Focus on IDS
CDX dataset and labeling Sep 23 2009 04:11AM
snort user (snort user gmail com)
The CDX dataset is available at
The paper describing the generation of labeled dataset is available

As a user of this dataset, how do I get labeling information.
The detailed network diagram is also available at

Attack labeling based on ip address: [?]
The IP addresses of the Red Team (the bad guys) is known ahead of
time. But the red team also
generates benign traffic. In addition, after taking over some of the
good machines, red team
can use those ip addresses to attack.

Unless the user digs deep and analyze the traffic in detail is it
possible to know
which sessions/packets are good / bad?
Otherwise what does labeled data mean?

Thanks for any clarification -

