Descriptor: Firewall Attack Detections and Extractions (FADE)
Gavin Black, Kassandra M. Fronczyk, William Arliss, Robert Allen · IEEE data descriptions. · 2025
Validating defenses to meet emerging cybersecurity challenges requires continuous updates to the datasets used for testing. In this paper, we introduce the Firewall Attack Detection Extractions (FADE) dataset designed to address gaps in available collections by generating a diverse and balanced corpus of over 10 million categorized attacks derived from open-source rule sets and public penetration testing repositories. The FADE samples not only provide a wide variety of attacks across eight common categories but also combines these with realistic network traffic to create 50 million total entries, offering a balanced mix of labeled benign and malicious traffic released in both csv and Apache Parquet formats with rows containing HTTP request strings plus metadata columns that state the benign/malicious label, attack category, and byte-range of any injected payload. The methodology for dataset creation, along with the algorithms used for payload injection, is detailed to enhance reproducibility for future attack inclusions. The FADE dataset specifically addresses limitations of existing datasets by focusing on character-based request data suitable for language model testing, explicitly modeling firewall behavior with high-confidence labeled payloads, and providing payload offsets for granular detection testing. We also provide an exploratory data analysis that demonstrates the characteristics of the dataset, including similarities between attack token frequencies and embedding spaces, underscoring the challenges and considerations necessary for developing effective defensive security tools. A classification performance baseline is established using multiple methods, highlighting the difficulty in crafting suitable predictive models. The FADE dataset, along with the relevant tools for data analysis, is being publicly released to foster research and development in network security.