Skip to main content
Kaggle

IoT-23: A labeled dataset with malicious and benign IoT network traffic

IoT Security & Intrusion Detection Cybersecurity
799 views
1 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"IoT-23 provides labeled IoT network-traffic captures, including 20 malware scenarios and 3 benign IoT captures, intended to support machine-learning research on IoT security."

Catalog Notes

IoT-23 is a dataset of network traffic from Internet of Things (IoT) devices, including 20 malware captures and 3 benign IoT captures.

It was first published in January 2020 (captures range 2018–2019) and was collected in the Stratosphere Laboratory (CTU in Prague) to support research on labeled IoT malware infections and benign traffic; the work was funded by Avast Software.

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on Kaggle.

Preview on Kaggle

Cite This Dataset

Garcia, S., Parmisano, A., & Erquiaga, M. J. (2020). IoT-23: A labeled dataset with malicious and benign IoT network traffic. [Dataset]. {Zenodo. https://doi.org/10.5281/zenodo.4743746

Source metadata: {Zenodo (2020) · DOI: 10.5281/zenodo.4743746

Indexed by IoTDataset.com on Feb 08, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Cybersecurity Zenodo

IoT-23; Labeled IoT Malware & Benign Traffic [325M Flows, 500+ Hours]

Real IoT malware traffic dataset with 325M labeled network flows from 20 malware and 3 benign device captures over 500+ hours. PCAP and Zeek conn.log formats. Used for IoT botnet detection, malware traffic classification, and ML security research.

Apr 13, 2026
Cybersecurity Kaggle

RT-IoT2022 - Real-Time IoT Infrastructure Intrusion Detection

A comprehensive dataset derived from real-time IoT infrastructure, designed for intrusion detection research and network security analysis.

Feb 19, 2026
Cybersecurity University

MedBIoT — Medium-Sized IoT Botnet IDS Dataset [83 devices]

IoT botnet IDS dataset using 83 real and emulated devices with Mirai, BashLite, and Torii traffic. Raw PCAP files support botnet and anomaly detection research.

Jun 02, 2026
Cybersecurity Mendeley Data

MQTTEEB-D: Real-World IoT Cybersecurity Dataset for AI-Powered Threat Detection in MQTT Networks

A real-world cybersecurity dataset capturing MQTT-based IoT network traffic with live attacks and anomalous behavior. Collected from an active deployment with multiple attack types including DoS, SlowITe, and malformed injections. Provides both raw and preprocessed CSV files with rich metadata for intrusion detection and anomaly classification research.

Feb 07, 2026
Educational IoT / Network Security Kaggle

IoEd-Net: Internet of Educational Things Dataset for Academic Network Analysis

Comprehensive dataset from University of New Brunswick containing over 202,085 network traffic records from IoT devices in academic environment, with classification of benign and malicious activities.

Jan 16, 2026
Network Security IoT Stratosphere Lab

IoT-23: A Labeled Dataset with Malicious and Benign IoT Network Traffic

Comprehensive dataset from Stratosphere Laboratory containing network traffic from 23 IoT malware captures including Mirai and Torii botnets, with over 325 million labeled connections for cybersecurity research and ML-based threat detection.

Jan 16, 2026

Explore other topics

All topics →