Skip to main content
University (Canadian Institute for Cybersecurity)

CICIDS2017 - Comprehensive Network Intrusion Detection Dataset

IoT Security & Intrusion Detection Cybersecurity / IoT Network Security
2,980 views
2 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"The most cited cybersecurity dataset worldwide with 2.8+ million network flows capturing 14 types of realistic attack scenarios including DDoS, brute force, botnet, and web attacks alongside benign traffic for advanced intrusion detection systems."

Catalog Notes

Dataset Overview

CICIDS2017 is the gold standard for network intrusion detection research, developed by the Canadian Institute for Cybersecurity. Collected over 5 days from a realistic network environment with both benign and attack traffic.

Attack Types (14 Types)

  • DoS/DDoS: Hulk, GoldenEye, Slowloris, SlowHTTPTest, Heartbleed
  • Port Scanning: Full port scan, SSH-Patator, FTP-Patator
  • Botnet: Botnet traffic simulation
  • Web Attacks: Brute Force, XSS, SQL Injection
  • Infiltration: Network infiltration attempts
  • Brute Force: SSH/FTP password attacks

Key Features & Metrics (80+ Features)

  • Flow Duration: Time between first and last packet
  • Header Length: Ethernet, IP, TCP/UDP headers
  • Protocol: TCP, UDP, ICMP statistics
  • Packet Counts: Total, PSH, ACK, URG flags
  • Byte Counts: Total, incoming, outgoing bytes
  • Inter-Arrival Time: Mean, std, min, max
  • Flow Bytes: Per second, per packet ratios
  • Packet Length: Mean, std, min, max statistics
  • Flags: FIN, SYN, RST, PSH, ACK, URG counts

Dataset Statistics

  • Total Flows: 2,830,743 network flows
  • Benign Traffic: 2,273,097 flows (80.3%)
  • Attack Traffic: 557,646 flows (19.7%)
  • Training Days: 3 days (Monday-Wednesday)
  • Test Days: 2 days (Thursday-Friday)

Device Types & Environment

  • IoT devices (smart home appliances)
  • Desktop workstations
  • Network servers
  • Virtualized environments
  • Realistic academic network topology

Research Applications

This dataset powers thousands of cybersecurity research papers annually and is the benchmark for:

  • Intrusion Detection Systems (IDS)
  • Machine Learning for Cybersecurity
  • Deep Learning Anomaly Detection
  • Network Traffic Classification
  • IoT Security Research
  • Zero-Day Attack Detection

Data Format & Structure

  • Format: CSV (Machine Generated Traffic, Wednesday, Thursday)
  • Features: 80 network flow features + labels
  • Size: ~2.5 GB compressed
  • Compatibility: Scikit-learn, TensorFlow, PyTorch

License & Usage

Free for academic, research, and commercial use under the CIC dataset license. Widely used in over 5,000 research publications.

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on University (Canadian Institute for Cybersecurity).

Preview on University (Canadian Institute for Cybersecurity)

Provided Citation

Sharafaldin, I., Lashkari, A. H., & Ghorbani, A. A. (2018). Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization. 4th International Conference on Information Systems Security and Privacy (ICISSP), Portugal.

This citation is displayed as supplied. Automatic style conversion is disabled because structured citation metadata is not recorded.

Source metadata: University (Canadian Institute for Cybersecurity) (2026)

Indexed by IoTDataset.com on Jan 20, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Cybersecurity IoTSyn Generated

Synthetic IoT Intrusion Detection Dataset — 18% Attacks

Free CC0 synthetic dataset: 500 rows of labelled network flows covering DoS, DDoS, botnet and reconnaissance traffic. 18% Attacks.

Apr 04, 2026
IoT Cybersecurity UCI Machine Learning Repository

RT-IoT2022

Real-time network traffic dataset from diverse IoT devices including normal behavior and various attacks (DDoS, brute-force, scans) for developing intrusion detection systems.

Jan 26, 2026
Cybersecurity University

CICIoT2023 - Large-Scale IoT Intrusion Detection Dataset

Comprehensive large-scale IoT intrusion detection dataset from Canadian Institute for Cybersecurity with 33 attack types across 105 real IoT devices. Includes 8.94 GB of network traffic data covering DDoS, DoS, Mirai, MITM, and reconnaissance attacks.

Jan 22, 2026
Cybersecurity Research Paper

MU-IoT - Comprehensive IoT Network Intrusion Dataset 2024

New realistic IoT network intrusion dataset (MU-IoT) with comprehensive attack scenarios for cybersecurity research. Published in IEEE 2024 with 4+ citations. Covers multiple IoT protocols and device types.

Jan 22, 2026
Cybersecurity Kaggle

TON_IoT Network Dataset - UNSW Cyber Range Lab Collection

Comprehensive network traffic dataset from UNSW Canberra Cyber Range Lab capturing benign and malicious flows in simulated IoT/IIoT smart environments using Argus and Zeek (Bro) tools.

Jan 22, 2026
Cybersecurity University

IoT Network Intrusion (CIC-IDS2017)

Realistic network traffic data containing benign activities and common IoT-targeted attacks like Brute Force, DoS, and Infiltration.

Jan 19, 2026

Explore other topics

All topics →