Annotated Encrypted Network Traffic Dataset for Application, OS, and Malware Identification
Authors/Creators
Description
This dataset provides an annotated collection of encrypted network communication intended for research on application identification, operating system fingerprinting, and malware detection in encrypted traffic. It combines network traffic captured in controlled sandbox environments executing selected Windows applications with malware-related communication obtained from automated malware analysis reports. In addition to application and malware traffic, the dataset includes background operating system communication generated by the capture environment, enabling comprehensive and realistic modeling of host behavior.
The dataset is publicly provided as Apache Parquet files containing preprocessed representations of the raw network traffic. The underlying raw packet capture data (PCAP files) are not publicly distributed but are available upon justified request. The Parquet files include extracted features and structured annotations suitable for direct use in data analysis and machine learning workflows.
The format and structure of the Parquet files, including field definitions and annotation schemas, are documented in the accompanying README.md file. The dataset is versioned and designed to be incrementally extended with additional applications, operating systems, and malware samples, supporting reproducible research and long-term reuse in encrypted traffic analysis and network security studies.
Technical info (En)
Version 1.0.0 contains an initial set of data files.
This dataset is organized into three complementary collections.
-
SOHO traffic, capturing real-world TLS flows from a small-office/home-office network with diverse devices and applications. This collection contains 108,036 TLS connections stored in 104 Parquet files (≈ 12.8 MB) and covers the period 2024-07-16 to 2024-11-22.
-
Malware traffic, consisting of TLS connections generated during sandboxed execution of malware and benign samples, with ground-truth labels such as malware family, severity, and sandbox operating system. It includes 828,171 TLS connections across 916 Parquet files (≈ 63.4 MB), collected between 2025-09-10 and 2025-09-30.
-
Windows applications traffic, containing TLS connections from controlled executions of known Windows applications in a sandbox environment, with application-level ground truth. This collection comprises 29,526 TLS connections in 5,892 Parquet files (≈ 63.2 MB) and spans 2025-09-26 to 2025-10-01.
Files
Readme.md
Files
(74.4 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:d23d01a273cbc796c70946cdda6a6662
|
3.1 kB | Preview Download |
|
md5:258d1a042e80f3c85bb361ec3cb03a07
|
43.2 MB | Preview Download |
|
md5:16c1783e3dd45611c7c15b89101c602d
|
4.8 kB | Preview Download |
|
md5:e8b8317b480958daf10f2a51680be4d8
|
10.1 MB | Preview Download |
|
md5:c43fba63b45848ba9846d29ac712d383
|
21.1 MB | Preview Download |
Additional details
Funding
- Technology Agency of the Czech Republic
- Privacy-respecting Explainable Assessment and Collection of Threats TM05000014
Software
- Repository URL
- https://github.com/rysavy-ondrej/AutoFedProfile
- Programming language
- Python , Jupyter Notebook
- Development Status
- Active