KRACK and Kr00k Attacks Datasets

Published: 21 July 2025| Version 1 | DOI: 10.17632/x29ggnwghy.1
Contributor:
Md Minhazul Islam Munna

Description

I have simulated KRACK and Kr00k attacks on a WPA2-secured network using an ASUS RT-AC68U router and client devices (Samsung Note 4, iPhone 6s, Windows 10 Pro and Linux). Traffic was captured during normal operation and attack phases using Wireshark and tcpdump, yielding 5.5M+ labeled frames (raw PCAPs + 34 features) for attack detection research.

Files

Steps to reproduce

Our methodology involves a controlled testbed featuring an ASUS RT-AC68U access point and diverse client devices (e.g., Samsung Note 4, iPhone 6s, Windows 10 Pro) to simulate real- world scenarios. Using tools like Wireshark and tcpdump, we captured both normal and attack traffic, focusing on anomalies such as key reinstallation (KRACK) and zero-key encryption (Kr00k). The dataset includes raw pcap files, extracted features (e.g., frame types, signal strength, encryption flags), and labeled samples, totaling over 5.5 million frames with distinct attack and normal traffic subsets.

Institutions

  • Beijing Institute of Technology

Categories

Cybersecurity, Intrusion Detection, Cyber Attack

Licence