Real-Time DNS Monitoring and Bandwidth Enforcement Logs for Machine Learning–Based Network Security Experiments
Description
This dataset contains network monitoring logs generated during real-time experiments evaluating a machine-learning-based malicious domain detection and dynamic bandwidth enforcement system. The system monitors DNS traffic, classifies accessed domains using a trained machine-learning model, and dynamically applies bandwidth-control policies to users accessing malicious domains. The dataset includes three types of logs: • User access logs recording domain access events, classification results, and bandwidth adjustments. • Penalty enforcement logs documenting bandwidth penalties applied to users accessing malicious domains. • Bandwidth change logs track bandwidth allocation changes during the experiment. The logs were collected during a controlled network experiment involving multiple concurrent users over a five-hour period. These data support the reproducibility of experiments related to DNS monitoring, automated bandwidth control, and machine-learning-assisted network security systems.
Files
Steps to reproduce
1. A controlled local network environment was configured using a Mikrotik RouterOS-based gateway. 2. DNS traffic generated by multiple users was continuously monitored by the proposed monitoring system. 3. Accessed domain names were analyzed using a trained machine learning classifier based on TF–IDF feature extraction and a linear Support Vector Machine model. 4. When a domain was classified as malicious (e.g., gambling, phishing, or pornography), the system triggered a bandwidth enforcement policy through the Mikrotik RouterOS API. 5. The system dynamically reduced the user's bandwidth allocation as a penalty and restored it after a predefined recovery interval. 6. All domain access events, bandwidth changes, and penalty actions were recorded as logs and exported into CSV files.
Institutions
- Universitas Bung HattaWest Sumatra, Padang