Skip to content
JournalsWorldThe Global Research Discovery Platform
Featured Dataset

Beyond Bots: Identifying Human-Driven SSH Intrusions in the Wild

This dataset contains SSH session logs collected using a high-interaction deception system based on Cowrie operating in proxy mode. The deployment was active for approximately eight months (July 2025 – March 2026) and captured real-world attacker interactions after successful authentication

👤
CreatorAnonymous
📅
Published2026-04-16
🔗
DOI10.5281/zenodo.19610238
📊
Downloads2
⚖️
Licensecc-by-4.0
Data TypeDataset
Published2026
Licensecc-by-4.0
Total Views95
Total Downloads2

This dataset contains SSH session logs collected using a high-interaction deception system based on Cowrie operating in proxy mode. The deployment was active for approximately eight months (July 2025 – March 2026) and captured real-world attacker interactions after successful authentication. To increase realism and reduce noise from large-scale automated login attempts, the system forwards sessions to isolated backend environments and applies adaptive credential filtering.

The dataset includes raw session data. Each session is represented as a sequence of executed commands together with metadata such as timestamps, and session identifiers. 

To enable reproducible analysis while protecting attacker privacy, IP addresses were anonymised prior to dataset release. Each unique source IP was assigned a stable numeric identifier (attacker_00001 … attacker_03479). The mapping is deterministic and consistent across all sessions — sessions originating from the same IP share the same pseudonymous identifier, preserving within-attacker session linkability without exposing the original addresses.                                                       

The dataset is intended to support research on attacker behavior in SSH environments, including the distinction between automated and human-driven activity, behavioral clustering, anomaly detection, and the evaluation of deception systems. Due to the absence of ground truth labels, the provided behavioral indicators should be interpreted as heuristic signals rather than definitive classifications.

 

Each session JSON contains the following fields:   

– session_id — unique 12-character hex identifier for the session   

– attacker_id — replacing the original attacker_ip field 

– country — 2-letter country code of the attacker                                           

📤 Share this page

Found this useful? Share it with your network.

✓ Link copied! Paste it on ResearchGate / Academia.edu
📦
Beyond Bots: Identifying Human-Driven SSH Intrusions in the… (Full Dataset)Size varies
⬇
📄
ReadmeVia DOI record
↗

Files are hosted on the source repository. Click download to access the full dataset.

Anonymous (2026). Beyond Bots: Identifying Human-Driven SSH Intrusions in the Wild. https://doi.org/10.5281/zenodo.19610238