•  
  •  
 

Turkish Journal of Electrical Engineering and Computer Sciences

Author ORCID Identifier

ARSHAD IQBAL: 0000-0002-9630-0918

SOHAIL ASGHAR: 0000-0001-6883-3584

Abstract

The efficacy of artificial intelligence (AI) in intrusion detection systems (IDS) is critically dependent on high-fidelity training data. However, as detailed in the manuscript's literature review, existing benchmark datasets are predominantly synthetic, outdated, or imbalanced and fail to capture the complexity of the contemporary threat landscape. To bridge this gap, this study introduces CUIP-X25, a novel real-world cyber-attack dataset captured over a four-month period using a dionaea honeypot deployed on a public network. Unlike synthetic alternatives, this dataset provides an authentic representation of modern adversarial tactics, techniques, and procedures, encompassing 3.16 million real events across ten distinct attack categories, including IoT-targeted exploits, malware injections, and brute-force attacks. To address class imbalance in AI model training, SMOTE was applied to create a balanced training dataset, yielding 4.57 million records. This study comprehensively details the data collection methodology, rigorous preprocessing pipeline, and heuristic-based algorithm for attack categorization, resulting in a cleaned dataset of 65 fully populated features. The dataset's validity was demonstrated through extensive statistical profiling, visualization, and experimental evaluation. Training random forest and hybrid CNN-LSTM models on CUIP-X25 achieved detection accuracies of 98.14% and 98.57%, respectively which are comparable to benchmark datasets. CUIP-X25 corpus is published in multiple formats, including raw SQLite log file, malware binaries, raw CSV files, original unbalanced dataset, and SMOTE-balanced dataset to support diverse research needs. By offering a realistic, validated, and publicly available benchmark, CUIP-X25 serves as an essential resource for developing next-generation AI-driven cybersecurity defenses.

DOI

10.55730/1300-0632.4278

Keywords

Real-world dataset, intrusion detection system, honeypot, dionaea, CUIP-X25, IoT security

First Page

833

Last Page

854

Publisher

The Scientific and Technological Research Council of Türkiye (TÜBİTAK)

Creative Commons License

Creative Commons Attribution 4.0 International License
This work is licensed under a Creative Commons Attribution 4.0 International License.

Share

COinS