# Extraction of features from DARPA dataset tcpdump files

**URL:** <https://community.zeek.org/t/extraction-of-features-from-darpa-dataset-tcpdump-files/505>\
**Category:** Zeek\
**Created:** [April 27, 2004, 5:23pm UTC](https://community.zeek.org/t/extraction-of-features-from-darpa-dataset-tcpdump-files/505 "2004-04-27T17:23:17Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [April 27, 2004, 5:23pm UTC](https://community.zeek.org/t/extraction-of-features-from-darpa-dataset-tcpdump-files/505/1 "2004-04-27T17:23:17Z")

</div>

> I'd like to extract 41 features and their corresponding attack classes based on  
> the DARPA 1999 dataset and 2000 dataset

Bro doesn't have these features directly coded into its analyzers.  
You could probably add them with not that much work, but I'd advise you  
to first consider whether you really want to do so: those datasets, while  
invaluable for the evaluations for which they were originally developed,  
are notorious for how they are misapplied for subsequent intrusion detection  
research. The main problem is that they have artifacts due to their synthetic  
nature. In particular, the feature set from the KDD Cup is known to be  
seriously flawed. See McHugh's critique of the original datasets and  
Mahoney/Chen's RAID 2003 paper on the problems with the KDD Cup feature set.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/extraction-of-features-from-darpa-dataset-tcpdump-files/505/2 "2022-05-06T15:37:01Z")

</div>


