DARPA Intrusion Detection Evaluation
1999 Training Data - Week 1
The simulation network normally collected data twenty-two hours a day. The tcpslice program was used to examine the outside tcpdump data files and the actual times of the first and last packet were extracted. These times are shown below. During the first week of training data the simulation network did not experience any unscheduled down time.
First Packet Time | Last Packet Time | |||||||||
Mon | Mar 1 | 08:00:02 | Tue | Mar 2 | 06:00:02 | |||||
Tue | Mar 2 | 08:00:02 | Wed | Mar 3 | 06:00:01 | |||||
Wed | Mar 3 | 08:00:03 | Thu | Mar 4 | 06:00:01 | |||||
Thu | Mar 4 | 08:00:03 | Fri | Mar 5 | 06:00:02 | |||||
Fri | Mar 5 | 08:00:02 | Sat | Mar 6 | 06:00:02 |
Monday
outside tcpdump data | 159,432 kb | gzipped |
inside tcpdump data | 165,264 kb | gzipped |
Solaris BSM audit data | 5,559 kb | gzipped |
NT audit data | 4,501 kb | tarred & gzipped |
Selected directory dumps | 3,118 kb | tarred & gzipped |
File system listing & inode record | 6,851 kb | tarred & gzipped |
Tuesday
outside tcpdump data | 155,620 kb | gzipped |
inside tcpdump data | 163,009 kb | gzipped |
Solaris BSM audit data | 2,869 kb | gzipped |
NT audit data | 82,712 kb | tarred & gzipped |
Selected directory dumps | 2,482 kb | tarred & gzipped |
File system listing & inode record | 6,347 kb | tarred & gzipped |
Wednesday
outside tcpdump data | 180,585 kb | gzipped |
inside tcpdump data | 186,631 kb | gzipped |
Solaris BSM audit data | 2,238 kb | gzipped |
NT audit data | 306 kb | tarred & gzipped |
Selected directory dumps | 3,057 kb | tarred & gzipped |
File system listing & inode record | 6,358 kb | tarred & gzipped |
Thursday
outside tcpdump data | 244,683 kb | gzipped |
inside tcpdump data | 267,904 kb | gzipped |
Solaris BSM audit data | 2,789 kb | gzipped |
NT audit data | 2,012 kb | tarred & gzipped |
Selected directory dumps | 3,116 kb | tarred & gzipped |
File system listing & inode record | 6,288 kb | tarred & gzipped |
Friday
outside tcpdump data | 141,562 kb | gzipped |
inside tcpdump data | 150,301 kb | gzipped |
Solaris BSM audit data | 2,074 kb | gzipped |
NT audit data | 10,546 kb | tarred & gzipped |
Selected directory dumps | 3,117 kb | tarred & gzipped |
File system listing & inode record | 2,732 kb | tarred & gzipped |
Errata.
None.
top of page