Dataset Using TLS Fingerprints for OS Identification in Encrypted Traffic

Open data API in a single place

Provided by Zenodo

Get early access to Dataset Using TLS Fingerprints for OS Identification in Encrypted Traffic API!

Let us know and we will figure it out for you.

Dataset information

Country of origin
Updated
2020.08.18 00:00
Created
2019.09.26
Available languages
English
Keywords
Quality scoring

Dataset description

The dataset consists of data from three different sources; flow records collected from the university backbone network, log entries from the two university DHCP (Dynamic Host Configuration Protocol) servers and a single RADIUS (Remote Authentication Dial In User Service) accounting server. The data was collected from 2019-07-12 00:00 to 2019-07-16 23:59 with a few hours overhead on both sides of the interval for the log entries to cover long connection sessions overlapping to and from the time frame. We measured the flow data from the university uplink to the Internet. In the dataset, we kept only flows with source IP addresses from university wireless networks (Eduroam). The flow data was then enriched with information from DHCP and RADIUS servers to contain ID of the RADIUS session and operating system od the transmitting device as derived from DHCP logs. The dataset is in the form of CSV file with the following information fields important for OS identification: Basic flow features Date flow start - timestamp of flow start Date flow end - timestamp of flow end Src IPv4 - source IPv4 address sPort - source L4 port Dst IPv4 - destination IPv4 address dPort - destination L4 port Extended TCP/IP parameters SYN size - the size of the initial SYN packet of a TCP connection (in bytes) TCP win - value of TCP Window size parameter TCP SYN TTL - observed TTL value HTTP parameters HTTP Host - hostname from the HTTP request HTTP UA OS - OS identification based on user-agent HTTP UA OS MAJ - OS identification based on user-agent HTTP UA OS MIN - OS identification based on user-agent HTTP UA OS BLD - OS identification based on user-agent TLS parameters TLS SNI - Server Name Indication field TLS SNI length - length of SNI in bytes TLS Client Version - TLS client hello Version field Client Cipher Suites - list of supported cipher suites TLS Extension Types - list of extension IDs TLS Extension Lengths - list of extension lengths TLS Elliptic Curves - list of supported curves (or supported groups in TLS1.3) TLS EC Point Formats - list of EC formats Log based extensions Session ID - ID of the session to match flows from one device Ground Truth OS - OS name derived from log data The observed network traffic contains privacy-sensitive information. Hereby, we declare that the monitored data used for our research were processed in accordance with the EU General Data Protection Regulation 2016/679. The published dataset was anonymized with cryptographic means using Crypto-PAn algorithm to preserve both the scientific value and user privacy. When using this dataset, please cite the original work as follows: @inproceedings{lastovicka2020using, title={Using TLS Fingerprints for OS Identification in Encrypted Traffic}, author={La{\v{s}}tovi{\v{c}}ka, Martin and {\v{S}}pa{\v{c}}ek, Stanislav and Velan, Petr and {\v{C}}eleda, Pavel}, booktitle = {2020 IEEE/IFIP Network Operations and Management Symposium (NOMS 2020)}, doi = {http://dx.doi.org/10.1109/NOMS47738.2020.9110319}, keywords = {OS fingerprinting;passive monitoring;IPFIX;TLS}, isbn = {978-1-7281-4973-8}, pages = {1-6}, publisher = {IEEE Xplore Digital Library}, year = {2020} }  
European data infrastructure with broad catalog discovery, free evaluation access and production-grade API options.
190K+
indexed dataset pages
32
countries and EU institutions
2019
API-first since
Free API quota
for evaluation and prototypes
SLA
history and push on production APIs
FAQ

Questions before production use

Practical answers on evaluation, licensing, freshness, versioning and support.

api.store is built and operated by Apitalks s.r.o. Company details and a direct contact path are linked in the footer for vendor checks and procurement review.
Yes. Selected APIs include a free API quota, so your team can validate coverage, freshness, response shape and workflow fit before asking for a production plan.
Often yes, but usage rights depend on the source license and dataset. We surface source, license and update metadata where available, and can help review terms before a production integration.
Maintained APIs include update metadata where available. For production integrations, we can add history, monitoring and push updates so changes are easier to detect and act on.
Production APIs can add SLA, stable identifiers, versioning support, history, push updates and direct support around the data your product or AI workflow depends on.

Didn't find the API you need?

Let us know and we will figure it out for you.

European data discovery with free evaluation access and production-grade API options.

Copyright © 2026. Made by Apitalks