Skip to main content
Zenodo

IoT-23; Labeled IoT Malware & Benign Traffic [325M Flows, 500+ Hours]

IoT Security & Intrusion Detection Cybersecurity
1,200 views
2 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"Real IoT malware traffic dataset with 325M labeled network flows from 20 malware and 3 benign device captures over 500+ hours. PCAP and Zeek conn.log formats. Used for IoT botnet detection, malware traffic classification, and ML security research."

Catalog Notes

Overview

IoT-23 (Aposemat IoT-23) is a large-scale, publicly available dataset of labeled network traffic from real IoT devices captured at the Stratosphere Laboratory, AIC Group, FEL, Czech Technical University in Prague. It is the first dataset to combine actual malware execution on physical IoT devices with benign device traffic, making it uniquely representative of real-world IoT threat scenarios.

The dataset contains 23 scenarios: 20 network captures from IoT devices infected with real malware samples (including Mirai, Torii, Okiru, Muhstik, and IRCBot variants) and 3 captures of completely benign IoT devices (Philips Hue smart light bridge, Amazon Echo, and a Somfy smart door lock). In total, it contains more than 760 million packets and 325 million labeled flows spanning over 500 hours of network traffic captured between 2018 and 2019.

Traffic was labeled using Zeek (Bro) conn.log format, with labels including Benign, C&C, DDoS, PartOfAHorizontalPortScan, FileDownload, Attack, and Okiru, among others. The research and dataset collection was funded by Avast Software.

Column Schema

ColumnDescription
tsTimestamp of the connection record.
uidUnique connection identifier.
id.orig_h / id.resp_hOriginator and responder IP addresses.
id.orig_p / id.resp_pOriginator and responder port numbers.
protoTransport protocol (tcp, udp, icmp).
serviceApplication-layer service detected.
durationConnection duration in seconds.
orig_bytes / resp_bytesBytes transferred by originator and responder.
labelTraffic class: Benign, C&C, DDoS, PortScan, FileDownload, etc.
detailed-labelGranular attack sub-label.

Key Statistics

  • Total Flows: 325+ million labeled flows
  • Total Packets: 760+ million
  • Traffic Duration: 500+ hours
  • Scenarios: 23 (20 malware + 3 benign)
  • Malware Families: Mirai, Torii, Okiru, Muhstik, IRCBot, and others
  • File Format: PCAP and Zeek conn.log (labeled)
  • Full download: ~20 GB; Light version (flows only): ~8.7 GB
  • Capture Period: 2018–2019; Published: January 2020

Use Cases

  • IoT malware traffic detection and botnet identification
  • Behavioral analysis of compromised IoT devices vs. benign devices
  • C&C communication detection and lateral movement analysis
  • ML-based multi-label network traffic classification for IoT security

Source & Attribution

Created by Sebastian Garcia, Agustin Parmisano, and Maria Jose Erquiaga at the Stratosphere Laboratory, Czech Technical University in Prague. Funded by Avast Software. Available for download from the Stratosphere IPS website and mirrored on Zenodo (record 4743746).

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on Zenodo.

Preview on Zenodo

Cite This Dataset

Garcia, Sebastian, Parmisano, Agustin, & Erquiaga, Maria Jose (2020). IoT-23: A labeled dataset with malicious and benign IoT network traffic. [Dataset]. Zenodo. https://doi.org/10.5281/ZENODO.4743745

Source metadata: Zenodo (2020) · DOI: 10.5281/ZENODO.4743745

Indexed by IoTDataset.com on Apr 13, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Network Security University

CICIoT2023: Real-Time IoT Attack Dataset [47M+ Labeled Flows, 33 Attack Types]

Large-scale IoT cybersecurity dataset with 47M+ labeled network flows from 105 real IoT devices across 33 attack types in 7 categories. PCAP and CSV formats. Built for IDS/IPS development and ML-based IoT traffic classification research.

Apr 13, 2026
Network Security University

TON_IoT: UNSW Telemetry, Network & OS Attack Traces [Multi-Source IIoT]

Heterogeneous IoT/IIoT dataset from UNSW Canberra Cyber Range with network traffic, Windows/Linux OS traces, and IoT sensor telemetry. Labeled for 9 attack types including DoS, DDoS, ransomware, and XSS. CSV and PCAP formats. Benchmark for AI-based IDS evaluation.

Apr 13, 2026
Network Security UCI

RT-IoT2022: Real-Time IoT IDS Dataset [41 Features, Multi-Attack]

Real-time IoT network security dataset from a live IoT infrastructure with 41 bidirectional flow features. Includes ThingSpeak-LED, Wipro-Bulb, and MQTT-Temp devices with SSH brute force, DDoS (Hping/Slowloris), and Nmap attack scenarios. CSV format. Used for adaptive IDS development.

Apr 13, 2026
Network Security Kaggle

IoTID20: IoT Network Intrusion Dataset [625K Flows, 4 Attack Types, 83 Features]

Smart-home-derived IoT botnet dataset with 625,783 labeled flow records and 83 network features. Covers DoS, Mirai, MITM, and Scan attacks from EZVIZ and SKT NGU Wi-Fi cameras. CSV format. Supports binary, category, and sub-category IDS classification tasks.

Apr 13, 2026
Cybersecurity Kaggle

Edge-IIoTset: Comprehensive IoT & IIoT Cyber Security Dataset [~12 GB, 15 Attack Types]

Realistic IoT/IIoT cybersecurity dataset supporting centralized and federated learning with 15 attack types across network, application, and protocol layers. CSV and PCAP formats (~12 GB). Available via IEEE Dataport and Kaggle. Designed for edge computing IDS research.

Apr 13, 2026
Cybersecurity UCI

N-BaIoT: Real IoT Botnet Traffic from 9 Infected Devices [7M Records, Mirai & BASHLITE]

Real IoT botnet traffic dataset from 9 commercial devices (webcams, routers, thermostats) authentically infected by Mirai and BASHLITE. Over 7M records, 115 statistical features. CSV format. Benchmark for deep-learning-based IoT anomaly and botnet detection.

May 03, 2026

Explore other topics

All topics →