Skip to content

Author

Valli Kumari Vatsavayi

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Open access Aug 2026

TSD-DDoS: A time-series dataset for TCP flooding attack detection and severity assessment for server health monitoring

Distributed Denial-of-Service (DDoS) attacks continue to threaten the availability of networked services by overwhelming server resources with malicious traffic. Among the different attack vectors, TCP flooding attacks remain particularly critical because TCP forms the backbone of reliable Internet services, such as web applications, cloud back-end systems, enterprise platforms, and many blockchain-based applications. Although several benchmark datasets exist for DDoS attack detection, most of them are flow-based and primarily support attack classification, offering a limited scope for analyzing how an ongoing attack impacts server health over time. This data article introduces TSD-DDoS, a time-series dataset specifically developed to fill a crucial gap in the detection of TCP flooding attacks and assessment of their severity in relation to server health. Unlike conventional flow-level datasets, TSD-DDoS organizes network traffic into fixed 5-second intervals. This temporal aggregation enables continuous monitoring of traffic patterns and provides direct insights into the progression and impact of TCP flooding on server performance and availability. By capturing the evolving nature of attacks over time, TSD-DDoS opens new avenues for research into time-aware detection mechanisms and server health monitoring, areas that are underrepresented in existing benchmark datasets. The dataset was constructed using packet capture (PCAP) files from the CICDDoS2019 benchmark dataset. The selected PCAP files were replayed at network speeds of up to 20 Gbps using the tcpreplay tool, whereas traffic capture was performed using Wireshark, a widely recognized packet analysis tool. The collected traffic was divided into successive 5-second intervals, and for each window, aggregated TCP statistics were extracted, specifically the counts of TCP-SYN, TCP-SYN-ACK, TCP-ACK, TCP-RST, and total TCP packets. Each interval was labeled as either normal or attack traffic, with an additional annotation indicating the server health status: Good, Fair, Serious, or Critical. These labels allowed for a clear temporal analysis of both the presence of attacks and the progression of severity. By offering structured, labelled, and time-indexed TCP traffic data, TSD-DDoS enables the development and evaluation of ML-based intrusion detection systems, time-sensitive server health monitoring tools, and adaptive resource management strategies. This is especially valuable in cloud and virtualized environments, where effective mitigation and scaling decisions rely on understanding how attacks evolve over time rather than on isolated flow-level metrics.

Sajja Ratan Kumar, Valli Kumari Vatsavayi · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.