The CIRA-CIC-DoHBrw-2020 and DoH-DGA-Malware-Traffic-HKD combined dataset

The "l1-total-malware.csv" contains traffic flows of Non-DoH 897493 and DoH 24019.
The "l2-total-malware.csv" includes traffic flows of Normal DoH 19807 and Suspicious DoH 4212.
The "l3-malware.csv" encloses traffic flows of PadCrypt 840, Sisron 744, Tinba 1808, and Zloader 820.

Note that the file size of the "l3-malware.csv" in this dataset is smaller than the one in the original dataset as a result of being saved by Microsoft Excel. For example, the first FlowBytesSent value is represented as 43859 in this data set, while it is 43859.0000000000 in the original data set.


License

If you use the dataset, please be sure to cite the following papers because the dataset has data from the CIRA-CIC-DoHBrw-2020 [1] and DoH-DGA-Malware-Traffic-HKD [2] datasets.

Mohammadreza MontazeriShatoori, Logan Davidson, Gurdip Kaur, and Arash Habibi Lashkari, "Detection of DoH Tunnels using Time-series Classification of Encrypted Traffic," The 5th IEEE Cyber Science and Technology Congress, Calgary, Canada, August 2020. 
https://ieeexplore.ieee.org/document/9251211

Rikima Mitsuhashi, Yong Jin, Katsuyoshi Iida, Takahiro Shinagawa, and Yoshiaki Takai, "Detection of DGA-based Malware Communications from DoH Traffic Using Machine Learning Analysis," 2023 IEEE 20th Consumer Communications & Networking Conference (CCNC), 2023. 
https://ieeexplore.ieee.org/document/10059835


References

[1] CIRA-CIC-DoHBrw-2020 (https://www.unb.ca/cic/datasets/dohbrw-2020.html)
[2] DoH-DGA-Malware-Traffic-HKD (https://github.com/rikima-mitsuhashi/DoH-DGA-Malware-Traffic-HKD/)


If you have any questions, contact mitsuhashi@os.ecc.u-tokyo.ac.jp.
March 2023.
