Endpoint Worm Scan Dataset
Worm Scan Dataset was originally collected at Michigan State University (MSU), USA. It consists of two parts, (1) Worm traces and, (2) Benign traces. Worm traffic traces consist of traffic logs of various real and simulated worms. They include Blaster, Dloader-NY, Forbot-FU, MyDoom-A, RBOT.CCC, Rbot-AQJ, Sdbot-AFR, SoBig.E, Zotob.G, Witty, CodeRed II and Sim Src Port. Benign traffic traces consist of 12 months traffic logs of 13 different endpoints which include office, home and university desktops and laptops.
Each entry in the log file has the following 6 fields:
< session id, direction, src port, dst port, protocol, timestamp > . More details can be found in our publications section.
Download