Skip to main navigation Skip to search Skip to main content

The Westermo network traffic data set

  • Per Erik Strandberg
  • , David Soderman
  • , Alireza Dehlaghi-Ghadim
  • , Miguel Leon
  • , Tijana Markovic
  • , Sasikumar Punnekkat
  • , Mahshid Helali Moghadam
  • , David Buffoni

Research output: Contribution to journalArticlepeer-review

87 Downloads (Pure)

Abstract

There is a growing body of knowledge on network intrusion detection, and several open data sets with network traffic and cyber-security threats have been released in the past decades. However, many data sets have aged, were not collected in a contemporary industrial communication system, or do not easily support research focusing on distributed anomaly detection. This paper presents the Westermo network traffic data set, 1.8 million network packets recorded in over 90 minutes in a network built up of twelve hardware devices. In addition to the raw data in PCAP format, the data set also contains pre-processed data in the form of network flows in CSV files. This data set can support the research community for topics such as intrusion detection, anomaly detection, misconfiguration detection, distributed or federated artificial intelligence, and attack classification. In particular, we aim to use the data set to continue work on resource-constrained distributed artificial intelligence in edge devices. The data set contains six types of events: harmless SSH, bad SSH, misconfigured IP address, duplicated IP address, port scan, and man in the middle attack.
Original languageEnglish
Article number109512
Number of pages10
JournalData In Brief
Volume50
Early online date1 Sept 2023
DOIs
Publication statusPublished - 1 Oct 2023

Keywords

  • Cyber-physical systems
  • Distributed artificial intelligence
  • Industrial communication system
  • Network intrusion detection

Fingerprint

Dive into the research topics of 'The Westermo network traffic data set'. Together they form a unique fingerprint.

Cite this