Skip to main content
Kaggle

Bot-IoT Dataset - Large-Scale IoT Botnet Traffic with Full Packet Capture

IoT Security & Intrusion Detection Cybersecurity
1,260 views
2 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"Comprehensive large-scale IoT botnet dataset combining legitimate IoT network traffic with realistic botnet attack scenarios. Features full packet captures (PCAP) and extracted flow features for diverse attack types including DDoS, reconnaissance, theft, and DoS attacks."

Catalog Notes

Dataset Overview

The Bot-IoT dataset is a large-scale IoT security resource that combines realistic benign IoT network traffic with diverse botnet attack scenarios. It provides both raw packet captures and processed network flow features, making it versatile for various research approaches.

Dataset Composition

The dataset integrates two distinct traffic sources:

1. Legitimate IoT Traffic

Normal operational traffic from IoT devices and services including:

  • Smart home device communications
  • IoT sensor data transmissions
  • Device-to-cloud service interactions
  • Inter-device communications in smart environments
  • Firmware updates and maintenance traffic

2. Botnet Attack Traffic

Realistic attack scenarios simulating compromised IoT devices participating in malicious activities across four major categories.

Attack Categories

DDoS Attacks (Distributed Denial of Service)

  • UDP flooding from multiple compromised devices
  • TCP SYN flood attacks
  • HTTP flood targeting web services
  • DNS amplification attacks

Reconnaissance and Information Gathering

  • Network scanning to identify vulnerable devices
  • Port scanning for open services
  • OS fingerprinting attempts
  • Service enumeration

Data Theft and Exfiltration

  • Keylogging traffic patterns
  • Data exfiltration through covert channels
  • Credential harvesting communications

DoS Attacks (Single-Source)

  • Resource exhaustion attacks
  • Protocol-specific DoS targeting IoT services

Data Formats

PCAP Files (Full Packet Capture)

Raw network packets captured at wire-level enabling deep packet inspection, protocol analysis, payload examination, and development of signature-based detection systems.

Flow Features (Extracted Statistics)

Processed network flow statistics providing efficient machine learning features without requiring packet-level processing:

  • Flow durations and packet counts
  • Byte statistics and protocol distributions
  • Flag counts and connection states
  • Inter-arrival times and burst patterns
  • Bidirectional flow characteristics

Scale and Diversity

The large-scale nature provides:

  • Millions of network flows
  • Diverse attack implementations
  • Realistic traffic mixing (benign and malicious)
  • Multiple device types and manufacturers
  • Temporal patterns spanning extended periods

Research Applications

  • Deep Learning IDS: Train neural networks on flow features for intrusion detection
  • Signature Development: Use PCAP files to create attack signatures
  • Behavioral Analysis: Study differences between legitimate and botnet traffic patterns
  • Protocol Analysis: Examine protocol-level characteristics of attacks
  • Real-Time Detection: Develop systems using flow-based features for online detection

Advantages for ML Research

  • Both binary classification (benign vs attack) and multi-class (attack type) labels
  • Rich feature set reducing preprocessing requirements
  • Sufficient data volume for deep learning approaches
  • Realistic class imbalance reflecting real networks

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on Kaggle.

Preview on Kaggle

Cite This Dataset

Vignesh Venkateswaran (2023). Bot-IoT Dataset. [Dataset]. Kaggle. https://www.kaggle.com/datasets/vigneshvenkateswaran/bot-iot

Source metadata: Kaggle (2023)

Indexed by IoTDataset.com on Jan 23, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Cybersecurity IoTSyn Generated

Synthetic IoT Intrusion Detection Dataset — 18% Attacks

Free CC0 synthetic dataset: 500 rows of labelled network flows covering DoS, DDoS, botnet and reconnaissance traffic. 18% Attacks.

Apr 04, 2026
Cybersecurity CIC Repository

CICIoT2023: Large-Scale IoT Attack Traffic Dataset

CICIoT2023 is a large-scale, flow-based network traffic dataset capturing real-time benign and malicious communications in an IoT environment composed of 105 physical devices. The dataset captures traffic traces for 33 attack scenarios grouped into seven categories: DDoS, DoS, Reconnaissance, web-based attacks, brute-force attempts, spoofing, and Mirai malware.

Feb 05, 2026
IoT Network Security Zenodo / ArXiv

Gotham Dataset 2025: A Reproducible Large-Scale IoT Network Dataset for Intrusion Detection

Large-scale reproducible IoT network dataset with traffic from 100+ diverse IoT devices including smart home, wearable, and industrial sensors, featuring multiple attack scenarios and benign behavior for intrusion detection research.

Jan 30, 2026
Cybersecurity / IoT Network Security University (Canadian Institute for Cybersecurity)

CICIDS2017 - Comprehensive Network Intrusion Detection Dataset

The most cited cybersecurity dataset worldwide with 2.8+ million network flows capturing 14 types of realistic attack scenarios including DDoS, brute force, botnet, and web attacks alongside benign traffic for advanced intrusion detection systems.

Jan 20, 2026
Cybersecurity Kaggle

IoT-23 Network Traffic Dataset - Full Collection

Large-scale labeled network traffic captures (PCAPs) from IoT devices. Based on Stratosphere Laboratory's famous IoT-23 dataset with botnet and normal traffic patterns.

Jan 21, 2026
Cybersecurity Mendeley Data

Smart Home Intrusion Detection Dataset — 7 Attack Scenarios

Smart home traffic captured under normal operation and seven multi-stage attack scenarios across heterogeneous end devices. CC BY 4.0, published 2026.

Jul 29, 2026

Explore other topics

All topics →