SigNet-10: Signal-Level Network Traffic Dataset

Published: 24 March 2026| Version 1 | DOI: 10.17632/vcbmwf7s4w.1
Contributors:
,
,

Description

This dataset, named SigNet-10, was developed to support research on network traffic classification using raw electrical signals captured at the physical layer. The core hypothesis behind this work is that different types of network traffic exhibit distinguishable patterns in their physical-layer waveforms due to variations in frame structure. The dataset contains Ethernet frame signals corresponding to ten widely used protocol types: DHCP, DNS, FTP-Data, HTTP, ICMP, NBNS, RTP, RTSP, SMB, and TLS. All data were collected in accordance with the 10Base-T Ethernet standard and are intended for research on signal-level network traffic classification. To construct the dataset, protocol-specific packet capture (PCAP) files were collected from various sources. These files were then retransmitted over a 10Base-T Ethernet link, and the corresponding electrical signals were captured from the Ethernet cable using an oscilloscope. In total, 12,916 unique signal samples (representing individual Ethernet frames) were extracted. In addition to the raw signal files (provided in .csv format), the dataset also includes the original PCAP files used during acquisition. This dataset can be used for signal-based network traffic classification, physical-layer analysis, and deep learning research. It offers a novel perspective on traffic analysis beyond conventional packet- or flow-level features.

Files

Steps to reproduce

Packets were captured by selecting various network interfaces through the web-based management interface of the Bitlis Eren University (BEU) firewall. For traffic that did not traverse the firewall, packet capture was performed using Wireshark on personal computers, with port mirroring configured on the relevant network switches. To increase protocol and user diversity, additional data were collected by accessing public FTP servers and by downloading traffic from platforms such as CloudShark and GitHub. All protocol-specific traffic was saved in .pcap format. The collected .pcap files were processed in MATLAB for deduplication and segmented based on the storage capacity of the oscilloscope. These segments were then replayed over a 10Base-T Ethernet link using Bit-Twist. A differential probe connected to a Tektronix MDO4104-6 oscilloscope with a DPO4ENET module was used to capture the raw electrical signals during transmission. Ethernet frames were decoded via the DPO4ENET module, producing corresponding .ETH.csv event files. Packets in these files were then matched with their counterparts in the original .pcap files using MATLAB. For each matched packet, the relevant signal segment was extracted (cropped) from the continuous oscilloscope recording. As a result, a unique signal file was generated for each packet. The final dataset, named SigNet-10, consists of 12,916 labeled signal files, each corresponding to an individual Ethernet frame belonging to one of ten commonly used protocols. Alongside the dataset, the oscilloscope event tables (*.ETH.csv files), segmented PCAP files (*part.pcap), and each recording’s original .isf (Instrument Specific File) from the oscilloscope have been provided. The ISF files preserve the oscilloscope’s native screen recordings and can be reloaded for review or verification purposes. Furthermore, the MATLAB scripts developed for dataset construction have also been included to facilitate reproducibility.

Institutions

Categories

Computer Network, Computer Communications, Network Protocol, Networking

Licence