This is our old Q&A Site. Please post any new questions and answers at

I am going to make a dataset such as KDDCup99 for machine learning purposes, but I don't know how can i extract intrinsic and time-based attributes from wireshark analyzer!! KDDCup99 introduces 43 attributes (intrinsic, time-based and host-based attributes), and I am going to extract this attributes from wireshark analyzer. How can i do it?

asked 02 Oct '12, 23:49

Bluebit's gravatar image

accept rate: 0%

edited 02 Oct '12, 23:51

You might like to consider also. This is a more recent unlabelled IDS dataset with more sophisticated attacks than the (as I look at it now) outdated KDDCup99.

(28 Feb '13, 20:17) pds

Jaap is mostly right.

One option is to:

  • Use tshark to log packet data to CSV format.
  • Post process that dataset to produce the 'connection' and 'two-second time window' attribute sets.
  • Do some other logging to get 'root_shell','su_attempted', etc attributes. (In Linux: history, last/lastb and /var/log/secure may help.)

A second option, if you need KDDCup99 data fields collected in real-time is to:

  • download the Wireshark source code: SVN Repo
  • hand-code the collection and processing in real-time using *shark's pre-parsed protocol fields in C;
  • then print to file using CSV file format.

The following should help in producing the CSV output from tshark CLI to 'logfile.csv':

-i <interface> 
-w logfile.pcap
-c 100
-T fields
-E header=y -E separator=, -E quote=d -E occurrence=f
-e ip.src -e ip.dst -e ip.proto -e ip.checksum -e tcp.srcport -e tcp.dstport
> logfile.csv

Use Wireshark's packet header browser/details panel to choose which attributes you want to log, then add those attributes to the -e arguments list.

permanent link

answered 18 Dec '12, 10:03

pds's gravatar image

accept rate: 100%

edited 12 Feb '13, 11:43

hey Friends too working on kdd99cup query is "how to trim (cut) data-set in 10% kdd99 cup...what are the factors we need to consider while trimming data"....kindly help me with algorithm or code to cut the data-set in to 10% of original...thanks

(28 Feb '13, 19:32) sac

Tshark and post process the text output?

permanent link

answered 03 Oct '12, 02:16

Jaap's gravatar image

Jaap ♦
accept rate: 14%

your comment is not clear for me!

(03 Oct '12, 04:02) Bluebit
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 02 Oct '12, 23:49

question was seen: 6,085 times

last updated: 01 Mar '13, 02:32

p​o​w​e​r​e​d by O​S​Q​A