AttackZoo: A Reproducible Testbed for Attack Execution and Network Traffic Dataset Generation

Resumo


The recurring generation of network traffic datasets for cybersecurity research is constrained by fragmented experimental workflows, limited reproducibility, and restricted coverage of attack vectors. We present AttackZoo, a reproducible testbed that integrates a containerized repository of 60 attacks categorized according to the MITRE ATT&CK framework and an orchestration layer that centers on a command-line interface (CLI) and automates the full cycle of execution, data collection, and consolidation. The pipeline incorporates traffic capture, log inspection, and feature extraction using multiple tools, producing structured and traceable datasets. In the released campaign, AttackZoo executed all 60 attacks across four execution levels and five repetitions, producing 1200 packet captures and 220.4 GB of derived datasets from 672.1 GB of raw traffic. Overall, the catalog covers 35 MITRE ATT&CK technique/sub-technique entries and 9 tactics, while the orchestration layer reduces the operational overhead of experiments and enables the systematic generation of comparable datasets, with all artifacts openly available.

Referências

Ahmad, R., Alsmadi, I., Alhamdani, W., and Tawalbeh, L. (2023). Zero-day attack detection: a systematic literature review. Artificial Intelligence Review, 56(10).

Bernieri, G., Etchevés Miciolino, E., Pascucci, F., and Setola, R. (2017). Monitoring system reaction in cyber-physical testbed under cyber-attacks. Computers & Electrical Engineering, 59:86–98.

Bragança, H., Kreutz, D., Rocha, V., Assolin, J., and Feitosa, E. (2026). MH-1M: A 1.34 million-sample multi-feature Android malware dataset with rich metadata. Scientific Data, 13(1):153.

Brito, I., Pinheiro, T., Santos, M., Santos, R., Gomes, G., Sampaio, H., Freitas, A., and Sampaio, L. (2025). HackInSDN: Uma arquitetura flexível, incremental e portável para experimentação em cibersegurança. In XLIII SBRC, pages 882–895.

Croft, R., Babar, M. A., and Kholoosi, M. M. (2023). Data quality for software vulnerability datasets. In ICSE, pages 121–133.

Dhanapal, A. and Nithyanandam, P. (2021). An OpenStack based cloud testbed framework for evaluating HTTP flooding attacks. Wireless Networks, 27(8):5491–5501.

Fideles, D. R., Lautert, D. P., Kreutz, D., and Quincozes, S. E. (2025). VulnSyncAI: PLN e LLMs para construção e atualização contínua de datasets de vulnerabilidades. In XLIII SBRC.

Freitas, A. V., Araújo Júnior, S. R. d., and Silva, H. (2024). MQTT-VET: Exploring MQTT protocol vulnerabilities. In LADC (Anais Estendidos), page 111–113.

Guo, Y., Bettaieb, S., and Casino, F. (2024). A comprehensive analysis on software vulnerability detection datasets: trends, challenges, and road ahead. International Journal of Information Security, 23(5):3311–3327.

Huang, H., Wlazlo, P., Sahu, A., Walker, A., Goulart, A. E., Davis, K. R., Swiler, L., Tarman, T. D., and Vugrin, E. (2024). Validating an emulation-based cybersecurity model with a physical testbed. IEEE Transactions on Dependable and Secure Computing.

Katuri, K., Park, S.-Y., Zuo, S., Miao, F., and Zhao, J. (2024). Demonstration of DoS attacks on Modbus protocol using an experimental CPS testbed. In NAPS, pages 1–6.

Kouril, D., Rebok, T., Jirsik, T., Cegan, J., Drasar, M., Vizvary, M., and Vykopal, J. (2014). Cloud-based testbed for simulation of cyber attacks. In NOMS, pages 1–6.

Kraust, S., Heller, P., and Mottok, J. (2025). Concept for designing an ICS testbed from a penetration testing perspective. In EuroS&PW, pages 561–568.

Polák, M., Sedlák, D., Fesl, J., and Tvrdík, P. (2024). Real data center network traffic dataset and analysis. In CloudNet, pages 1–5.

Prates Jr., N. G., Andrade, A. M., Mello, E. R. d., Wangham, M. S., and Nogueira, M. (2021). Um ambiente de experimentação em cibersegurança para Internet das Coisas. In Anais do VI Workshop do testbed FIBRE, pages 68–79.

Shafi, M., Lashkari, A. H., and Roudsari, A. H. (2025). NTLFlowLyzer: Towards generating an intrusion detection dataset and intruders behavior profiling through network and transport layers traffic analysis and pattern extraction. Computers & Security.

Siboni, S., Sachidananda, V., Meidan, Y., Bohadana, M., Mathov, Y., Bhairav, S., Shabtai, A., and Elovici, Y. (2019). Security testbed for Internet-of-Things devices. IEEE Transactions on Reliability, 68(1):23–44.

Soares, T., Mello, J., Barcellos, L., Sayyed, R., Siqueira, G., Casola, K., Costa, E., Gustavo, N., Feitosa, E., and Kreutz, D. (2021). Detecção de malwares Android: Levantamento empírico da disponibilidade e da atualização das fontes de dados. In ERRC.

Sáez-de Cámara, X., Flores, J. L., Arellano, C., Urbieta, A., and Zurutuza, U. (2024). Gotham testbed: A reproducible IoT testbed for security experiments and dataset generation. IEEE Transactions on Dependable and Secure Computing, 21(1):186–203.

Whang, S. E., Roh, Y., Song, H., and Lee, J.-G. (2023). Data collection and quality challenges in deep learning: a data-centric AI perspective. The VLDB Journal, 32(4).

Wlazlo, P., Sahu, A., Mao, Z., Huang, H., Goulart, A., Davis, K., and Zonouz, S. (2021). Man-in-the-middle attacks and defence in a power system cyber-physical testbed. IET Cyber-Physical Systems: Theory & Applications.

Yang, Z., Liu, X., Li, T., Wu, D., Wang, J., Zhao, Y., and Han, H. (2022). A systematic literature review of methods and datasets for anomaly-based network intrusion detection. Computers & Security, 116:102675.
Publicado
01/09/2026
BITZKI, Leonardo; KREUTZ, Diego; BERTHOLDO, Leandro; KAPELINSKI, Cristhian. AttackZoo: A Reproducible Testbed for Attack Execution and Network Traffic Dataset Generation. In: SALÃO DE FERRAMENTAS - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 109-118. DOI: https://doi.org/10.5753/sbseg_estendido.2026.33492.

Artigos mais lidos do(s) mesmo(s) autor(es)

<< < 1 2 3 4 5 6 7 8 9 10 > >>