Toward Instrumenting Network Warfare Competitions to Generate Labeled Datasets
B. Sangster, T.J. O'Connor, T. Cook, R. Fanelli, E. Dean, J. Adams, C. Morrell, and G. Conti; "Toward Instrumenting Network Warfare Competitions to Generate Labeled Datasets;" USENIX Security's Workshop on Cyber Security Experimentation and Test (CSET); August 2009.
Acknowledgements
We would like to thank the following for their support, helpful ideas, and feedback: Army Research Labs, Michael Collins, Robert Cunningham, Carrie Gates, FLOCON, Richard Lippmann, Lisa Marvel, MIT Lincoln Labs, John McHugh, NSA, and Tamara Yu.Permission
The National Security Agency permitted both the recording and release of the following datasets.Datasets for the Research Community Blog
If you would like to provide feedback on the 2009 Inter-Service Academy Cyber Defense Exercise datasets, or would like to provide comments or suggestions for upcoming data captures engineered by the ITOC, please visit our blog.
Network Diagram (Pre-CDX 2009)
In an attempt to provide users of our dataset a means to correlate IP addresses found in the PCAP files with the IP addresses to hosts on the internal USMA network, we are including a link to the planning document used just prior to the execution of CDX 2009 (NOTE: USMA utilized network address translation). Keep in mind this was a planning document. Changes may have occurred to the USMA network that were not annotated on this document. We hope to have the actual router configuration files uploaded to the website within the next week.
Pre-CDX 2009 Network Diagram (USMA Internal Network)
Data Capture from National Security Agency (NSA)
- NSA Data Capture
1/15 (953 MB)
MD5: 790fa7d06392944e6e760aabb0bb6ba7 - NSA Data
Capture 2/15 (953 MB)
MD5: 7ba5416b4b9bb686987334b3c88e022c - NSA Data
Capture 3/15 (953 MB)
MD5: f10ea9f15c78b17a8ef230c6c6559360 - NSA Data
Capture 4/15 (953 MB)
MD5: 2df4282be1f17f8342cdbb18f2f64c33 - NSA Data
Capture 5/15 (953 MB)
MD5: f4ba815152b88975fbe909f4c27961fb - NSA Data
Capture 6/15 (953 MB)
MD5: 68d9c71fe9ee6a846972b44aee65fbe7 - NSA Data
Capture 7/15 (953 MB)
MD5: a8f9ffde1c363ab71d29b782cc159e21 - NSA Data
Capture 8/15 (953 MB)
MD5: d1ca80d198dc7325b21daa5cacf7b509 - NSA Data
Capture 9/15 (953 MB)
MD5: a111bcd85cf92b3c1e4b9917fc88ce21 - NSA Data
Capture 10/15 (953 MB)
MD5: 4255f0a50bd6ae6a358d08de6ba2f4c4 - NSA Data
Capture 11/15 (953 MB)
MD5: 2e44e7c1eb2b9c3ba3274c2f1990db5b - NSA Data
Capture 12/15 (953 MB)
MD5: 1240ec458e0f0aca97b226ac1e2a0b03 - NSA Data
Capture 13/15 (953 MB)
MD5: 4da56c736054a321b2e6b58358791851 - NSA Data
Capture 14/15 (953 MB)
MD5: ac96b8b33e46c9048fda809d8c3a4596 - NSA Data
Capture 15/15 (480 MB)
MD5: 0a40e3000a14112933ffc8f4c2056811
Data Capture Outside West Point Network Border
- Border Data
Capture 1/8 (3.50 MB)
MD5: dbe35d71dd5f42b685171fd372998402 - Border Data
Capture 2/8 (156 MB)
MD5: ada297154443703854a8b8d2f5bdc211 - Border Data
Capture 3/8 (95.3 MB)
MD5: 3ca15adb9317811e63af43f858756eec - Border Data
Capture 4/8 (95.3 MB)
MD5: 3b4d17ac12e7996437037999a5761db4 - Border Data
Capture 5/8 (95.3 MB)
MD5: 09c63c23fba6bf2600eae99f38d7b8d6 - Border Data
Capture 6/8 (95.3 MB)
MD5: 238d7b2433995f08bf1e0baca0d3c44a - Border Data
Capture 7/8 (95.3 MB)
MD5: 511f94f37c3692f9405e897d1ad8cbc0 - Border Data
Capture 8/8 (72.8 MB)
MD5:66255c33a947413ac26e51c4bc14048e
Snort Intrusion Detection Log/strong: from 0700-Nov-08 to 1600-Nov-11 (Entire Exercise)
- Snort IDS Alert Log (10.8 MB)
MD5: 54d005c1a4ac393df9a4c2eed78f0c24
Domain Name Service Logs: from 0700-Nov-08 to 1600-Nov-11 (Entire Exercise)
- External DNS named Service Log
(6.33 MB)
MD5: b9814bf9e1a5672688bc745fe1d4be23 - External DNS Message Log
(80.8 KB)
MD5: 8cf9294169c057c798b8f62132b22801
Web Server Logs: 24-Hour Logs from 1600-Nov-10 to 1600-Nov-11 (Final Day of Exercise)
- Apache Web Server Access Log
(860 KB)
MD5: 769559e08e188a23889fb7fcbf9995ea - Apache Web
Server Error Log (104 KB)
MD5: 3efa89b4dd16f3c9c64977acf342d913
Our personal favorite:
Nov 11 09:36:55 www logger: 10.2.27.218 - -[11/Nov/2011:09:36:55 -0500]
"GET /redteamsayshiplzblockmeagainandagainandagainandagain HTTP/1.0" 302 261
Log Server Aggregate Log: from 0700-Nov-11 to 1600-Nov-11 (Final Day of Exercise)
- Splunk Log Server
Aggregate Log (109 KB)
MD5: 54d005c1a4ac393df9a4c2eed78f0c24
CONTACT INFO
Please contact MAJ Benjamin Sangster (benjamin [dot] sangster [at] usma [dot] edu) for any further details about the enclosed datasets and logs.