MedBIoT — Medium-Sized IoT Botnet IDS Dataset [83 devices]
IoT botnet IDS dataset using 83 real and emulated devices with Mirai, BashLite, and Torii traffic. Raw PCAP files support botnet and anomaly detection research.
View DatasetShowing 11 of 11 datasets
IoT botnet IDS dataset using 83 real and emulated devices with Mirai, BashLite, and Torii traffic. Raw PCAP files support botnet and anomaly detection research.
View DatasetReal IoT botnet traffic dataset from 9 commercial devices (webcams, routers, thermostats) authentically infected by Mirai and BASHLITE. Over 7M records, 115 statistical features. CSV format. Benchmark for deep-learning-based IoT anomaly and botnet detection.
View DatasetLarge-scale IoT cybersecurity dataset with 47M+ labeled network flows from 105 real IoT devices across 33 attack types in 7 categories. PCAP and CSV formats. Built for IDS/IPS development and ML-based IoT traffic classification research.
View DatasetReal IoT malware traffic dataset with 325M labeled network flows from 20 malware and 3 benign device captures over 500+ hours. PCAP and Zeek conn.log formats. Used for IoT botnet detection, malware traffic classification, and ML security research.
View DatasetSmart-home-derived IoT botnet dataset with 625,783 labeled flow records and 83 network features. Covers DoS, Mirai, MITM, and Scan attacks from EZVIZ and SKT NGU Wi-Fi cameras. CSV format. Supports binary, category, and sub-category IDS classification tasks.
View DatasetReproducible large-scale IoT network dataset from 78 emulated devices using MQTT, CoAP, and RTSP protocols. Includes benign and malicious traffic with DoS, brute force, scanning, and C&C attacks in PCAP and CSV formats.
View DatasetCICIoT2023 is a large-scale, flow-based network traffic dataset capturing real-time benign and malicious communications in an IoT environment composed of 105 physical devices. The dataset captures traffic traces for 33 attack scenarios grouped into seven categories: DDoS, DoS, Reconnaissance, web-based attacks, brute-force attempts, spoofing, and Mirai malware.
View DatasetThe Gotham Dataset is a large-scale, reproducible benchmark for evaluating decentralized Intrusion Detection Systems (IDS) and Federated Learning in virtualized smart cities. It captures interface-level network traffic from 78 heterogeneous IoT devices, including complex attack vectors like Mirai botnets, Merlin C2 traffic, and CoAP amplification, preserving the non-IID nature of edge data for realistic AI security training.
View DatasetSpecialized dataset for detecting IoT botnet attacks using network traffic analysis. Captures behavior of 9 real IoT devices infected with Mirai and BASHLITE malware variants. Ideal for training ML models to identify compromised IoT devices through traffic patterns.
View DatasetComprehensive large-scale IoT intrusion detection dataset from Canadian Institute for Cybersecurity with 33 attack types across 105 real IoT devices. Includes 8.94 GB of network traffic data covering DDoS, DoS, Mirai, MITM, and reconnaissance attacks.
View DatasetComprehensive dataset from Stratosphere Laboratory containing network traffic from 23 IoT malware captures including Mirai and Torii botnets, with over 325 million labeled connections for cybersecurity research and ML-based threat detection.
View Dataset