基于40周真实网络流量构建大规模时序数据集,助力异常检测模型评估
CESNET-TimeSeries24: Time Series Dataset for Network Traffic Anomaly Detection and Forecasting
- 从27.5万个活跃IP地址采集40周流量构建时序数据集
- 涵盖运营商级网络多样性,提升异常检测模型真实场景测试能力
- 适合研究网络异常检测与预测算法的科研人员使用
网络流量异常检测对保障计算机网络安全和识别恶意行为至关重要。基于预测的方法是主流检测手段之一,但缺乏广泛的真实世界网络数据集用于预测与异常检测,可能导致算法性能被高估。本文通过收集来自CESNET3网络的40周流量数据,构建了一个包含27.5万个活跃IP地址行为的时序数据集。该数据集源自互联网服务提供商环境,具备高度的网络实体差异性,为预测与异常检测模型提供了真实且具有挑战性的测试基准,有助于揭示基于预测的异常检测方法在实际部署中的表现。
原文摘要 · Abstract (English)
Anomaly detection in network traffic is crucial for maintaining the security of computer networks and identifying malicious activities. One of the primary approaches to anomaly detection are methods based on forecasting. Nevertheless, extensive real-world network datasets for forecasting and anomaly detection techniques are missing, potentially causing performance overestimation of anomaly detection algorithms. This manuscript addresses this gap by introducing a dataset comprising time series data of network entities' behavior, collected from the CESNET3 network. The dataset was created from 40 weeks of network traffic of 275 thousand active IP addresses. The ISP origin of the presented data ensures a high level of variability among network entities, which forms a unique and authentic challenge for forecasting and anomaly detection models. It provides valuable insights into the practical deployment of forecast-based anomaly detection approaches.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。