IoT-DH: IoT DDoS Honeypot Dataset for Attack Analysis
Catalog Summary
"Comprehensive honeypot dataset for analyzing DDoS attacks on IoT devices, containing 10 key attributes from PCAP data converted to CSV format."
Catalog Notes
Dataset Overview
The IoT DDoS Honeypot Dataset is a comprehensive collection designed to enhance our understanding of Distributed Denial of Service (DDoS) attacks targeting IoT devices. The data was collected from a specially designed honeypot system to attract real-world cyberattacks.
Key Features
- 10 key attributes for comprehensive analysis
- Real data from honeypot deployment
- Conversion from PCAP to CSV for accessibility
- Detailed information about attacker tactics and techniques
- Focus on DDoS attack patterns specific to IoT
Data Structure/Columns
The dataset contains 10 specific attributes:
- dt: Timestamp of the packet
- dur: Duration in seconds
- dur_nsec: Duration in nanoseconds
- tot_dur: Total duration
- pktrate: Packet rate
- protocol: Network protocol (TCP/UDP/ICMP)
- port_no: Port number
- tx_kbps: Transmission speed (kbps)
- rx_kbps: Reception speed (kbps)
- tot_kbps: Total bandwidth (kbps)
- label: Attack classification (Benign/Attack)
Data Collection Method
Data was collected using a honeypot system specifically designed to attract DDoS attacks on IoT devices. The data was recorded in PCAP format and then converted to CSV for ease of access and analysis in machine learning applications.
Research Applications
- Analysis of DDoS attack patterns on IoT
- Threat intelligence and threat identification
- Study of attacker tactics and techniques
- Development of defense mechanisms
- Network traffic profiling for IoT security
Machine Learning Use Cases
- Binary classification (Benign vs Attack)
- DDoS attack detection models
- Traffic pattern analysis
- Real-time anomaly detection
- Bandwidth-based attack identification
Data Preview
| dt | dur | dur_nsec | tot_dur | pktrate | protocol | port_no | tx_kbps | rx_kbps | tot_kbps | label |
|---|---|---|---|---|---|---|---|---|---|---|
| 2024-01-10 08:15:23 | 1.250 | 1250000000 | 2.5 | 150 | TCP | 80 | 512.3 | 128.7 | 641.0 | Benign |
| 2024-01-10 08:16:45 | 0.050 | 50000000 | 0.1 | 8500 | UDP | 53 | 9876.5 | 234.2 | 10110.7 | Attack |
| 2024-01-10 08:17:12 | 2.100 | 2100000000 | 4.2 | 95 | ICMP | 0 | 256.1 | 198.4 | 454.5 | Benign |
Showing first few rows for preview
Provided Citation
IoT DDoS Honeypot Dataset, Mendeley Data, 2024. DOI: 10.17632/8dns3xbckv.1.
This citation is displayed as supplied. Automatic style conversion is disabled because structured citation metadata is not recorded.
Source metadata: Mendeley (2026)
Indexed by IoTDataset.com on Jan 16, 2026
Review the Source Record
Confirm the licence, version, access conditions, file format, and provenance at the source before use.