Aller au contenu principal
Accès ouvert déclaré 2026 dataset

Controlled Synthetic Network Traffic Dataset for Intrusion Detection Research: An 80,000-Flow Four-Class Dataset

0Citations signalées — pas une note de qualité
1Institutions déclarées
1Pays d’affiliation déclarés

Résumé fourni par la source

This repository provides a controlled synthetic network traffic dataset developed for flow-based intrusion detection research. The dataset contains 80,000 flow records distributed equally across four traffic classes: Normal, Denial-of-Service (DoS), Man-in-the-Middle (MitM), and Scan, with 20,000 flows per class. Traffic was generated using class-specific packet-level behavioral mechanisms and subsequently transformed into flow-level records. The released dataset contains flow attributes including source and destination addresses, source and destination ports, flow timestamps, duration, packet count, byte count, and class label. The dataset was subjected to integrity verification, class-wise statistical characterization, cross-class behavioral analysis, and Wasserstein-distance analysis. A Random Forest classifier using flow duration, packet count, and byte count was additionally employed as a diagnostic evaluation of internal behavioral separability. A group-aware partitioning strategy was used for MitM traffic to ensure that paired directional flows originating from the same interaction remained within the same training or testing partition. The repository includes the final four-class dataset together with class-specific flow data, statistical validation outputs, Wasserstein-distance results, and diagnostic classification results. The dataset is intended as a controlled experimental resource for studying relationships between packet-level traffic-generation behavior and resulting flow-level characteristics. Diagnostic classification results should be interpreted as evidence of internal dataset separability and not as an estimate of intrusion-detection performance in independent operational networks. The dataset was generated in a controlled synthetic environment and is intentionally balanced. It does not reproduce the full protocol diversity, topology, background traffic, class prevalence, or variability of operational networks.

Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.

Contrôle bibliographique ouvert

La source scientifique ouverte est momentanément indisponible.

Institutions déclarées

Une affiliation ne permet pas de déduire la nationalité d’un auteur.

BNTIC News n’est pas le producteur de ces données. Recherche à la demande dans Crossref et Europe PMC, sans clé ; OpenAlex reste optionnel. Aucun service payant requis, aucune réponse conservée. Sources et limites.