PANDAcap – SSH Honeypot Dataset
Stamatogiannakis, Manolis and Bos, Herbert and Groth, Paul

eurosec2020-pandacap-dataset (194 files) 3.86kB 4.97kB
checksums.sha256 17.54kB
pcap/pandahoney.0000.pcap 26.15MB
pcap/pandahoney.0002.pcap 13.76kB
pcap/pandahoney.0003.pcap 75.48kB
pcap/pandahoney.0004.pcap 50.18kB
pcap/pandahoney.0005.pcap 151.33kB
pcap/pandahoney.0006.pcap 19.33MB
pcap/pandahoney.0007.pcap 14.88MB
pcap/pandahoney.0008.pcap 81.55kB
pcap/pandahoney.0009.pcap 42.17kB
pcap/pandahoney.0010.pcap 22.30MB
pcap/pandahoney.0011.pcap 397.11kB
pcap/pandahoney.0012.pcap 21.93MB
pcap/pandahoney.0013.pcap 21.63MB
pcap/pandahoney.0014.pcap 60.12kB
pcap/pandahoney.0015.pcap 18.32MB
pcap/pandahoney.0016.pcap 20.83MB
pcap/pandahoney.0017.pcap 21.95MB
pcap/pandahoney.0018.pcap 22.78kB
pcap/pandahoney.0019.pcap 22.09MB
pcap/pandahoney.0020.pcap 22.60MB
pcap/pandahoney.0021.pcap 15.01MB
pcap/pandahoney.0022.pcap 26.44kB
pcap/pandahoney.0023.pcap 21.01MB
pcap/pandahoney.0024.pcap 43.33kB
pcap/pandahoney.0025.pcap 22.18MB
pcap/pandahoney.0026.pcap 4.80MB
pcap/pandahoney.0027.pcap 12.99MB
pcap/pandahoney.0028.pcap 22.17MB
pcap/pandahoney.0029.pcap 29.80kB
pcap/pandahoney.0030.pcap 28.56MB
pcap/pandahoney.0031.pcap 20.76MB
pcap/pandahoney.0032.pcap 19.38MB
pcap/pandahoney.0033.pcap 5.21MB
pcap/pandahoney.0034.pcap 23.47MB
pcap/pandahoney.0035.pcap 10.15MB
pcap/pandahoney.0036.pcap 28.22kB
pcap/pandahoney.0037.pcap 2.65MB
pcap/pandahoney.0038.pcap 22.96MB
pcap/pandahoney.0039.pcap 24.90kB
pcap/pandahoney.0040.pcap 13.31MB
pcap/pandahoney.0041.pcap 6.80MB
pcap/pandahoney.0042.pcap 27.02kB
pcap/pandahoney.0043.pcap 13.96MB
pcap/pandahoney.0044.pcap 4.03MB
pcap/pandahoney.0045.pcap 14.85kB
pcap/pandahoney.0046.pcap 23.19MB
pcap/pandahoney.0047.pcap 72.36kB
pcap/pandahoney.0048.pcap 188.52MB
pcap/pandahoney.0049.pcap 264.85MB
pcap/pandahoney.0050.pcap 42.63kB
pcap/pandahoney.0051.pcap 19.25kB
pcap/pandahoney.0052.pcap 8.84MB
pcap/pandahoney.0053.pcap 20.56kB
pcap/pandahoney.0054.pcap 42.41kB
pcap/pandahoney.0055.pcap 4.33MB
pcap/pandahoney.0056.pcap 78.77kB
pcap/pandahoney.0057.pcap 63.71kB
pcap/pandahoney.0058.pcap 138.87kB
pcap/pandahoney.0059.pcap 15.83MB
pcap/pandahoney.0060.pcap 12.27MB
pcap/pandahoney.0062.pcap 29.34MB
pcap/pandahoney.0063.pcap 19.33MB
pcap/pandahoney.0064.pcap 36.81MB
qcow/pandahoney.0000.qcow2 267.65MB
qcow/pandahoney.0002.qcow2 231.60MB
qcow/pandahoney.0003.qcow2 227.41MB
qcow/pandahoney.0004.qcow2 228.52MB
qcow/pandahoney.0005.qcow2 228.20MB
qcow/pandahoney.0006.qcow2 260.64MB
qcow/pandahoney.0007.qcow2 259.39MB
qcow/pandahoney.0008.qcow2 226.69MB
qcow/pandahoney.0009.qcow2 226.62MB
qcow/pandahoney.0010.qcow2 266.14MB
qcow/pandahoney.0011.qcow2 178.32MB
qcow/pandahoney.0012.qcow2 265.42MB
qcow/pandahoney.0013.qcow2 267.58MB
qcow/pandahoney.0014.qcow2 231.80MB
qcow/pandahoney.0015.qcow2 259.46MB
qcow/pandahoney.0016.qcow2 263.00MB
qcow/pandahoney.0017.qcow2 267.65MB
qcow/pandahoney.0018.qcow2 227.08MB
qcow/pandahoney.0019.qcow2 267.91MB
qcow/pandahoney.0020.qcow2 269.88MB
qcow/pandahoney.0021.qcow2 258.61MB
qcow/pandahoney.0022.qcow2 227.08MB
qcow/pandahoney.0023.qcow2 212.60MB
qcow/pandahoney.0024.qcow2 228.52MB
qcow/pandahoney.0025.qcow2 267.26MB
qcow/pandahoney.0026.qcow2 230.69MB
qcow/pandahoney.0027.qcow2 262.86MB
qcow/pandahoney.0028.qcow2 272.17MB
qcow/pandahoney.0029.qcow2 179.50MB
qcow/pandahoney.0030.qcow2 269.81MB
qcow/pandahoney.0031.qcow2 264.57MB
qcow/pandahoney.0032.qcow2 262.60MB
qcow/pandahoney.0033.qcow2 232.59MB
qcow/pandahoney.0034.qcow2 267.91MB
qcow/pandahoney.0035.qcow2 240.25MB
qcow/pandahoney.0036.qcow2 227.28MB
qcow/pandahoney.0037.qcow2 230.49MB
qcow/pandahoney.0038.qcow2 267.98MB
qcow/pandahoney.0039.qcow2 248.91MB
qcow/pandahoney.0040.qcow2 259.85MB
qcow/pandahoney.0041.qcow2 245.56MB
qcow/pandahoney.0042.qcow2 227.61MB
qcow/pandahoney.0043.qcow2 260.51MB
qcow/pandahoney.0044.qcow2 232.06MB
qcow/pandahoney.0045.qcow2 228.00MB
qcow/pandahoney.0046.qcow2 267.12MB
qcow/pandahoney.0047.qcow2 227.74MB
qcow/pandahoney.0048.qcow2 249.10MB
qcow/pandahoney.0049.qcow2 294.58MB
qcow/pandahoney.0050.qcow2 315.62MB
qcow/pandahoney.0051.qcow2 227.54MB
qcow/pandahoney.0052.qcow2 249.43MB
qcow/pandahoney.0053.qcow2 243.53MB
qcow/pandahoney.0054.qcow2 228.33MB
qcow/pandahoney.0055.qcow2 235.93MB
qcow/pandahoney.0056.qcow2 227.61MB
qcow/pandahoney.0057.qcow2 226.75MB
qcow/pandahoney.0058.qcow2 227.93MB
qcow/pandahoney.0059.qcow2 259.33MB
qcow/pandahoney.0060.qcow2 259.59MB
qcow/pandahoney.0062.qcow2 250.35MB
qcow/pandahoney.0063.qcow2 258.74MB
qcow/pandahoney.0064.qcow2 286.92MB
qcow/ubuntu16-planb.qcow2 1.93GB
rr/pandahoney.0000.tar.gz 247.15MB
rr/pandahoney.0002.tar.gz 182.33MB
rr/pandahoney.0003.tar.gz 195.18MB
rr/pandahoney.0004.tar.gz 194.82MB
rr/pandahoney.0005.tar.gz 195.66MB
rr/pandahoney.0006.tar.gz 234.59MB
rr/pandahoney.0007.tar.gz 220.51MB
rr/pandahoney.0008.tar.gz 195.01MB
rr/pandahoney.0009.tar.gz 180.10MB
rr/pandahoney.0010.tar.gz 256.23MB
rr/pandahoney.0011.tar.gz 195.53MB
rr/pandahoney.0012.tar.gz 247.42MB
rr/pandahoney.0013.tar.gz 245.49MB
rr/pandahoney.0014.tar.gz 165.39MB
rr/pandahoney.0015.tar.gz 226.53MB
rr/pandahoney.0016.tar.gz 238.28MB
rr/pandahoney.0017.tar.gz 246.73MB
rr/pandahoney.0018.tar.gz 194.56MB
rr/pandahoney.0019.tar.gz 249.72MB
rr/pandahoney.0020.tar.gz 243.04MB
rr/pandahoney.0021.tar.gz 220.75MB
rr/pandahoney.0022.tar.gz 190.09MB
rr/pandahoney.0023.tar.gz 245.91MB
rr/pandahoney.0024.tar.gz 179.79MB
rr/pandahoney.0025.tar.gz 253.91MB
rr/pandahoney.0026.tar.gz 201.20MB
rr/pandahoney.0027.tar.gz 234.95MB
rr/pandahoney.0028.tar.gz 249.62MB
rr/pandahoney.0029.tar.gz 194.83MB
rr/pandahoney.0030.tar.gz 267.30MB
rr/pandahoney.0031.tar.gz 239.23MB
rr/pandahoney.0032.tar.gz 235.45MB
rr/pandahoney.0033.tar.gz 202.34MB
rr/pandahoney.0034.tar.gz 256.70MB
rr/pandahoney.0035.tar.gz 209.45MB
rr/pandahoney.0036.tar.gz 189.33MB
rr/pandahoney.0037.tar.gz 197.47MB
rr/pandahoney.0038.tar.gz 253.55MB
rr/pandahoney.0039.tar.gz 181.40MB
rr/pandahoney.0040.tar.gz 216.21MB
rr/pandahoney.0041.tar.gz 193.60MB
rr/pandahoney.0042.tar.gz 194.48MB
rr/pandahoney.0043.tar.gz 217.82MB
rr/pandahoney.0044.tar.gz 202.97MB
rr/pandahoney.0045.tar.gz 194.11MB
rr/pandahoney.0046.tar.gz 257.06MB
rr/pandahoney.0047.tar.gz 194.67MB
rr/pandahoney.0048.tar.gz 1.15GB
rr/pandahoney.0049.tar.gz 546.20MB
rr/pandahoney.0050.tar.gz 171.45MB
rr/pandahoney.0051.tar.gz 194.42MB
rr/pandahoney.0052.tar.gz 221.74MB
rr/pandahoney.0053.tar.gz 181.62MB
rr/pandahoney.0054.tar.gz 181.30MB
rr/pandahoney.0055.tar.gz 257.75MB
rr/pandahoney.0056.tar.gz 195.06MB
rr/pandahoney.0057.tar.gz 196.20MB
rr/pandahoney.0058.tar.gz 198.92MB
rr/pandahoney.0059.tar.gz 234.19MB
rr/pandahoney.0060.tar.gz 230.80MB
rr/pandahoney.0062.tar.gz 247.46MB
rr/pandahoney.0063.tar.gz 244.17MB
rr/pandahoney.0064.tar.gz 217.95MB
ubuntu16-planb-kernelinfo.conf 1.57kB
Type: Dataset
Tags: Dataset, PANDA, record and replay, docker, honeypot

title= {PANDAcap – SSH Honeypot Dataset},
journal= {},
author= {Stamatogiannakis, Manolis and Bos, Herbert and Groth, Paul},
year= {},
url= {},
abstract= {# PANDAcap – SSH Honeypot Dataset

## Overview
This is a dataset of **63 [PANDA][panda] traces**, collected using the
[PANDAcap][pandacap] framework.
The dataset aims to offer a starting point for the analysis of *ssh
brute force attacks*.
The traces were collected through the  course of approximately 3 days
from 21 to 23 February 2020.
A VM was configured using PANDAcap so that it accepts all passwords for
user `root`. When an ssh session starts for the user, PANDA is signaled
by the [recctrl plugin][recctrl] to start recording for 30'.

You can read more details about the experimental setup and an overview
of the dataset **EuroSec 2020** publication.


[1] Manolis Stamatogiannakis, Herbert Bos, and Paul Groth.
PANDAcap: A Framework for Streamlining Collection of Full-System Traces.
In *Proceedings of the 13th European Workshop on Systems Security*,
EuroSec '20, Heraklion, Greece, April 2020.
doi: [10.1145/3380786.3391396][eurosec20-doi],
preprint: [][eurosec20-preprint]


## Dataset layout
The dataset is split in 3 zip files/directories:
* **rr**: Contains the 63 PANDA traces of the dataset. The traces are in the
  upcoming RRArchive format. Note that PANDA support for the format is still
  wip at the time of writing (April 2020). If you need to downgrade to the
  traditional PANDA trace format, you can use the snippet we provide below.
* **qcow**: Contains the QCOW base image (`ubuntu16-planb.qcow2`) used to create
  the dataset, as well as the disk deltas for the 63 traces. These can be mounted
  to inspect the contents of the filesystem before and after each session.
  and disk deltas for the 63 traces. Quick instructions on how to mount
  and inspect a QCOW image can be found below.
* **pcap**: Contains the pcap network traces for the sessions in the PANDA traces.
  These have been extracted using the PANDA [network plugin][network]. We decided
  to also include them in the dataset as standalone files for convenience.

Additionally, we provide the PANDA linux kernel profile `ubuntu16-planb-kernelinfo.conf`,
which can be used to analyze the traces using the PANDA [osi_linux plugin][osi_linux].

If you wish to reuse the VM image in your project, it is also available as a standalone
download through [][at-vm-url], along with more detailed information
on its contents.

## Handy snippets

### Convert traces to traditional PANDA format
From inside the `rr` directory, run:

for f in *.tar.gz; do
    tar -zxvf "$f" --exclude=PANDArr --xform='s%/%-%' --xform='s%-metadata%%'
    rm -f "$f"

### Mounting a QCOW image
Run the following as root:
modprobe nbd max_part=69
qemu-nbd -c /dev/nbd0 ./ubuntu16-planb.qcow2
mount /dev/nbd0p1 ./mnt
# some work...
umount mnt
qemu-nbd -d /dev/nbd0

[a-trace-convert]: #convert-traces-to-traditional-panda-format
[a-qcow-mount]: #mounting-a-qcow-image
keywords= {Dataset, PANDA, record and replay, docker, honeypot},
terms= {Data are shared in accordance to the Creative Commons Attribution 4.0 International license.

For the included VM IMAGE, the following apply. The VM IMAGE is a COLLECTION of various open-source components, shared for research purposes. The VM IMAGE is provided "as is", without warranty of any kind, express or implied, including but not limited to the warranties of merchantability, fitness for a particular purpose and noninfringement. In no event shall the authors of the VM IMAGE or copyright holders be liable for any claim, damages or other liability, whether in an action of contract, tort or otherwise, arising from, out of or in connection with the  VM IMAGE or the use or other dealings in the VM IMAGE. NO ASSERTIONS are made on the copyright and licensing terms of the open-source components included in the VM IMAGE.},
license= {Creative Commons Attribution 4.0 International},
superseded= {}

Hosted by users: