DOI: 10.3390/data11090244 ISSN: 2306-5729

Fast-Flux Dataset: Enhancing Cybersecurity Analysis and Defense

Ahmed S. Shatnawi, Basheer Al-Duwairi, Zakarea Al-Shara, Mahmoud M. Almazari

A fast-flux network (FFN) keeps itself accessible by frequently altering its IP addresses, usually avoiding standard detection techniques. In April 2025, six countries released a joint advisory describing this method as a national security threat and calling on DNS providers to improve their detection analytics. Most existing datasets used for these analytics are outdated. This data descriptor presents a new fast-flux dataset compiled from confirmed fast-flux domains and two months of repeated DNS lookups. We used VirusTotal to find additional domains associated with each resolved address. The dataset contains 67,606 fast-flux domains and 23,924 legitimate domains taken from the top Alexa sites. For each domain and IP address, we record the geolocation, autonomous system number (ASN), and country. The dataset also includes a feature file consisting of 91,530 records and 20 features. It also includes the threat model, three analysis tasks, and evaluation results from various studies. A feature-definition forest trained with this protocol achieves 96.0% classification accuracy and serves as the reference baseline. We include the original JSON responses so users can examine or alter the feature definitions.