Skip to main content
Zenodo

IoT Emulated ICMP/Ping Dataset — Normal and Malicious Traffic [3.2 GB PCAP]

IoT Security & Intrusion Detection Network Security
125 views
2 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"IoT IDS dataset for distinguishing normal and malicious ICMP/Ping traffic generated from an ESP-01s embedded device. PCAP, Zeek logs, and labelled CSV files."

Catalog Notes

Overview

This Zenodo dataset provides normal and malicious ICMP/Ping traffic generated from an embedded IoT device. It is explicitly related to intrusion detection systems, computer network traffic, and IoT security.

The data generation sequence starts with raw PCAP network traffic generated by an ESP-01s device. The PCAP files are then transformed into Zeek log files, and the logs are extracted into labelled CSV files prepared for machine-learning analysis.

The dataset is useful for studying ICMP flood and Ping flood behaviour in lightweight IoT environments and for evaluating ML-based detection of malicious ICMP/Ping activity.

Column Schema

ColumnDescription
pcap_fileRaw ICMP/Ping packet-capture file generated from the ESP-01s device.
zeek_logZeek log extracted from the raw PCAP traffic.
csv_recordLabelled CSV record derived from Zeek log extraction.
traffic_typeNormal or malicious ICMP/Ping traffic category.
labelMachine-learning label used to distinguish normal and malicious traffic.

Key Statistics

  • Total Records: Labelled CSV files extracted from Zeek logs; row count not specified on the Zenodo page
  • Features: Zeek-derived flow information for ICMP/Ping traffic
  • File Format: PCAP, Zeek logs, CSV
  • File Size: Raw PCAP archive 3.2 GB; Zeek logs 1.4 MB; extracted CSV dataset 8.8 kB
  • Time Period: Published March 26, 2023; modified July 4, 2023
  • Device: ESP-01s embedded IoT device

Use Cases

  • ICMP/Ping flood intrusion detection
  • Embedded IoT traffic classification
  • Zeek-to-CSV feature extraction workflows
  • Machine-learning evaluation for lightweight IoT network attacks

Source & Attribution

Created by Omar Almorabea, Tariq Khanzada, Muhammad Aslam, Fatheah Hendi, and Ahmad Almorabea. Published on Zenodo with DOI 10.5281/zenodo.7772015 and licensed under CC BY 4.0.

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on Zenodo.

Preview on Zenodo

Cite This Dataset

Almorabea, O., Khanzada, T., Aslam, M., Hendi, F., & Almorabea, A. (2023). IoT Emulated Dataset for ICMP/Ping Normal and Malicious Traffic. [Dataset]. Zenodo. https://doi.org/10.5281/zenodo.7772015

Source metadata: Zenodo (2023) · DOI: 10.5281/zenodo.7772015

Indexed by IoTDataset.com on Jun 02, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Network Security University

MQTT-IoT-IDS2020 — MQTT Internet of Things IDS Dataset

MQTT IoT IDS dataset from a simulated network with 12 sensors, broker, camera, and attacker. PCAP and CSV features support MQTT intrusion detection research.

Jun 02, 2026
Cybersecurity Kaggle

TON_IoT Network Dataset - UNSW Cyber Range Lab Collection

Comprehensive network traffic dataset from UNSW Canberra Cyber Range Lab capturing benign and malicious flows in simulated IoT/IIoT smart environments using Argus and Zeek (Bro) tools.

Jan 22, 2026
Cybersecurity University

MedBIoT — Medium-Sized IoT Botnet IDS Dataset [83 devices]

IoT botnet IDS dataset using 83 real and emulated devices with Mirai, BashLite, and Torii traffic. Raw PCAP files support botnet and anomaly detection research.

Jun 02, 2026
Cybersecurity Kaggle

RT-IoT2022 - Real-Time IoT Infrastructure Intrusion Detection

A comprehensive dataset derived from real-time IoT infrastructure, designed for intrusion detection research and network security analysis.

Feb 19, 2026
Cybersecurity Mendeley Data

MQTTEEB-D: Real-World IoT Cybersecurity Dataset for AI-Powered Threat Detection in MQTT Networks

A real-world cybersecurity dataset capturing MQTT-based IoT network traffic with live attacks and anomalous behavior. Collected from an active deployment with multiple attack types including DoS, SlowITe, and malformed injections. Provides both raw and preprocessed CSV files with rich metadata for intrusion detection and anomaly classification research.

Feb 07, 2026
Cybersecurity Kaggle

IoT-23 Network Traffic Dataset - Full Collection

Large-scale labeled network traffic captures (PCAPs) from IoT devices. Based on Stratosphere Laboratory's famous IoT-23 dataset with botnet and normal traffic patterns.

Jan 21, 2026

Explore other topics

All topics →