Skip to main content
University

MedBIoT — Medium-Sized IoT Botnet IDS Dataset [83 devices]

Cybersecurity
8 views
2 min read
License

Abstract

"IoT botnet IDS dataset using 83 real and emulated devices with Mirai, BashLite, and Torii traffic. Raw PCAP files support botnet and anomaly detection research."

Description

Overview

MedBIoT is a medium-sized IoT botnet dataset built to address the shortage of labelled data for IoT botnet detection. It combines real and emulated IoT devices in a network of 83 devices.

The dataset contains legitimate traffic and real malware network data. Three botnet malware families were deployed: Mirai, BashLite, and Torii. The traffic focuses on early botnet stages, including spreading and command-and-control communication.

The dataset is provided as raw PCAP files in bulk and fine-grained formats. Files are labelled according to traffic source, malware family, botnet phase, and device type, enabling feature extraction for supervised and unsupervised IDS experiments.

Column Schema

ColumnDescription
pcap_fileRaw packet-capture filename indicating source, phase, and device type.
traffic_sourceLegitimate or malware traffic source.
botnet_familyMirai, BashLite, Torii, or none for legitimate traffic.
botnet_phaseBotnet phase such as spreading or command-and-control.
device_typeReal or emulated IoT device type such as switch, light bulb, lock, fan, or light.
labelBenign or malicious label derived from the PCAP file grouping.

Key Statistics

  • Total Records: Raw PCAP traffic files; packet count not stated on the primary dataset page
  • Features: Extractable packet and flow features from PCAP files
  • File Format: PCAP
  • File Size: Not specified on the primary dataset page
  • Time Period: Public release date February 27, 2020
  • Devices: 83 real and emulated IoT devices
  • Malware Families: Mirai, BashLite, Torii

Use Cases

  • IoT botnet intrusion detection
  • Malware family classification
  • Early-stage botnet propagation and C&C detection
  • Anomaly and outlier detection in IoT networks

Source & Attribution

Created by Alejandro Guerra Manzanares, Jorge Alberto Medina Galindo, Hayretdin Bahsi, and Sven Nõmm at Tallinn University of Technology. The dataset page requests citation of the ICISSP 2020 paper with DOI 10.5220/0009187802070218.

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on University.

Preview on University

Cite This Dataset

Guerra-Manzanares, Alejandro, Medina-Galindo, Jorge Alberto, Bahsi, Hayretdin, & Nõmm, Sven (2020). MedBIoT — Medium-Sized IoT Botnet IDS Dataset [83 devices]. Proceedings of the 6th International Conference on Information Systems Security and Privacy - ICISSP. [Dataset]. SciTePress. https://doi.org/10.5220/0009187802070218

Source: SciTePress (2020) · DOI: 10.5220/0009187802070218

Indexed by IoTDataset.com on Jun 02, 2026

Ready to Start Your Research?

Download this dataset directly from the official repository and start building your next breakthrough project.

Download Dataset

Related Topics & Keywords

Share This Research

More in Cybersecurity

View All