ReadMe CTU13.zip file contains: ReadMe.txt CTU-13-Dataset.tar Folders 1 through 13 botnet-capture. . . .pcap capture. . . binetflow .exe readme The CTU-13 dataset consist of a group of 13 different malware captures done in a real network environment. The captures include Botnet, Normal, and Background traffic. The Botnet traffic comes from the infected hosts, the Normal traffic from the verified normal hosts, and the Background traffic is all the rest of traffic. The dataset is labeled in a flow by flow basis, consisting in one of the largest and more labeled botnet datasets available. Date range of data: Aug 10, 2011 through Aug 15, 2011 Additional information available at: http://mcfp.weebly.com/the-ctu-13-dataset-a-labeled-dataset-with-botnet-normal-and-background-traffic.html How to cite this dataset Author(s): Sebastian Garcia, Martin Grill, and Honza Stiborek Title: CTF-13 Dataset: A Labeled Dataset with Botnet, Normal and Background Traffic Publisher: University of Arizona Artificial Intelligence Lab, AZSecure-data, Director Hsinchun Chen Location: [AZSecure-data has not yet implemented Digital Object Identifiers or Persistent URLs, please copy and paste the location where you retrieve this file from within http://www.azsecure-data.org/] Publication date: June 3, 2016 ALSO CITE: "An empirical comparison of botnet detection methods" Sebastian Garcia, Martin Grill, Honza Stiborek and Alejandro Zunino. Computers and Security Journal, Elsevier. 2014. Vol 45, pp 100-123. http://dx.doi.org/10.1016/j.cose.2014.05.011 IEEE formatted data citation: S. Garcia, M. Grill, H. Stiborek. CTF-13 Dataset: A Labeled Dataset with Botnet, Normal and Background Traffic. University of Arizona Artificial Intelligence Lab, AZSecure-data, Director Hsinchun Chen. Available http://www.azsecure-data.org/ [3 June 2016]