IoT-DH: IoT DDoS Honeypot Dataset for Attack Analysis
Abstract
"Comprehensive honeypot dataset for analyzing DDoS attacks on IoT devices, containing 10 key attributes from PCAP data converted to CSV format."
Description
Dataset Overview
The IoT DDoS Honeypot Dataset is a comprehensive collection designed to enhance our understanding of Distributed Denial of Service (DDoS) attacks targeting IoT devices. The data was collected from a specially designed honeypot system to attract real-world cyberattacks.
Key Features
- 10 key attributes for comprehensive analysis
- Real data from honeypot deployment
- Conversion from PCAP to CSV for accessibility
- Detailed information about attacker tactics and techniques
- Focus on DDoS attack patterns specific to IoT
Data Structure/Columns
The dataset contains 10 specific attributes:
- dt: Timestamp of the packet
- dur: Duration in seconds
- dur_nsec: Duration in nanoseconds
- tot_dur: Total duration
- pktrate: Packet rate
- protocol: Network protocol (TCP/UDP/ICMP)
- port_no: Port number
- tx_kbps: Transmission speed (kbps)
- rx_kbps: Reception speed (kbps)
- tot_kbps: Total bandwidth (kbps)
- label: Attack classification (Benign/Attack)
Data Collection Method
Data was collected using a honeypot system specifically designed to attract DDoS attacks on IoT devices. The data was recorded in PCAP format and then converted to CSV for ease of access and analysis in machine learning applications.
Research Applications
- Analysis of DDoS attack patterns on IoT
- Threat intelligence and threat identification
- Study of attacker tactics and techniques
- Development of defense mechanisms
- Network traffic profiling for IoT security
Machine Learning Use Cases
- Binary classification (Benign vs Attack)
- DDoS attack detection models
- Traffic pattern analysis
- Real-time anomaly detection
- Bandwidth-based attack identification
Data Preview
| dt | dur | dur_nsec | tot_dur | pktrate | protocol | port_no | tx_kbps | rx_kbps | tot_kbps | label |
|---|---|---|---|---|---|---|---|---|---|---|
| 2024-01-10 08:15:23 | 1.250 | 1250000000 | 2.5 | 150 | TCP | 80 | 512.3 | 128.7 | 641.0 | Benign |
| 2024-01-10 08:16:45 | 0.050 | 50000000 | 0.1 | 8500 | UDP | 53 | 9876.5 | 234.2 | 10110.7 | Attack |
| 2024-01-10 08:17:12 | 2.100 | 2100000000 | 4.2 | 95 | ICMP | 0 | 256.1 | 198.4 | 454.5 | Benign |
Showing first few rows for preview
Cite This Dataset
Mendeley (2026). IoT-DH: IoT DDoS Honeypot Dataset for Attack Analysis. [Dataset]. Mendeley. https://data.mendeley.com/datasets/8dns3xbckv/1
Select your preferred citation style above. The citation will automatically update and you can copy it to your clipboard.
Original source: Mendeley (2026). Visit official page for more details.
Indexed by IoTDataset.com on Jan 16, 2026
Ready to Start Your Research?
Download this dataset directly from the official repository and start building your next breakthrough project.