Cargando…

Dataset of intrusion detection alerts from a sharing platform

The dataset contains intrusion detection alerts obtained via an alert sharing platform (SABU) for one week. A plethora of heterogeneous intrusion detection systems deployed across several organizations contributed to the sharing platform. The alerts are stored in the intrusion Detection Extensible A...

Descripción completa

Detalles Bibliográficos
Autores principales: Husák, Martin, Žádník, Martin, Bartoš, Václav, Sokol, Pavol
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Elsevier 2020
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7701952/
https://www.ncbi.nlm.nih.gov/pubmed/33299907
http://dx.doi.org/10.1016/j.dib.2020.106530
_version_ 1783616517549588480
author Husák, Martin
Žádník, Martin
Bartoš, Václav
Sokol, Pavol
author_facet Husák, Martin
Žádník, Martin
Bartoš, Václav
Sokol, Pavol
author_sort Husák, Martin
collection PubMed
description The dataset contains intrusion detection alerts obtained via an alert sharing platform (SABU) for one week. A plethora of heterogeneous intrusion detection systems deployed across several organizations contributed to the sharing platform. The alerts are stored in the intrusion Detection Extensible Alert (IDEA) format and categorized using the eCSIRT.net Incident Taxonomy. Dataset can be used in several areas of cybersecurity research for the analysis of intrusion detection alerts including temporal and spatial correlations, reputation scoring, attack scenario reconstruction, and attack projection. The network identifiers (e.g., IP addresses, hostnames) are anonymized. However, the list of interesting features (e.g., presence on blacklists, geolocation) of such entities at the time of data collection is provided.
format Online
Article
Text
id pubmed-7701952
institution National Center for Biotechnology Information
language English
publishDate 2020
publisher Elsevier
record_format MEDLINE/PubMed
spelling pubmed-77019522020-12-08 Dataset of intrusion detection alerts from a sharing platform Husák, Martin Žádník, Martin Bartoš, Václav Sokol, Pavol Data Brief Data Article The dataset contains intrusion detection alerts obtained via an alert sharing platform (SABU) for one week. A plethora of heterogeneous intrusion detection systems deployed across several organizations contributed to the sharing platform. The alerts are stored in the intrusion Detection Extensible Alert (IDEA) format and categorized using the eCSIRT.net Incident Taxonomy. Dataset can be used in several areas of cybersecurity research for the analysis of intrusion detection alerts including temporal and spatial correlations, reputation scoring, attack scenario reconstruction, and attack projection. The network identifiers (e.g., IP addresses, hostnames) are anonymized. However, the list of interesting features (e.g., presence on blacklists, geolocation) of such entities at the time of data collection is provided. Elsevier 2020-11-17 /pmc/articles/PMC7701952/ /pubmed/33299907 http://dx.doi.org/10.1016/j.dib.2020.106530 Text en © 2020 The Authors http://creativecommons.org/licenses/by/4.0/ This is an open access article under the CC BY license (http://creativecommons.org/licenses/by/4.0/).
spellingShingle Data Article
Husák, Martin
Žádník, Martin
Bartoš, Václav
Sokol, Pavol
Dataset of intrusion detection alerts from a sharing platform
title Dataset of intrusion detection alerts from a sharing platform
title_full Dataset of intrusion detection alerts from a sharing platform
title_fullStr Dataset of intrusion detection alerts from a sharing platform
title_full_unstemmed Dataset of intrusion detection alerts from a sharing platform
title_short Dataset of intrusion detection alerts from a sharing platform
title_sort dataset of intrusion detection alerts from a sharing platform
topic Data Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7701952/
https://www.ncbi.nlm.nih.gov/pubmed/33299907
http://dx.doi.org/10.1016/j.dib.2020.106530
work_keys_str_mv AT husakmartin datasetofintrusiondetectionalertsfromasharingplatform
AT zadnikmartin datasetofintrusiondetectionalertsfromasharingplatform
AT bartosvaclav datasetofintrusiondetectionalertsfromasharingplatform
AT sokolpavol datasetofintrusiondetectionalertsfromasharingplatform