DARPA Intrusion Detection Evaluation
1998 DARPA Intrusion Detection Evaluation Data Set
1998 DARPA Intrusion Detection Evaluation Data Set Overview
There were two parts to the 1998 DARPA Intrusion Detection Evaluation: an off-line evaluation and a real-time evaluation.
Intrusion detection systems were tested in the off-line evaluation using network traffic and audit logs collected on a simulation network. The systems processed this data in batch mode and attempted to identify attack sessions in the midst of normal activities.
Intrusion detection systems were delivered to AFRL for the real-time evaluation. These systems were inserted into the AFRL network testbed and attempted to identify attack sessions in the midst of normal activities, in realtime.
Intrusion detection systems were tested as part of the off-line evaluation, the real-time evaluation or both.
Sample Data
A sample of the network traffic and audit logs that were used for evaluating systems. These data were first made available in February 1998.
- README file
- Sample Data Set [3,000 Kb tar/gzip]
Four-Hour Subset of Training Data
A somewhat larger sample of training data. These data were first made available in May 1998.
- README file
- Tcpdump data [38 MB gzip]
- BSM data [5 MB gzip]
- ASCII BSM data [6 MB gzip]
- File system dump (ufsdump) - /root [40 MB gzip]
- File system dump (ufsdump) - /usr [87 MB gzip]
- File system dump (ufsdump) - /home [1 MB gzip]
- File system dump (ufsdump) - /opt [93 MB gzip]
Training Data
Seven weeks of network-based attacks in the midst of normal background data. Listings of attacks and anomalies are available on the Documentation page.
- First Week of Training Data
- Second Week of Training Data
- Third Week of Training Data
- Fourth Week of Training Data
- Fifth Week of Training Data
- Sixth Week of Training Data
- Seventh Week of Training Data
Testing Data
Two weeks of network-based attacks in the midst of normal background data.
- First Week of Test Data
- Second Week of Test Data
- First Week Truth [13.7 MB tar gzip]
- Second Week Truth [13.1 MB tar gzip]
top of page