Botnet dataset
External Dataset
External Data Source
University of New Brunswick
52 (lowest rank is 52)

Category & Restrictions

malicious traffic, network data, malware, botnet


Assessing performance of any detection approach requires experimentation with data that is heterogeneous enough to simulate real traffic to an acceptable level.

Botnet traces can be merged with benign data by mapping malicious data to either machines existing in the home network or machines outside of the current network. Considering the wide range of IP addresses in the traces, we mapped botnet IPs to the hosts outside of the current network using BitTwist packet generator. Malicious and benign traffic were then replayed using TCPReplay and captured by TCPdump as a single dataset. ;

Additional Details

