A Data-Centric Network Traffic Dataset for Anomaly Detection: Construction, Reproducible Pipeline, and Technical Validation
| UDC.coleccion | Investigación | |
| UDC.departamento | Ciencias da Computación e Tecnoloxías da Información | |
| UDC.grupoInv | Telemática | |
| UDC.grupoInv | Laboratorio Interdisciplinar de Aplicacións da Intelixencia Artificial (LIA2) | |
| UDC.institutoCentro | CITIC - Centro de Investigación de Tecnoloxías da Información e da Comunicación | |
| UDC.issue | 8 | |
| UDC.journalTitle | Data | |
| UDC.startPage | 199 | |
| UDC.volume | 11 | |
| dc.contributor.author | Quirumbay Yagua, Daniel | |
| dc.contributor.author | Fernández, Diego | |
| dc.contributor.author | Nóvoa, Francisco | |
| dc.contributor.author | Garabato, D. | |
| dc.date.accessioned | 2026-09-17T08:51:03Z | |
| dc.date.available | 2026-09-17T08:51:03Z | |
| dc.date.issued | 2026 | |
| dc.description.abstract | [Abstract]: The effectiveness of machine learning and deep learning methods for network anomaly detection depends strongly on the quality and representativeness of the datasets used for training and evaluation. Despite recent advances, many publicly available benchmarks rely on synthetic traffic, outdated attack scenarios, or limited representation of encrypted communications. This work presents a network traffic dataset derived from operational firewall logs collected in a heterogeneous institutional environment dominated by HTTPS/TLS traffic. A structured data-centric pipeline was implemented, including preprocessing, behavioral feature engineering, unsupervised pseudo-labeling through the EFMS–KMeans algorithm, class balancing using SMOTE, and the generation of model-oriented sequential representations for deep learning analysis. The resulting dataset contains large-scale flow-level records describing volumetric, behavioral, and temporal traffic characteristics while preserving privacy through anonymization procedures. Technical validation was conducted using statistical analysis, entropy-based measurements, clustering quality metrics, and dimensionality reduction techniques, confirming data consistency, structural diversity, and class separability. The dataset is publicly available through the Mendeley Data repository together with metadata and documentation supporting anomaly detection research, encrypted traffic analysis, and the evaluation of machine learning and deep learning approaches in realistic cybersecurity environments. | |
| dc.description.sponsorship | This work was carried out at CITIC within the framework of project PID2023-150794OB-I00, funded by the Ministry of Science, Innovation and Universities (MICIU), the State Research Agency (AEI) (Grant No. 10.13039/501100011033), and co-funded by the European Regional Development Fund (ERDF), European Union. The authors also acknowledge support from the Xunta de Galicia and the European Union (FEDER Galicia 2021–2027 Programme) through grants ED431B 2024/21, ED431B 2024/02, and CITIC ED431G 2023/01. Partial funding was also received through the ERDF EU Interreg VI-A Spain–Portugal (POCTEP) 2021–2027 Programme under the project “Quantum IBER_IA: Impulso estratégico de las capacidades en tecnologías cuánticas e inteligencia artificial en el espacio ibérico transfronterizo”. | |
| dc.description.sponsorship | Xunta de Galicia; ED431B 2024/21 | |
| dc.description.sponsorship | Xunta de Galicia; ED431B 2024/02 | |
| dc.description.sponsorship | Xunta de Galicia; ED431G 2023/01 | |
| dc.description.uri | http://dx.doi.org/10.17632/g5dtm7349f | |
| dc.identifier.citation | Quirumbay Yagual, D.; Fernández Iglesias, D.; Nóvoa, F.J.; Garabato, D. A Data-Centric Network Traffic Dataset for Anomaly Detection: Construction, Reproducible Pipeline, and Technical Validation. Data 2026, 11(8), 199. https://doi.org/10.3390/data11080199 | |
| dc.identifier.doi | 10.3390/data11080199 | |
| dc.identifier.issn | 2306-5729 | |
| dc.identifier.uri | https://hdl.handle.net/2183/49289 | |
| dc.language.iso | eng | |
| dc.publisher | MDPI | |
| dc.relation.isbasedon | The dataset is publicly available through the Mendeley Data repository | |
| dc.relation.projectID | info:eu-repo/grantAgreement/AEI/Plan Estatal de Investigación Científica y Técnica y de Innovación 2021-2023/PID2023-150794OB-I00/ES/MEJORANDO LA DETECCION DE CIBER AMENAZAS USANDO MODELOS DE LENGUAJE DE GRAN TAMAÑO PARA PROTOCOLOS DE RED | |
| dc.relation.uri | https://doi.org/10.3390/data11080199 | |
| dc.rights | Attribution 4.0 International | en |
| dc.rights.accessRights | open access | |
| dc.rights.uri | http://creativecommons.org/licenses/by/4.0/ | |
| dc.subject | Anomaly detection | |
| dc.subject | Data-centric cybersecurity | |
| dc.subject | Encrypted traffic | |
| dc.subject | Network traffic dataset | |
| dc.subject | Pseudo-labeling | |
| dc.subject | Reproducible pipeline | |
| dc.title | A Data-Centric Network Traffic Dataset for Anomaly Detection: Construction, Reproducible Pipeline, and Technical Validation | |
| dc.type | journal article | |
| dc.type.hasVersion | VoR | |
| dspace.entity.type | Publication | |
| relation.isAuthorOfPublication | 9b9fbda3-512a-4143-986b-c7b60305e041 | |
| relation.isAuthorOfPublication | 6f38fb90-68db-4d7c-89e0-8cff7f9d673c | |
| relation.isAuthorOfPublication | 1a431829-71d0-44aa-a001-8d2984c3b413 | |
| relation.isAuthorOfPublication.latestForDiscovery | 9b9fbda3-512a-4143-986b-c7b60305e041 |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- FernandezIglesias_Diego_2026_A_Data_Centric_Network_Traffic_Dataset.pdf
- Size:
- 2.05 MB
- Format:
- Adobe Portable Document Format

