遇见数据集

Comprehensive, Multi-Source Cyber-Security Events Data Set

收藏
DataCite Commons2023-01-04 更新2024-07-13 收录
官方服务:

资源简介:

This data set represents 58 consecutive days of de-identified event data collected from five sources within Los Alamos National Laboratory’s corporate, internal computer network. The data sources include Windows-based authentication events from both individual computers and centralized Active Directory domain controller servers; process start and stop events from individual Windows computers; Domain Name Service (DNS) lookups as collected on internal DNS servers; network flow data as collected on at several key router locations; and a set of well-defined red teaming events that present bad behavior within the 58 days. In total, the data set is approximately 12 gigabytes compressed across the five data elements and presents 1,648,275,307 events in total for 12,425 users, 17,684 computers, and 62,974 processes. Specific users that are well known system related (SYSTEM, Local Service) were not de-identified though any well-known administrators account were still de-identified. In the network flow data, well-known ports (e.g. 80, 443, etc) were not de-identified. All other users, computers, process, ports, times, and other details were de-identified as a unified set across all the data elements (e.g. U1 is the same U1 in all of the data). The specific timeframe used is not disclosed for security purposes. In addition, no data that allows association outside of LANL’s network is included. All data starts with a time epoch of 1 using a time resolution of 1 second. In the authentication data, failed authentication events are only included for users that had a successful authentication event somewhere within the data set.

本数据集收录了来自洛斯阿拉莫斯国家实验室(Los Alamos National Laboratory)企业内部计算机网络的58天连续去标识化事件数据,数据来源共五类:其一为基于Windows的身份验证事件,涵盖单机与集中式活动目录(Active Directory)域控制器服务器产生的日志;其二为单机Windows系统的进程启停事件;其三为内部域名系统(Domain Name Service, DNS)服务器采集的DNS查询记录;其四为关键路由器节点采集的网络流数据;其五为覆盖该58天周期、表征恶意行为的标准化红队测试事件集。该数据集五类数据模块压缩后总容量约12吉字节,总计包含1648275307条事件,涉及12425名用户、17684台设备及62974个进程。其中,已知的系统相关用户(如SYSTEM、本地服务账户)未进行去标识化处理,但所有知名管理员账户仍完成去标识化;在网络流数据中,知名端口(如80、443等)未做去标识化处理;其余所有用户、设备、进程、端口、时间戳及其他细节均在全数据模块中完成统一去标识化(例如所有数据模块中的U1均指代同一实体)。出于安全考量,本数据集未披露具体时间范围,且未包含任何可关联至洛斯阿拉莫斯国家实验室网络之外的信息。所有数据的时间纪元起始值为1,时间分辨率为1秒。在身份验证数据模块中,仅收录那些在数据集内至少出现过一次成功身份验证事件的用户所对应的失败身份验证记录。

创建时间:
2015-05-28
搜集汇总
背景与挑战
背景概述
该数据集是一个全面的多源网络安全事件数据集,包含58天来自洛斯阿拉莫斯国家实验室内部网络的去标识化事件数据,涵盖认证、进程、DNS、网络流和红队事件五大来源,总计约12GB压缩数据、超过16亿个事件,涉及数万用户、计算机和进程。其特点在于数据来源多样、去标识化处理统一(但系统用户和知名端口除外),且专注于内部网络行为,适用于网络安全分析和研究。
以上内容由遇见数据集搜集并总结生成
二维码
社区交流群
二维码
科研交流群
商业服务