arXiv ScienceSearch

arXiv · 2601.05813

Descriptor: Multi-Regional Cloud Honeypot Dataset (MURHCAD)

Abstract

This data article introduces a comprehensive, high-resolution honeynet dataset designed to support standalone analyses of global cyberattack behaviors. Collected over a continuous 72-hour window (June 9 to 11, 2025) on Microsoft Azure, the dataset comprises 132,425 individual attack events captured by three honeypots (Cowrie, Dionaea, and SentryPeer) deployed across four geographically dispersed virtual machines. Each event record includes enriched metadata (UTC timestamps, source/destination IPs, autonomous system and organizational mappings, geolocation coordinates, targeted ports, and honeypot identifiers alongside derived temporal features and standardized protocol classifications). We provide actionable guidance for researchers seeking to leverage this dataset in anomaly detection, protocol-misuse studies, threat intelligence, and defensive policy design. Descriptive statistics highlight significant skew: 2,438 unique source IPs span 95 countries, yet the top 1% of IPs account for 1% of all events, and three protocols dominate: Session Initiation Protocol (SIP), Telnet, Server Message Block (SMB). Temporal analysis uncovers pronounced rush-hour peaks at 07:00 and 23:00 UTC, interspersed with maintenance-induced gaps that reveal operational blind spots. Geospatial mapping further underscores platform-specific biases: SentryPeer captures concentrated SIP floods in North America and Southeast Asia, Cowrie logs Telnet/SSH scans predominantly from Western Europe and the U.S., and Dionaea records SMB exploits around European nodes. By combining fine-grained temporal resolution with rich, contextual geolocation and protocol metadata, this standalone dataset aims to empower reproducible, cloud-scale investigations into evolving cyber threats. Accompanying analysis code and data access details are provided.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Enrique Feito-Casares, Ismael Gómez-Talal, José-Luis Rojo-Álvarez. 2026-01-09. Descriptor: Multi-Regional Cloud Honeypot Dataset (MURHCAD). https://doi.org/10.1109/ieeedata.2026.3687845

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Access Paths for Efficient Ordering with Large Language Models

In this work, we present the \texttt{LLM ORDER BY} semantic operator as a logical abstraction and conduct a systematic study of its physical implementations. First, we propose several improvements to existing semantic sorting algorithms and introduce a semantic-aware external merge sort algorithm. Our extensive evaluation reveals that no single implementation offers universal optimality on all datasets. From our evaluations, we observe a general scaling relationship between sorting cost and the ordering quality for comparison-based algorithms. Building on these insights, we design a budget-aware optimizer that utilizes heuristic rules, LLM-as-Judge evaluation, and consensus aggregation to dynamically select the near-optimal access path for LLM ORDER BY. In our extensive evaluations, our optimizer consistently achieves ranking accuracy on par with or superior to the best static methods across all benchmarks. We believe that this work provides foundational insights into the principled optimization of semantic operators essential for building robust, large-scale LLM-powered analytic systems.

cs.DB

Expressive Power of Property Graph Constraint Languages

We present the first principled and systematic study of the expressive power of property graph constraint languages, focused on the recent PG-Keys language, set to inform the upcoming revision of the GQL standard. To this end, we position PG-Keys within the broader landscape of existing formalisms. In particular, we compare PG-Keys with two core property graph constraint languages: Graph Functional Dependencies (GFD) and Graph Generating Dependencies (GGD). One hurdle is that these formalisms allow different kinds of graph pattern languages and data predicates. To make a fair comparison, based on their structural differences only, we first present a unifying framework. Within this framework, we consider conjunctive regular path queries (CRPQ) as graph patterns with equality and inequality predicates. We then identify well-behaved fragments, establish expressiveness inclusion, and prove separation results, yielding a complete and strict hierarchy of expressive power. The results identify precisely when PG-Keys provide strictly greater expressive power, clarifying their place among state-of-the-art property graph constraint formalisms.

cs.DB

Answering Conjunctive Queries with Aggregations under Updates

Dynamic query processing keeps query answers up to date during insertions and deletions. For conjunctive queries (CQs) under set semantics, the classes maintainable in constant amortized time are known exactly: the $q$-hierarchical CQs under arbitrary updates, and the free-connex CQs under insertion-only updates. Many analytics tasks, including \textsf{SUM}/\textsf{COUNT} aggregations, provenance, and access control, are captured by evaluating a CQ over a positive commutative semiring. We thus ask whether aggregation changes what can be maintained efficiently, and if so, when. Under \emph{insertion-only} updates, it does: the boundary retreats from free-connex to a new class we call \emph{strong-connex}, with $q\text{-hierarchical} \subsetneq \text{strong-connex} \subsetneq \text{free-connex} \subsetneq \text{acyclic}$. For every \emph{strictly monotone} semiring, including the sum-product and tropical semirings, no free-connex but non-strong-connex CQ is maintainable in $O(|D|^{1/2-ε})$ time under the OuMv and OMv conjectures, whereas every strong-connex CQ is maintainable in $O(1)$ amortized time over every semiring. Under \emph{arbitrary} updates, the boundary stays at the $q$-hierarchical CQs for every semiring with $O(1)$-deletable aggregates, and maintenance over any semiring is at least as hard as over the Boolean semiring. We further strengthen the lower bounds to semirings that fall outside the class and to query with different \emph{height} and \emph{dimension}, under the combinatorial $k$-clique and generalized OuMv conjectures. All upper bounds come from a single framework, obtained by adapting CROWN to annotated relations; together with the lower bounds, they yield dichotomies parameterized by both the query and the semiring, recovering the Boolean results as a special case.

cs.DB