threaTrace-detector / threaTrace

MIT License
83 stars 22 forks source link

Which subset of DARPA E3 is used? #14

Open Chaves2021 opened 7 months ago

Chaves2021 commented 7 months ago

As stated in the paper: "We choose files that contain anomalous behavior as testing set. We remove part of the dataset because some graphs are generated in exceptional accidents such as outages and shutdown of hosts"

It's unclear which files are removed, since in the code just 2 files kept, but in the paper results there are more nodes than in the 2 files used as train and test.

hkimm-sbu commented 4 months ago

Yes I have the same exact question.