Skip to main content
Stratosphere Lab

IoT-23: A Labeled Dataset with Malicious and Benign IoT Network Traffic

IoT Security & Intrusion Detection Network Security IoT
555 views
2 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"Comprehensive dataset from Stratosphere Laboratory containing network traffic from 23 IoT malware captures including Mirai and Torii botnets, with over 325 million labeled connections for cybersecurity research and ML-based threat detection."

Catalog Notes

Dataset Overview

The IoT-23 dataset is a comprehensive collection of network traffic from Internet of Things devices infected with malware. Created by the Stratosphere Laboratory, it contains 23 different malware captures plus 3 benign scenarios, representing one of the most extensive labeled IoT botnet datasets available for research purposes.

Key Features

  • 23 malware infection scenarios with real IoT botnets
  • 3 benign traffic scenarios for baseline comparison
  • Over 325 million labeled network connections
  • PCAP files with complete packet captures
  • Bidirectional NetFlow data (argus format)
  • Labeled connections (Malicious, Benign, or Unknown)
  • Multiple malware families: Mirai, Torii, Hide and Seek, Hakai
  • Real IoT devices used: Philips HUE, Amazon Echo, Somfy doorlock

Data Structure

Each scenario in the dataset includes multiple data formats:

  • PCAP Files: Complete packet captures for deep analysis
  • Conn.log Files: Connection summaries in Zeek/Bro format
  • Labeled Flows: CSV files with labeled connections
  • Metadata: Information about infection type and device
  • Network Features: Duration, protocol, packets, bytes, ports
  • Behavioral Labels: Malicious, Benign, Background, or Unknown

Data Collection Method

The dataset was created by intentionally infecting real IoT devices with malware in a controlled laboratory environment. Traffic was captured during the infection process and normal operation, providing authentic examples of IoT botnet behavior. All captures were performed with proper isolation to prevent actual attacks.

Malware Families Included

  • Mirai: Famous IoT botnet targeting cameras and routers
  • Torii: Advanced persistent IoT botnet
  • Hide and Seek: P2P-based IoT botnet
  • Hakai: Variant of Mirai targeting specific devices
  • Others: Various IoT-specific malware strains

Research Applications

  • IoT botnet detection and classification
  • Malware behavior analysis in IoT environments
  • Development of network-based intrusion detection systems
  • Machine learning model training for threat detection
  • IoT security protocol evaluation
  • Behavioral analysis of infected IoT devices
  • Comparative studies of different malware families

Machine Learning Use Cases

  • Binary classification (Malicious vs. Benign traffic)
  • Multi-class malware family classification
  • Anomaly detection in IoT network behavior
  • Time-series analysis of infection patterns
  • Deep learning for packet-level analysis
  • Feature engineering from network flows
  • Botnet command and control detection
  • Zero-day malware detection using behavioral models

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on Stratosphere Lab.

Preview on Stratosphere Lab

Provided Citation

Garcia, S., Parmisano, A., & Erquiaga, M. J. (2020). IoT-23: A labeled dataset with malicious and benign IoT network traffic. Stratosphere Laboratory.

This citation is displayed as supplied. Automatic style conversion is disabled because structured citation metadata is not recorded.

Source metadata: Stratosphere Lab (2026)

Indexed by IoTDataset.com on Jan 16, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Cybersecurity University

MedBIoT — Medium-Sized IoT Botnet IDS Dataset [83 devices]

IoT botnet IDS dataset using 83 real and emulated devices with Mirai, BashLite, and Torii traffic. Raw PCAP files support botnet and anomaly detection research.

Jun 02, 2026
Cybersecurity Zenodo

IoT-23; Labeled IoT Malware & Benign Traffic [325M Flows, 500+ Hours]

Real IoT malware traffic dataset with 325M labeled network flows from 20 malware and 3 benign device captures over 500+ hours. PCAP and Zeek conn.log formats. Used for IoT botnet detection, malware traffic classification, and ML security research.

Apr 13, 2026
Network Security University

CICIoT2023: Real-Time IoT Attack Dataset [47M+ Labeled Flows, 33 Attack Types]

Large-scale IoT cybersecurity dataset with 47M+ labeled network flows from 105 real IoT devices across 33 attack types in 7 categories. PCAP and CSV formats. Built for IDS/IPS development and ML-based IoT traffic classification research.

Apr 13, 2026
Cybersecurity UCI

N-BaIoT: Real IoT Botnet Traffic from 9 Infected Devices [7M Records, Mirai & BASHLITE]

Real IoT botnet traffic dataset from 9 commercial devices (webcams, routers, thermostats) authentically infected by Mirai and BASHLITE. Over 7M records, 115 statistical features. CSV format. Benchmark for deep-learning-based IoT anomaly and botnet detection.

May 03, 2026
Network Security Kaggle

IoTID20: IoT Network Intrusion Dataset [625K Flows, 4 Attack Types, 83 Features]

Smart-home-derived IoT botnet dataset with 625,783 labeled flow records and 83 network features. Covers DoS, Mirai, MITM, and Scan attacks from EZVIZ and SKT NGU Wi-Fi cameras. CSV format. Supports binary, category, and sub-category IDS classification tasks.

Apr 13, 2026
Cybersecurity Kaggle

IoT-23: A labeled dataset with malicious and benign IoT network traffic

IoT-23 provides labeled IoT network-traffic captures, including 20 malware scenarios and 3 benign IoT captures, intended to support machine-learning research on IoT security.

Feb 08, 2026

Explore other topics

All topics →