{"url":"/dataset/cicids2017","name":"CICIDS2017","full_name":"Intrusion Detection Evaluation Dataset (CIC-IDS2017)","description_markdown":"Intrusion Detection Evaluation Dataset (CIC-IDS2017)\r\nIntrusion Detection Systems (IDSs) and Intrusion Prevention Systems (IPSs) are the most important defense tools against the sophisticated and ever-growing network attacks. Due to the lack of reliable test and validation datasets, anomaly-based intrusion detection approaches are suffering from consistent and accurate performance evolutions.\r\n\r\nOur evaluations of the existing eleven datasets since 1998 show that most are out of date and unreliable. Some of these datasets suffer from the lack of traffic diversity and volumes, some do not cover the variety of known attacks, while others anonymize packet payload data, which cannot reflect the current trends. Some are also lacking feature set and metadata.\r\n\r\nCICIDS2017 dataset contains benign and the most up-to-date common attacks, which resembles the true real-world data (PCAPs). It also includes the results of the network traffic analysis using CICFlowMeter with labeled flows based on the time stamp, source, and destination IPs, source and destination ports, protocols and attack (CSV files). Also available is the extracted features definition. \r\n\r\nGenerating realistic background traffic was our top priority in building this dataset. We have used our proposed B-Profile system (Sharafaldin, et al. 2016) to profile the abstract behavior of human interactions and generates naturalistic benign background traffic. For this dataset, we built the abstract behaviour of 25 users based on the HTTP, HTTPS, FTP, SSH, and email protocols.\r\n\r\nThe data capturing period started at 9 a.m., Monday, July 3, 2017 and ended at 5 p.m. on Friday July 7, 2017, for a total of 5 days. Monday is the normal day and only includes the benign traffic. The implemented attacks include Brute Force FTP, Brute Force SSH, DoS, Heartbleed, Web Attack, Infiltration, Botnet and DDoS. They have been executed both morning and afternoon on Tuesday, Wednesday, Thursday and Friday.\r\n\r\nIn our recent dataset evaluation framework (Gharib et al., 2016), we have identified eleven criteria that are necessary for building a reliable benchmark dataset. None of the previous IDS datasets could cover all of the 11 criteria. In the following, we briefly outline these criteria:\r\n\r\nComplete Network configuration: A complete network topology includes Modem, Firewall, Switches, Routers, and presence of a variety of operating systems such as Windows, Ubuntu and Mac OS X.\r\n\r\nComplete Traffic: By having a user profiling agent and 12 different machines in Victim-Network and real attacks from the Attack-Network.\r\n\r\nLabelled Dataset: Section 4 and Table 2 show the benign and attack labels for each day. Also, the details of the attack timing will be published on the dataset document.\r\n\r\nComplete Interaction: As Figure 1 shows, we covered both within and between internal LAN by having two different networks and Internet communication as well.\r\n\r\nComplete Capture: Because we used the mirror port, such as tapping system, all traffics have been captured and recorded on the storage server.\r\n\r\nAvailable Protocols: Provided the presence of all common available protocols, such as HTTP, HTTPS, FTP, SSH and email protocols.\r\n\r\nAttack Diversity: Included the most common attacks based on the 2016 McAfee report, such as Web based, Brute force, DoS, DDoS, Infiltration, Heart-bleed, Bot and Scan covered in this dataset.\r\n\r\nHeterogeneity: Captured the network traffic from the main Switch and memory dump and system calls from all victim machines, during the attacks execution.\r\n\r\nFeature Set: Extracted more than 80 network flow features from the generated network traffic using CICFlowMeter and delivered the network flow dataset as a CSV file. See our PCAP analyzer and CSV generator.\r\n\r\nMetaData: Completely explained the dataset which includes the time, attacks, flows and labels in the published paper.\r\n\r\nThe full research paper outlining the details of the dataset and its underlying principles:\r\n\r\nIman Sharafaldin, Arash Habibi Lashkari, and Ali A. Ghorbani, “Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization”, 4th International Conference on Information Systems Security and Privacy (ICISSP), Purtogal, January 2018\r\n\r\nDay, Date, Description, Size (GB)\r\n\r\nMonday, Normal Activity, 11.0G\r\nTuesday, attacks + Normal Activity, 11G\r\nWednesday, attacks + Normal Activity, 13G\r\nThursday, attacks + Normal Activity, 7.8G\r\nFriday, attacks + Normal Activity, 8.3G\r\nVictim and attacker networks information\r\nFirewall: 205.174.165.80, 172.16.0.1\r\n\r\nDNS+ DC Server: 192.168.10.3\r\n\r\nOutsiders (Attackers network)\r\n\r\nKali: 205.174.165.73\r\nWin: 205.174.165.69, 70, 71\r\nInsiders (Victim network)\r\n\r\nWeb server 16 Public: 192.168.10.50, 205.174.165.68\r\nUbuntu server 12 Public: 192.168.10.51, 205.174.165.66\r\nUbuntu 14.4, 32B: 192.168.10.19\r\nUbuntu 14.4, 64B: 192.168.10.17\r\nUbuntu 16.4, 32B: 192.168.10.16\r\nUbuntu 16.4, 64B: 192.168.10.12\r\nWin 7 Pro, 64B: 192.168.10.9\r\nWin 8.1, 64B: 192.168.10.5\r\nWin Vista, 64B: 192.168.10.8\r\nWin 10, pro 32B: 192.168.10.14\r\nWin 10, 64B: 192.168.10.15\r\nMAC: 192.168.10.25\r\n\r\nMonday, July 3, 2017\r\nBenign (Normal human activities)\r\n\r\n\r\nTuesday, July 4, 2017\r\nBrute Force\r\n\r\nFTP-Patator (9:20 – 10:20 a.m.)\r\n\r\nSSH-Patator (14:00 – 15:00 p.m.)\r\n\r\nAttacker: Kali, 205.174.165.73\r\n\r\nVictim: WebServer Ubuntu, 205.174.165.68 (Local IP: 192.168.10.50)\r\n\r\n\r\nNAT Process on Firewall:\r\n\r\nAttack: 205.174.165.73 -> 205.174.165.80 (IP Valid Firewall) -> 172.16.0.10 -> 192.168.10.50\r\n\r\nReply: 192.168.10.50 -> 172.16.0.1 -> 205.174.165.80 -> 205.174.165.73\r\n\r\n\r\nWednesday, July 5, 2017\r\nDoS / DDoS\r\n\r\nDoS slowloris (9:47 – 10:10 a.m.)\r\n\r\nDoS Slowhttptest (10:14 – 10:35 a.m.)\r\n\r\nDoS Hulk (10:43 – 11 a.m.)\r\n\r\nDoS GoldenEye (11:10 – 11:23 a.m.)\r\n\r\n\r\nAttacker: Kali, 205.174.165.73\r\n\r\nVictim: WebServer Ubuntu, 205.174.165.68 (Local IP192.168.10.50)\r\n\r\n\r\nNAT Process on Firewall:\r\n\r\nAttack: 205.174.165.73 -> 205.174.165.80 (IP Valid Firewall) -> 172.16.0.10 -> 192.168.10.50\r\n\r\nReply: 192.168.10.50 -> 172.16.0.1 -> 205.174.165.80 -> 205.174.165.73\r\n\r\n\r\nHeartbleed Port 444 (15:12 - 15:32)\r\n\r\nAttacker: Kali, 205.174.165.73\r\n\r\nVictim: Ubuntu12, 205.174.165.66 (Local IP192.168.10.51)\r\n\r\n\r\nNAT Process on Firewall:\r\n\r\nAttack: 205.174.165.73 -> 205.174.165.80 (IP Valid Firewall) -> 172.16.0.11 -> 192.168.10.51\r\n\r\nReply: 192.168.10.51 -> 172.16.0.1 -> 205.174.165.80 -> 205.174.165.73\r\n\r\n\r\nThursday, July 6, 2017\r\nMorning\r\nWeb Attack – Brute Force (9:20 – 10 a.m.)\r\n\r\nWeb Attack – XSS (10:15 – 10:35 a.m.)\r\n\r\nWeb Attack – Sql Injection (10:40 – 10:42 a.m.)\r\n\r\nAttacker: Kali, 205.174.165.73\r\n\r\nVictim: WebServer Ubuntu, 205.174.165.68 (Local IP192.168.10.50)\r\n\r\n\r\nNAT Process on Firewall:\r\n\r\nAttack: 205.174.165.73 -> 205.174.165.80 (IP Valid Firewall) -> 172.16.0.10 -> 192.168.10.50\r\n\r\nReply: 192.168.10.50 -> 172.16.0.1 -> 205.174.165.80 -> 205.174.165.73\r\n\r\n\r\nAfternoon\r\nInfiltration – Dropbox download\r\n\r\nMeta exploit Win Vista (14:19 and 14:20-14:21 p.m.) and (14:33 -14:35)\r\n\r\nAttacker: Kali, 205.174.165.73\r\n\r\nVictim: Windows Vista, 192.168.10.8\r\n\r\n\r\nInfiltration – Cool disk – MAC (14:53 p.m. – 15:00 p.m.)\r\n\r\nAttacker: Kali, 205.174.165.73\r\n\r\nVictim: MAC, 192.168.10.25\r\n\r\n\r\nInfiltration – Dropbox download\r\n\r\nWin Vista (15:04 – 15:45 p.m.)\r\n\r\nFirst Step:\r\n\r\nAttacker: Kali, 205.174.165.73\r\n\r\nVictim: Windows Vista, 192.168.10.8\r\n\r\n\r\nSecond Step (Portscan + Nmap):\r\n\r\nAttacker:Vista, 192.168.10.8\r\n\r\nVictim: All other clients\r\n\r\n\r\nFriday, July 7, 2017\r\nMorning\r\nBotnet ARES (10:02 a.m. – 11:02 a.m.)\r\n\r\nAttacker: Kali, 205.174.165.73\r\n\r\nVictims: Win 10, 192.168.10.15 + Win 7, 192.168.10.9 + Win 10, 192.168.10.14 + Win 8, 192.168.10.5 + Vista, 192.168.10.8\r\n\r\n\r\nAfternoon\r\nPort Scan:\r\n\r\nFirewall Rule on (13:55 – 13:57, 13:58 – 14:00, 14:01 – 14:04, 14:05 – 14:07, 14:08 - 14:10, 14:11 – 14:13, 14:14 – 14:16, 14:17 – 14:19, 14:20 – 14:21, 14:22 – 14:24, 14:33 – 14:33, 14:35 - 14:35)\r\n\r\nFirewall rules off (sS 14:51-14:53, sT 14:54-14:56, sF 14:57-14:59, sX 15:00-15:02, sN 15:03-15:05, sP 15:06-15:07, sV 15:08-15:10, sU 15:11-15:12, sO 15:13-15:15, sA 15:16-15:18, sW 15:19-15:21, sR 15:22-15:24, sL 15:25-15:25, sI 15:26-15:27, b 15:28-15:29)\r\n\r\nAttacker: Kali, 205.174.165.73\r\n\r\nVictim: Ubuntu16, 205.174.165.68 (Local IP: 192.168.10.50)\r\n\r\nNAT Process on Firewall:\r\n\r\nAttacker: 205.174.165.73 -> 205.174.165.80 (IP Valid Firewall) -> 172.16.0.1\r\n\r\nAfternoon\r\nDDoS LOIT (15:56 – 16:16)\r\n\r\nAttackers: Three Win 8.1, 205.174.165.69 - 71\r\n\r\nVictim: Ubuntu16, 205.174.165.68 (Local IP: 192.168.10.50)\r\n\r\nNAT Process on Firewall:\r\n\r\nAttackers: 205.174.165.69, 70, 71 -> 205.174.165.80 (IP Valid Firewall) -> 172.16.0.1\r\n\r\n\r\nLicense\r\nThe CICIDS2017 dataset consists of labeled network flows, including full packet payloads in pcap format, the corresponding profiles and the labeled flows (GeneratedLabelledFlows.zip) and CSV files for machine and deep learning purpose (MachineLearningCSV.zip) are publicly available for researchers. If you are using our dataset, you should cite our related paper which outlining the details of the dataset and its underlying principles:\r\n\r\nIman Sharafaldin, Arash Habibi Lashkari, and Ali A. Ghorbani, “Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization”, 4th International Conference on Information Systems Security and Privacy (ICISSP), Portugal, January 2018","description_withheld":null,"homepage":"https://www.unb.ca/cic/datasets/ids-2017.html","introduced_date":null,"introduced_date_note":null,"introduced_by":null,"license":null,"modalities":[],"tasks":[{"name":"Intrusion Detection","url":"/task/intrusion-detection","datasets_with_task":"/datasets/task/intrusion-detection"},{"name":"Network Intrusion Detection","url":"/task/network-intrusion-detection","datasets_with_task":"/datasets/task/network-intrusion-detection"}],"languages":[],"variants":["CICIDS2017"],"data_loaders":[],"num_papers_in_archive":18,"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28"},"benchmarks":[{"leaderboard":"/sota/network-intrusion-detection-on-cicids2017","task":"Network Intrusion Detection","dataset_variant":"CICIDS2017","rows":5,"metrics":["Avg F1","Precision","Recall"],"first_row_in_archive_order":{"model":"OC-SVM / RF","paper":"/paper/a-novel-multi-stage-approach-for-hierarchical","metrics":{"Avg F1":"0.9875","Precision":"99.26","Recall":"98.34"},"code_links":[{"title":"mverkerk/multi-stage-hierarchical-ids","url":"https://gitlab.ilabt.imec.be/mverkerk/multi-stage-hierarchical-ids"}]},"note":"rows are the archive's own order at snapshot; nothing here re-ranks them"},{"leaderboard":"/sota/intrusion-detection-on-cicids2017","task":"Intrusion Detection","dataset_variant":"CICIDS2017","rows":2,"metrics":["Accuracy (%)","F1 Score (Macro Avg)","Precision (Macro Avg)","Recall (Macro Avg)"],"first_row_in_archive_order":{"model":"K-Nearest Neighbors","paper":"/paper/implementing-lightweight-intrusion-detection","metrics":{"Accuracy (%)":"98.07","F1 Score (Macro Avg)":"98.07","Precision (Macro Avg)":"98.08","Recall (Macro Avg)":"98.07"},"code_links":[{"title":"rylandtikes/Lightweight-IDS","url":"https://github.com/rylandtikes/Lightweight-IDS"}]},"note":"rows are the archive's own order at snapshot; nothing here re-ranks them"}],"papers_with_a_benchmark_row":[{"paper":"/paper/implementing-lightweight-intrusion-detection","title":"Implementing Lightweight Intrusion Detection System on Resource Constrained Devices","date":"2024-10-28","rows_on_this_dataset":2,"code_links":1,"syntology":null},{"paper":"/paper/deep-learning-applications-for-intrusion","title":"Deep Learning Applications for Intrusion Detection in Network Traffic","date":"2024-01-13","rows_on_this_dataset":1,"code_links":1,"syntology":null},{"paper":"/paper/a-novel-multi-stage-approach-for-hierarchical","title":"A Novel Multi-Stage Approach for Hierarchical Intrusion Detection","date":"2023-03-21","rows_on_this_dataset":1,"code_links":1,"syntology":null},{"paper":"/paper/an-intrusion-detection-system-based-on-deep","title":"An Intrusion Detection System based on Deep Belief Networks","date":"2022-07-05","rows_on_this_dataset":2,"code_links":1,"syntology":null},{"paper":"/paper/synthesis-of-a-machine-learning-model-for","title":"Synthesis of a Machine Learning Model for Detecting Computer Attacks Based on the CICIDS2017 Dataset","date":"2020-01-01","rows_on_this_dataset":1,"code_links":2,"syntology":null}],"syntology_totals":{"read_at":"2026-09-24T18:15:14+00:00","papers_with_samples":0,"samples_harvested":0,"samples_ran":0,"samples_unverified":0,"pointer_only_for_licence":0,"papers_with_no_sample_that_ran":0,"note":"the per-paper counts above, summed; not a rate"},"papers_note":"The archive never published its papers-using-dataset list; these are papers with a leaderboard row on this dataset's benchmarks."}