/03/31 by Markus Ring, Sarah Wunderlich, Deniz Scheuring +2 · 786 citations
Computer Science · #cs.CR

paper · pdf · doi:10.1016/j.cose.2019.06.005

published in Computers & Security 86, 147-167 (Elsevier BV) · submitted manuscript to Computer & Security

crossref created 2019/06/11 · arxiv created 2019/07/06 · arxiv updated 2019/07/09 · crossref issued 2019/09/01 · crossref published 2019/09/01 · crossref published-print 2019/09/01 · crossref deposited 2025/09/28 · crossref indexed 2026/08/05

Abstract

Labeled data sets are necessary to train and evaluate anomaly-based network intrusion detection systems. This work provides a focused literature survey of data sets for network-based intrusion detection and describes the underlying packet- and flow-based network data in detail. The paper identifies 15 different properties to assess the suitability of individual data sets for specific evaluation scenarios. These properties cover a wide range of criteria and are grouped into five categories such as data volume or recording environment for offering a structured search. Based on these properties, a comprehensive overview of existing data sets is given. This overview also highlights the peculiarities of each data set. Furthermore, this work briefly touches upon other sources for network-based data such as traffic generators and traffic repositories. Finally, we discuss our observations and provide some recommendations for the use and creation of network-based data sets.

Cited by