Skip to main content
Mendeley

IoT-DH: IoT DDoS Honeypot Dataset for Attack Analysis

Abstract

"Comprehensive honeypot dataset for analyzing DDoS attacks on IoT devices, containing 10 key attributes from PCAP data converted to CSV format."

Description

Dataset Overview

The IoT DDoS Honeypot Dataset is a comprehensive collection designed to enhance our understanding of Distributed Denial of Service (DDoS) attacks targeting IoT devices. The data was collected from a specially designed honeypot system to attract real-world cyberattacks.

Key Features

  • 10 key attributes for comprehensive analysis
  • Real data from honeypot deployment
  • Conversion from PCAP to CSV for accessibility
  • Detailed information about attacker tactics and techniques
  • Focus on DDoS attack patterns specific to IoT

Data Structure/Columns

The dataset contains 10 specific attributes:

  • dt: Timestamp of the packet
  • dur: Duration in seconds
  • dur_nsec: Duration in nanoseconds
  • tot_dur: Total duration
  • pktrate: Packet rate
  • protocol: Network protocol (TCP/UDP/ICMP)
  • port_no: Port number
  • tx_kbps: Transmission speed (kbps)
  • rx_kbps: Reception speed (kbps)
  • tot_kbps: Total bandwidth (kbps)
  • label: Attack classification (Benign/Attack)

Data Collection Method

Data was collected using a honeypot system specifically designed to attract DDoS attacks on IoT devices. The data was recorded in PCAP format and then converted to CSV for ease of access and analysis in machine learning applications.

Research Applications

  • Analysis of DDoS attack patterns on IoT
  • Threat intelligence and threat identification
  • Study of attacker tactics and techniques
  • Development of defense mechanisms
  • Network traffic profiling for IoT security

Machine Learning Use Cases

  • Binary classification (Benign vs Attack)
  • DDoS attack detection models
  • Traffic pattern analysis
  • Real-time anomaly detection
  • Bandwidth-based attack identification

Data Preview

dtdurdur_nsectot_durpktrateprotocolport_notx_kbpsrx_kbpstot_kbpslabel
2024-01-10 08:15:231.25012500000002.5150TCP80512.3128.7641.0Benign
2024-01-10 08:16:450.050500000000.18500UDP539876.5234.210110.7Attack
2024-01-10 08:17:122.10021000000004.295ICMP0256.1198.4454.5Benign

Showing first few rows for preview

Cite This Dataset

Mendeley (2026). IoT-DH: IoT DDoS Honeypot Dataset for Attack Analysis. [Dataset]. Mendeley. https://data.mendeley.com/datasets/8dns3xbckv/1

Select your preferred citation style above. The citation will automatically update and you can copy it to your clipboard.

Original source: Mendeley (2026). Visit official page for more details.

Indexed by IoTDataset.com on Jan 16, 2026

Ready to Start Your Research?

Download this dataset directly from the official repository and start building your next breakthrough project.

Download Dataset

Related Topics & Keywords

Share This Research

More in Industrial IoT / Network Security

View All