IoT Lab Capture
- Description:
- Model: Edimax IC-7113W
- Duration:
Description of Files
- .capinfos
- .dnstop
- mitm.out
- Mitm proxy interception file of http and https
- .mitm.weblog
- This is the HTTP and HTTPS web log that includes Labels. This is the preferred file for web analysis.
- This file includes a header with the columns names. There are two new columns defined by us:
- Column id: This number is unique for all the weblogs generated inside the same TCP connection. When a TCP connection is opened and several GET/POST, etc., requests are made inside it, all of them are assigned the same Id in this file.
- Column timestamp_end: This is the timestamp when the weblog ended. If you use this with the id column you can compute the total duration of the TCP connection that generated all the weblogs. Similar to the duration of a hypothetical CONNECT request if this would have been done using a proxy.
- .passivedns
- .pcap
- .rrd
- .weblogng
- WEB log of http traffic only. Generated with justsniffer
- .exe.zip
- bro
- Folder with all the bro output files
- .biargus
- Argus binary file. Bidirectional flows, 3600s of report time.
- .binetflow
- Argus text file with bidirectional flows. Report time 3600 secs.
- .uniargus
- Argus binary file. Unidirectional flows, 5s of report time.
- .uninetflow
- Argus text file with unidirectional flows. Report time 5 secs. TAB as column separator.
IP Addresses
- Infected device: 192.168.100.109
- Default GW: 192.168.100.1
Generic Dataset name: CTU-Honeypot-Capture-2
Origin device: IP camera 1
Timeline
Start. 2018/05/21
Mon May 21 14:16:37 CEST 2018
The port redirection was not working for the last couple of days. The rule was applied again, and now the port redirection works well, just remember the limited bandwidth.
Thu Jul 12 12:12 CEST 2018
Sniffing computer went off due to maintenance.
Thu Jul 12 12:54:16 CEST 2018
Sniffing computer is back on.
Thu Jul 12 14:26:13 CEST 2018
Capturing traffic is working again.
Sat Jul 14 08:22 CEST 2018
Electricity outage at the building.
Sat Jul 14 09:41:12 CEST 2018
Electricity is back on, capturing started again.
Wed Jul 18 11:47:47 CEST 2018
Reboot of the sniffing computer.
Wed Jul 18 11:53:46 CEST 2018
Reboot of the sniffing computer.
Thu Jul 26 14:53:58 CEST 2018
Camera disconnected.
Tue Jul 31 10:24:53 CEST 2018
Camera connected again.
Fri Aug 10 14:19:56 CEST 2018
Camera maintenance from IP 147.32.217.200
Mon Sep 10 08:01 CEST 2018
Electricity outage at the university building.
Thu Oct 18 CEST 2018
Configuration of the lab infrastructure.
Disclaimer
These files were generated in the Stratosphere Laboratory as part of the Aposemat Project for collecting IoT malware captures Done in the CVUT University, Prague, Czech Republic. The goal is to store long-lived real iot malware traffic and to generate labeled netflows files. Any question feel free to contact us at: Sebastian Garcia: sebastian.garcia@agents.fel.cvut.cz
You need authorization from the Stratosphere Lab to use these files.
Suricata run with rules updated on 2021-03-06