CTU Hornet 65 Niner is a dataset of 65 days of network traffic attacks captured in cloud servers used as honeypots to help understand how geography may impact the inflow of network attacks. The honeypots were placed in nine different geographical locations: Amsterdam, London, Frankfurt, San Francisco, New York, Singapore, Toronto, Bangalore, and Sydney. The data was captured from April 28th to July 1st, 2024.
The nine cloud servers were created and configured following identical instructions using Ansible [1] in DigitalOcean [2] cloud provider. The network capture was performed using the Zeek [3] network monitoring tool, which was installed oneach cloud server. The cloud servers had only one service running (SSH on a non-standard port) and were fully dedicated to being used as a honeypot. No honeypot software was used in this dataset.
The dataset is composed of nine scenarios:
Administration IPs: 88.103.231.202
Administration Port: 902
Instance OS: Ubuntu 23.10 x64
Instance Capacity: 1GB / 1 Intel CPU
Instance Storage: 25 GB NVMe SSDs
Instance Transfer: 1000 GB transfer
Honeypot | City | Region | IPv4 | Public IPv4 Gateway | Private IPv4 | IPv6 | Public IPv6 Gateway |
---|---|---|---|---|---|---|---|
Honeypot-Cloud-DigitalOcean-Geo-1 | Amsterdam | Europe | 104.248.195.152 | 104.248.192.1 | 10.110.0.2 | 2a03:b0c0:2:d0::11ae:1 | 2a03:b0c0:2:d0::1 |
Honeypot-Cloud-DigitalOcean-Geo-2 | Bangalore | Asia | 165.22.222.201 | 165.22.208.1 | 10.122.0.3 | 2400:6180:100:d0::993:c001 | 2400:6180:100:d0::1 |
Honeypot-Cloud-DigitalOcean-Geo-3 | Frankfurt | Europe | 209.38.234.36 | 209.38.224.1 | 10.135.0.2 | 2a03:b0c0:3:d0::123c:e001 | 2a03:b0c0:3:d0::1 |
Honeypot-Cloud-DigitalOcean-Geo-4 | London | Europe | 165.232.34.90 | 165.232.32.1 | 10.106.0.2 | 2a03:b0c0:1:d0::1114:9001 | 2a03:b0c0:1:d0::1 |
Honeypot-Cloud-DigitalOcean-Geo-5 | New York | North America | 165.22.2.102 | 165.22.0.1 | 10.116.0.2 | 2604:a880:400:d0::1edd:8001 | 2604:a880:400:d0::1 |
Honeypot-Cloud-DigitalOcean-Geo-6 | San Francisco | North America | 64.23.252.8 | 64.23.240.1 | 10.124.0.2 | 2604:a880:4:1d0::219:3000 | 2604:a880:4:1d0::1 |
Honeypot-Cloud-DigitalOcean-Geo-7 | Singapore | Asia | 152.42.255.26 | 152.42.240.1 | 10.104.0.2 | 2400:6180:0:d0::41:e001 | 2400:6180:0:d0::1 |
Honeypot-Cloud-DigitalOcean-Geo-8 | Toronto | North America | 147.182.157.27 | 147.182.144.1 | 10.118.0.2 | 2604:a880:cad:d0::d8b:d001 | 2604:a880:cad:d0::1 |
Honeypot-Cloud-DigitalOcean-Geo-9 | Sydney | Oceania | 170.64.225.155 | 170.64.224.1 | 10.126.0.2 | 2400:6180:10:200::132:5000 | 2400:6180:10:200::1 |
To cite this work: Valeros, Veronica; Garcia, Sebastian (2024), “CTU Hornet 65 Niner: A Network Dataset of Geographically Distributed Low-Interaction Honeypots”, Mendeley Data, V1, doi: 10.17632/nt4p9zsv5k.1
This dataset used cloud server instances from Digital Ocean. For this dataset, all cloud servers have the same technical configurations: a) Operating System: Ubuntu 23.10 x64, b) Instance Capacity: 1GB / 1 Intel CPU, c) Instance Storage: 25 GB NVMe SSDs, d) Instance Transfer: 1000 GB transfer.
The servers were created and configured using Ansible [1]: