A Data-Centric Network Traffic Dataset for Anomaly Detection: Construction, Reproducible Pipeline, and Technical Validation

UDC.coleccionInvestigación
UDC.departamentoCiencias da Computación e Tecnoloxías da Información
UDC.grupoInvTelemática
UDC.grupoInvLaboratorio Interdisciplinar de Aplicacións da Intelixencia Artificial (LIA2)
UDC.institutoCentroCITIC - Centro de Investigación de Tecnoloxías da Información e da Comunicación
UDC.issue8
UDC.journalTitleData
UDC.startPage199
UDC.volume11
dc.contributor.authorQuirumbay Yagua, Daniel
dc.contributor.authorFernández, Diego
dc.contributor.authorNóvoa, Francisco
dc.contributor.authorGarabato, D.
dc.date.accessioned2026-09-17T08:51:03Z
dc.date.available2026-09-17T08:51:03Z
dc.date.issued2026
dc.description.abstract[Abstract]: The effectiveness of machine learning and deep learning methods for network anomaly detection depends strongly on the quality and representativeness of the datasets used for training and evaluation. Despite recent advances, many publicly available benchmarks rely on synthetic traffic, outdated attack scenarios, or limited representation of encrypted communications. This work presents a network traffic dataset derived from operational firewall logs collected in a heterogeneous institutional environment dominated by HTTPS/TLS traffic. A structured data-centric pipeline was implemented, including preprocessing, behavioral feature engineering, unsupervised pseudo-labeling through the EFMS–KMeans algorithm, class balancing using SMOTE, and the generation of model-oriented sequential representations for deep learning analysis. The resulting dataset contains large-scale flow-level records describing volumetric, behavioral, and temporal traffic characteristics while preserving privacy through anonymization procedures. Technical validation was conducted using statistical analysis, entropy-based measurements, clustering quality metrics, and dimensionality reduction techniques, confirming data consistency, structural diversity, and class separability. The dataset is publicly available through the Mendeley Data repository together with metadata and documentation supporting anomaly detection research, encrypted traffic analysis, and the evaluation of machine learning and deep learning approaches in realistic cybersecurity environments.
dc.description.sponsorshipThis work was carried out at CITIC within the framework of project PID2023-150794OB-I00, funded by the Ministry of Science, Innovation and Universities (MICIU), the State Research Agency (AEI) (Grant No. 10.13039/501100011033), and co-funded by the European Regional Development Fund (ERDF), European Union. The authors also acknowledge support from the Xunta de Galicia and the European Union (FEDER Galicia 2021–2027 Programme) through grants ED431B 2024/21, ED431B 2024/02, and CITIC ED431G 2023/01. Partial funding was also received through the ERDF EU Interreg VI-A Spain–Portugal (POCTEP) 2021–2027 Programme under the project “Quantum IBER_IA: Impulso estratégico de las capacidades en tecnologías cuánticas e inteligencia artificial en el espacio ibérico transfronterizo”.
dc.description.sponsorshipXunta de Galicia; ED431B 2024/21
dc.description.sponsorshipXunta de Galicia; ED431B 2024/02
dc.description.sponsorshipXunta de Galicia; ED431G 2023/01
dc.description.urihttp://dx.doi.org/10.17632/g5dtm7349f
dc.identifier.citationQuirumbay Yagual, D.; Fernández Iglesias, D.; Nóvoa, F.J.; Garabato, D. A Data-Centric Network Traffic Dataset for Anomaly Detection: Construction, Reproducible Pipeline, and Technical Validation. Data 2026, 11(8), 199. https://doi.org/10.3390/data11080199
dc.identifier.doi10.3390/data11080199
dc.identifier.issn2306-5729
dc.identifier.urihttps://hdl.handle.net/2183/49289
dc.language.isoeng
dc.publisherMDPI
dc.relation.isbasedonThe dataset is publicly available through the Mendeley Data repository
dc.relation.projectIDinfo:eu-repo/grantAgreement/AEI/Plan Estatal de Investigación Científica y Técnica y de Innovación 2021-2023/PID2023-150794OB-I00/ES/MEJORANDO LA DETECCION DE CIBER AMENAZAS USANDO MODELOS DE LENGUAJE DE GRAN TAMAÑO PARA PROTOCOLOS DE RED
dc.relation.urihttps://doi.org/10.3390/data11080199
dc.rightsAttribution 4.0 Internationalen
dc.rights.accessRightsopen access
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/
dc.subjectAnomaly detection
dc.subjectData-centric cybersecurity
dc.subjectEncrypted traffic
dc.subjectNetwork traffic dataset
dc.subjectPseudo-labeling
dc.subjectReproducible pipeline
dc.titleA Data-Centric Network Traffic Dataset for Anomaly Detection: Construction, Reproducible Pipeline, and Technical Validation
dc.typejournal article
dc.type.hasVersionVoR
dspace.entity.typePublication
relation.isAuthorOfPublication9b9fbda3-512a-4143-986b-c7b60305e041
relation.isAuthorOfPublication6f38fb90-68db-4d7c-89e0-8cff7f9d673c
relation.isAuthorOfPublication1a431829-71d0-44aa-a001-8d2984c3b413
relation.isAuthorOfPublication.latestForDiscovery9b9fbda3-512a-4143-986b-c7b60305e041

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
FernandezIglesias_Diego_2026_A_Data_Centric_Network_Traffic_Dataset.pdf
Size:
2.05 MB
Format:
Adobe Portable Document Format