You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Greetings YisroelMirsky,
I wish to use your datasets as an input to my models. However, upon looking into the I/O graphs of the captured pcap files, I found that there is no spikes of any attack packets after 1st million packets in the following dataset (I downloaded all 9 pcaps from google drive in your github kitsune project):
In the SSL renegotiation pcap:
As can be seen, after the first million packets, there is no significant rise in SSL filter line.
In the SSDP flood pcap:
Also, there is no abnormal behavior in the UDP filter line. I presume in SSDP flood attack, UDP packets are the attack vectors. (The abnormal behavior of UDP packets doesn't happen until the very end, which is after around 2.621.185 packets)
Do I understand your statement of "clean network traffic was captured for the first 1 million packets " correctly? Or am I missing something?
Thanks,
Hieu
The text was updated successfully, but these errors were encountered:
fil618
changed the title
Clean network traffic are not the 1st million packets!
Clean network traffic are not the 1st million packets
Dec 9, 2021
Greetings YisroelMirsky,
I wish to use your datasets as an input to my models. However, upon looking into the I/O graphs of the captured pcap files, I found that there is no spikes of any attack packets after 1st million packets in the following dataset (I downloaded all 9 pcaps from google drive in your github kitsune project):
In the SSL renegotiation pcap:

As can be seen, after the first million packets, there is no significant rise in SSL filter line.
In the SSDP flood pcap:

Also, there is no abnormal behavior in the UDP filter line. I presume in SSDP flood attack, UDP packets are the attack vectors. (The abnormal behavior of UDP packets doesn't happen until the very end, which is after around 2.621.185 packets)
Do I understand your statement of "clean network traffic was captured for the first 1 million packets " correctly? Or am I missing something?
Thanks,
Hieu
The text was updated successfully, but these errors were encountered: