Dataset

64 views
Skip to first unread message

Mehdi Maleki

unread,
Aug 4, 2015, 4:35:10 PM8/4/15
to security-onion
I need good dataset(same darpa but new) that has these property:
1)Be public & free
2)Has identification list file for checking my IDS performance
3)Has a multistage attack

Doug Burks

unread,
Aug 4, 2015, 4:45:09 PM8/4/15
to securit...@googlegroups.com
As I mentioned in your previous thread, have you tried the pcaps
included in Security Onion in /opt/samples/?

Specifically, the /opt/samples/mta/ directory has several interesting
pcaps with related descriptions at:
http://malware-traffic-analysis.net/blog-entries.html

For example, /opt/samples/mta/2014-12-05-phishing-email-traffic.pcap
has a detailed writeup here:
http://malware-traffic-analysis.net/2014/12/05/index.html
> --
> You received this message because you are subscribed to the Google Groups "security-onion" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
> To post to this group, send email to securit...@googlegroups.com.
> Visit this group at http://groups.google.com/group/security-onion.
> For more options, visit https://groups.google.com/d/optout.



--
Doug Burks
Need Security Onion Training or Commercial Support?
http://securityonionsolutions.com

Mehdi Maleki

unread,
Aug 5, 2015, 1:51:51 AM8/5/15
to security-onion
i don't have mta directory there.i have markufu & pnsm directory there.

Doug Burks

unread,
Aug 5, 2015, 6:55:22 AM8/5/15
to securit...@googlegroups.com
The securityonion-samples-mta package has been included in our ISO
image since 12.04.5.1:
http://blog.securityonion.net/2015/02/security-onion-120451-iso-image-now.html

You can install it manually with:
sudo apt-get update
sudo apt-get install securityonion-samples-mta

On Wed, Aug 5, 2015 at 1:51 AM, Mehdi Maleki <mehd...@gmail.com> wrote:
> i don't have mta directory there.i have markufu & pnsm directory there.
>
Reply all
Reply to author
Forward
0 new messages