Karim Syed Sohaib, Afzal Mehreen, Iqbal Waseem, Abri Dawood Al
Department of Information Security, National University of Science and Technology (NUST), Islamabad-44000, Pakistan.
Electrical and Computer Engineering Department, College of Engineering, Sultan Qaboos University, Al-Khud, 123 Muscat, Oman.
Data Brief. 2024 Mar 5;54:110290. doi: 10.1016/j.dib.2024.110290. eCollection 2024 Jun.
The novel dataset called Linux-APT Dataset 2024 captures Advanced Persistent Threat (APT) attacks along with other latest and sophisticated payloads. Existing datasets lacks latest attacker's techniques and procedures, APTs tactics and configuration to capture maximum Linux log sources to observe the working and behaviour of an APT in a detailed manner. The environment which supported us in capturing the logs is composed of Linux machines and a centralized logging system configured appropriately to captures and detect all possible events and logs for an APT and other complex intrusion. Unlike Microsoft Windows, Linux logging system are investigated enough and usually systems relies on limited log sources but for an APT, all possible log sources should be evaluated and added to completely analyse the behaviour, trajectory, and operation of an APT. To keep the dataset up to date and realistic, recent payloads and APTs are emulated in the environment. A well-known cyber-security framework 'MITRE ATT&CK' is utilised to map the behaviour and operation in a generalized manner after capturing the events and logs. This dataset can be used for training and conducting a variety of experiments to build as well as design the solutions for detecting most recent intrusions and APT attacks for Linux System.
名为“Linux-APT数据集2024”的新型数据集捕捉了高级持续性威胁(APT)攻击以及其他最新、复杂的有效载荷。现有数据集缺乏最新攻击者的技术和程序、APT战术及配置,无法捕捉到最多的Linux日志源以详细观察APT的工作情况和行为。支持我们捕捉日志的环境由Linux机器和一个经过适当配置的集中式日志系统组成,该系统能够捕捉和检测APT及其他复杂入侵的所有可能事件和日志。与微软Windows不同,Linux日志系统的研究不够充分,而且通常系统依赖有限的日志源,但对于APT来说,应该评估并添加所有可能的日志源,以便全面分析APT的行为、轨迹和操作。为了使数据集保持最新和真实,在该环境中模拟了近期的有效载荷和APT。在捕捉事件和日志后,利用一个著名的网络安全框架“MITRE ATT&CK”以通用方式映射行为和操作。该数据集可用于训练和进行各种实验,以构建和设计用于检测Linux系统最新入侵和APT攻击的解决方案。