Biblio-US17: A labeled real URL dataset for anomaly-based intrusion detection systems development
Jesús E. Dı́az-Verdejo, Rafael Estepa, Antonio Estepa, Javier Muñoz-Calle, Germán Madinabeitia · 2024
The development of anomaly-based intrusion detection systems is hindered by the scarcity of adequate datasets. An ideal dataset should contain real traffic, genuine attacks and cover a large time period that may demonstrate time shift. To be useful, the dataset must be labeled to provide accurate ground-truth, This paper presents a dataset of URLs that possesses these qualities. It can therefore be used to effectively train, test, and validate URL-based anomaly detection systems. The dataset is publicly available and contains 47M registers, including 320k attacks, and spans for 6.5 months. It is partitioned acording to two schemes to allow for time dependent and time independent experiments.