<div class="csl-bib-body">
<div class="csl-entry">Brenner, B., Fabini, J., Offermanns, M., Semper, S., & Zseby, T. (2024). Malware communication in smart factories: A network traffic data set. <i>Computer Networks</i>, <i>255</i>, Article 110804. https://doi.org/10.1016/j.comnet.2024.110804</div>
</div>
-
dc.identifier.issn
1389-1286
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/203860
-
dc.description.abstract
Machine learning-based intrusion detection requires suitable and realistic data sets for training and testing. However, data sets that originate from real networks are rare. Network data is considered privacy sensitive and the purposeful introduction of malicious traffic is usually not possible. In this paper we introduce a labeled data set captured at a smart factory located in Vienna, Austria during normal operation and during penetration tests with different attack types. The data set consists of 173 GB of Packet Capture (PCAP) files, which represent 16 days (395 h) of factory operation. It includes Message Queuing Telemetry Transport (MQTT), OPC Unified Architecture (OPC UA), and Modbus/TCP traffic. The captured malicious traffic was originated by a professional penetration tester who performed two types of attacks: (a) aggressive attacks that are easier to detect and (b) stealthy attacks that are harder to detect. Our data set includes the raw PCAP files and extracted flow data. Labels for packets and flows indicate whether packets (or flows) originated from a specific attack or from benign communication. We describe the methodology for creating the data set, conduct an analysis of the data and provide detailed information about the recorded traffic itself. The data set is freely available to support reproducible research and the comparability of results in the area of intrusion detection in industrial networks.
en
dc.language.iso
en
-
dc.publisher
ELSEVIER
-
dc.relation.ispartof
Computer Networks
-
dc.rights.uri
http://creativecommons.org/licenses/by/4.0/
-
dc.subject
Data set
en
dc.subject
ICS
en
dc.subject
IDS
en
dc.subject
IIOT
en
dc.subject
Industrial control systems
en
dc.subject
Internet of Things
en
dc.subject
Intrusion detection system
en
dc.subject
IoT
en
dc.subject
Network security
en
dc.subject
Network traffic
en
dc.subject
Operational technology
en
dc.subject
OT
en
dc.title
Malware communication in smart factories: A network traffic data set