Raw network data was collected over a period of 5 days, Monday through Friday, and stored in PCAP files.
Monday was used to create most of the Benign data, while the Attack-Network implemented various types of attacks over the next 4 days,
such as Brute Force connections (FTP and SSH), several types of DoS attacks, as well as a Botnet attack, Infiltration attacks and subsequent Port-Scanning activity.
The PCAP data was processed using a tool developed by one of the authors of [1], called… See the full description on the dataset page:
https://huggingface.co/datasets/bvk/CICIDS-2017.