Data in Brief (Apr 2022)

Data set and machine learning models for the classification of network traffic originators

  • Daniele Canavese,
  • Leonardo Regano,
  • Cataldo Basile,
  • Gabriele Ciravegna,
  • Antonio Lioy

Journal volume & issue
Vol. 41
p. 107968

Abstract

Read online

The widespread adoption of encryption in computer network traffic is increasing the difficulty of analyzing such traffic for security purposes. The data set presented in this data article is composed of network statistics computed on captures of TCP flows, originated by executing various network stress and web crawling tools, along with statistics of benign web browsing traffic. Furthermore, this data article describes a set of Machine Learning models, trained using the described data set, which can classify network traffic by the tool category (network stress tool, web crawler, web browser), the specific tool (e.g., Firefox), and also the tool version (e.g., Firefox 68) used to generate it. These models are compatible with the analysis of traffic with encrypted payload since statistics are evaluated only on the TCP headers of the packets. The data presented in this article can be useful to train and assess the performance of new Machine Learning models for tool classification.

Keywords