HTTP Tarpit Interaction Dataset: 11-Month Analysis of Botnet Resource Exhaustion and Global DDoS Correlation
Résumé fourni par la source
This dataset contains 251,140 interaction records captured by an asynchronous HTTP Tarpit over an 11-month period. The primary objective of the system was to exhaust the computational and session resources of attacking botnets by maintaining persistent, slow-response connections. Advanced Technical Analysis: Infrastructure: Built on a Python-based asynchronous engine (aiohttp), allowing the handling of thousands of concurrent bot sessions without system degradation. Protocol Simulation: The tarpit mimics a standard HTTP server but responds byte-by-byte with variable delays, effectively bypassing the simple timeout mechanisms of modern botnets. Global Incident Correlation: Cloudflare Hyper-DDoS (Sept 2, 2025): The sensor recorded a 5.4x increase in scanning intensity (817 events/hour) during the peak of global HTTP/2 Rapid Reset attacks. Gaming Sector Impact (Albion Online, June 2025): Captured secondary scanning waves during large-scale DDoS campaigns against MMORPG infrastructure. Secret Hunting: Detailed logs show high-frequency targeting of configuration backups (.env.prod, wp-config.php.bak) and sensitive internal endpoints. Version 2.0 Updates & Sanitization Introduced the real_ip column to provide verified source IP addresses Implemented programmatic recovery of source IPs for 254 anomalous records, addressing Log4Shell payloads and IP spoofing attempts Added explicit definitions and SQL procedures for data sanitization to ensure reproducibility Now .csv tables in folder artifacts of archive tarpit_events.tar.gz Technical Content: The provided SQLite database (tarpit_events.db) and CSV export include 23 fields covering: Full HTTP headers and User-Agent strings. Detailed GeoIP and ASN metadata. Precise connection duration and byte-count metrics. Evidence of "Secret Hunting" (targeting of .env, wp-config, and backup files). Authors & Affiliations Boiko, Viktor (ORCID: 0000-0001-5929-657X) — Scientific Supervisor & Lead Researcher. Associate Professor. Spesivtsev, Mykola (ORCID: 0009-0007-5640-5241) — Lead Software Developer & Researcher. Affiliation: Faculty of Cybersecurity and Information Technologies, National University "Odesa Law Academy", Ukraine. (ROR: https://ror.org/0282prk66)Usage and Licensing Intended for academic research in Cybersecurity, IDS Machine Learning, and Threat Intelligence. License: Creative Commons Attribution 4.0 International (CC BY 4.0).