Download: files Zip File
| Number of Instances: | 209237 | Security Area: | Files |
|---|---|---|---|
| Number of Attributes: | 23 | Date Donated: | 2012 |
| Missing Values? | - | Associated ML Tasks: | Network Analysis |
Mike Sconzo
Security Repository
Secrepo.com
An interface for driving the analysis of files, possibly independent of any network protocol over which they’re transported.
| Data Type | Count | Unique Values | Missing Values | |
|---|---|---|---|---|
| ts | float64 | 209237 | 209191 | 0 |
| fuid | object | 209237 | 209232 | 0 |
| tx_hosts | object | 209237 | 15315 | 0 |
| rx_hosts | object | 209237 | 788 | 0 |
| conn_uids | object | 209237 | 87997 | 0 |
| source | object | 209237 | 1 | 0 |
| depth | int64 | 209237 | 1 | 0 |
| analyzers | object | 209237 | 3 | 0 |
| mime_type | object | 209228 | 39 | 9 |
| filename | object | 10756 | 6832 | 198481 |
| duration | float64 | 209237 | 52782 | 0 |
| local_orig | float64 | 0 | 0 | 209237 |
| is_orig | object | 209237 | 2 | 0 |
| seen_bytes | int64 | 209237 | 39262 | 0 |
| total_bytes | float64 | 151095 | 32104 | 58142 |
| missing_bytes | int64 | 209237 | 81 | 0 |
| overflow_bytes | int64 | 209237 | 1 | 0 |
| timedout | object | 209237 | 2 | 0 |
| parent_fuid | float64 | 0 | 0 | 209237 |
| md5 | object | 209089 | 125089 | 148 |
| sha1 | object | 209089 | 125089 | 148 |
| sha256 | float64 | 0 | 0 | 209237 |
| extracted | float64 | 0 | 0 | 209237 |
Bro Logs http://gauss.ececs.uc.edu/Courses/c6055/pdf/bro_log_vars.pdf
Neise, Patrick. "Intrusion Detection Through Relationship Analysis". Oct 2016 https://www.sans.org/reading-room/whitepapers/detection/intrusion-detection-relationship-analysis-37352
Frances Bernadette C. De Ocampo, Trisha Mari L. Del Castillo, Miguel Alberto N. Gomez. "AUTOMATED SIGNATURE CREATOR FOR A SIGNATURE BASED INTRUSION DETECTION SYSTEM WITH NETWORK ATTACK DETECTION CAPABILITIES". 2013 http://sdiwc.net/digital-library/automated-signature-creator-for-a-signature-based-intrusion-detection-system-with-network-attack-detection-capabilities-pancakes.html