10.23721/100/17307
External Data Source
Aktaion Dataset
IMPACT
2018
en
aktaion, aktaion dataset, dataset, 1247, inferlink corporation, inferlink, source, external data source, corporation, external, format, arff, traffic, detection, train, labeled, original, ids, purpose, ransomware, network, behaviors, pcap, project, behavior, malware, expressive, multiple, machine, microbehaviors, statistics, lightweight, exploits, security, adverse, family, feature, parallel, attack, programmatic, micro, mechanism, derived, key, evolving, conversion, meant, intrusion, framework, prototype, limited, abstraction, based, extraction, analysis, contagiodump, raw, restrictions, iocs, timing, notably, level, steps, add, bro, net, java, building, rules, simple, collected, shared, learning, description, concept, sequential, idea, blend, sources, other, virtual, teaching, helps, blogspot, detecting, provide, signals, license, relevant, tool
17307
1247
This collection contains labeled network traffic data in ARFF format. The original purpose was to train ransomware detection in the Aktaion IDS.
Data was collected from multiple sources, most notably contagiodump.blogspot.com and malware-traffic-analysis.net as PCAP data. Due to license restrictions, the shared data is limited to the example data, which is in ARFF format, and derived from the raw PCAP data in two steps: PCAP to Bro format conversion, and then feature extraction (microbehaviors) to ARFF (using Aktaion).
Aktaion is a lightweight Java virtual machine based project for detecting exploits (and more generally attack behaviors). The project is meant to be a learning/teaching tool on how to blend multiple security signals and behaviors into an expressive framework for intrusion detection. The key abstraction we wanted to prototype is the idea of a micro behavior. This concept helps to provide an expressive mechanism to add high level IOCs such as timing behavior of a certain malware family in parallel to simple statistics, rules or anything relevant to building a programmatic description of a sequential evolving set of adverse behaviors.