Data
Viewed: [[ro.stat.viewed]] Cited: [[ro.stat.cited]] Accessed: [[ro.stat.accessed]]
ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2FANDS&rft_id=info:doi10.25958/f4sc-7402&rft.title=ECU-MALNETT&rft.identifier=10.25958/f4sc-7402&rft.publisher=Edith Cowan University&rft.description=ECU-MALNETT (ECU MALware NETwork Traffic) is a real world, reproducible dataset of labeled benign and malicious network flows built from the Peekaboo execution corpus. Peekaboo runs evasive malware with dynamic binary instrumentation and records raw host-level PCAPs while granting full Internet access, yielding noisy, real-world captures with background OS activity and concurrent processes. To derive trustworthy labels from these traces, we apply Construct, a baseline aware, zero-trust labeling framework. Construct first ingests a baseline capture to establish reference sets (DNS qnames, HTTP hosts, TLS SNIs, and socket endpoints) and grows a conservative benign IP pool only via whitelisted DNS resolutions. During per-sample analysis, flows are marked benign only if they match the baseline or an explicit whitelist; all others are treated as suspicious. Malicious evidence then propagates: DNS resolutions outside the benign pool label dependent flows as malicious, while beacon-like timing and anomalous HTTP/port usage extend labels across related endpoints. The result is a corpus of automatically inferred, reproducible, and explainable flow labels that preserves real-world noise and avoids synthetic ground-truth assumptions, enabling rigorous, comparable benchmarking for AI-based malware-traffic analytics. Both Construct and the ECU-MALNETT labels are released to support transparent evaluation and accelerate research on network-based detection of evasive malware.&rft.creator=Matthew Gaber&rft.creator=Michael Johnstone&rft.creator=Mohiuddin Ahmed&rft.date=2026&rft_rights= http://creativecommons.org/licenses/by-nc/4.0/&rft_subject=malware&rft_subject=network traffic&rft_subject=Computer Sciences&rft_subject=Cybersecurity&rft.type=dataset&rft.language=English Access the data

Licence & Rights:

Non-Commercial Licence view details

Access:

Open

Contact Information

[email protected]

Full description

ECU-MALNETT (ECU MALware NETwork Traffic) is a real world, reproducible dataset of labeled benign and malicious network flows built from the Peekaboo execution corpus. Peekaboo runs evasive malware with dynamic binary instrumentation and records raw host-level PCAPs while granting full Internet access, yielding noisy, real-world captures with background OS activity and concurrent processes. To derive trustworthy labels from these traces, we apply Construct, a baseline aware, zero-trust labeling framework. Construct first ingests a baseline capture to establish reference sets (DNS qnames, HTTP hosts, TLS SNIs, and socket endpoints) and grows a conservative benign IP pool only via whitelisted DNS resolutions. During per-sample analysis, flows are marked benign only if they match the baseline or an explicit whitelist; all others are treated as suspicious. Malicious evidence then propagates: DNS resolutions outside the benign pool label dependent flows as malicious, while beacon-like timing and anomalous HTTP/port usage extend labels across related endpoints. The result is a corpus of automatically inferred, reproducible, and explainable flow labels that preserves real-world noise and avoids synthetic ground-truth assumptions, enabling rigorous, comparable benchmarking for AI-based malware-traffic analytics. Both Construct and the ECU-MALNETT labels are released to support transparent evaluation and accelerate research on network-based detection of evasive malware.

Notes

From Peekaboo’s 20,500 executed samples, ECU-MALNETT comprises a stratified random subset capped at 20 samples per family, covering 58 families across worms, ransomware, trojans, spyware, botnets, post-exploitation tools, APTs, and benign software. The result pairs realistic, noisy captures with automatically inferred labels, enabling rigorous benchmarking of malware traffic analytics without unrealistic ground-truth assumptions.

This dataset is part of a larger collection

Click to explore relationships graph
Subjects

User Contributed Tags    

Login to tag this record with meaningful keywords to make it easier to discover

Identifiers
ACN 633 798 857