Skip to main content
University

MedBIoT — Medium-Sized IoT Botnet IDS Dataset [83 devices]

IoT Security & Intrusion Detection Cybersecurity
162 views
2 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"IoT botnet IDS dataset using 83 real and emulated devices with Mirai, BashLite, and Torii traffic. Raw PCAP files support botnet and anomaly detection research."

Catalog Notes

Overview

MedBIoT is a medium-sized IoT botnet dataset built to address the shortage of labelled data for IoT botnet detection. It combines real and emulated IoT devices in a network of 83 devices.

The dataset contains legitimate traffic and real malware network data. Three botnet malware families were deployed: Mirai, BashLite, and Torii. The traffic focuses on early botnet stages, including spreading and command-and-control communication.

The dataset is provided as raw PCAP files in bulk and fine-grained formats. Files are labelled according to traffic source, malware family, botnet phase, and device type, enabling feature extraction for supervised and unsupervised IDS experiments.

Column Schema

ColumnDescription
pcap_fileRaw packet-capture filename indicating source, phase, and device type.
traffic_sourceLegitimate or malware traffic source.
botnet_familyMirai, BashLite, Torii, or none for legitimate traffic.
botnet_phaseBotnet phase such as spreading or command-and-control.
device_typeReal or emulated IoT device type such as switch, light bulb, lock, fan, or light.
labelBenign or malicious label derived from the PCAP file grouping.

Key Statistics

  • Total Records: Raw PCAP traffic files; packet count not stated on the primary dataset page
  • Features: Extractable packet and flow features from PCAP files
  • File Format: PCAP
  • File Size: Not specified on the primary dataset page
  • Time Period: Public release date February 27, 2020
  • Devices: 83 real and emulated IoT devices
  • Malware Families: Mirai, BashLite, Torii

Use Cases

  • IoT botnet intrusion detection
  • Malware family classification
  • Early-stage botnet propagation and C&C detection
  • Anomaly and outlier detection in IoT networks

Source & Attribution

Created by Alejandro Guerra Manzanares, Jorge Alberto Medina Galindo, Hayretdin Bahsi, and Sven Nõmm at Tallinn University of Technology. The dataset page requests citation of the ICISSP 2020 paper with DOI 10.5220/0009187802070218.

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on University.

Preview on University

Cite This Dataset

Guerra-Manzanares, A., Medina-Galindo, J. A., Bahsi, H., & Nõmm, S. (2020). MedBIoT: Generation of an IoT Botnet Dataset in a Medium-sized IoT Network. [Dataset]. SciTePress. https://doi.org/10.5220/0009187802070218

Source metadata: SciTePress (2020) · DOI: 10.5220/0009187802070218

Indexed by IoTDataset.com on Jun 02, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Cybersecurity Zenodo

IoT-23; Labeled IoT Malware & Benign Traffic [325M Flows, 500+ Hours]

Real IoT malware traffic dataset with 325M labeled network flows from 20 malware and 3 benign device captures over 500+ hours. PCAP and Zeek conn.log formats. Used for IoT botnet detection, malware traffic classification, and ML security research.

Apr 13, 2026
Network Security Zenodo

IoT Emulated ICMP/Ping Dataset — Normal and Malicious Traffic [3.2 GB PCAP]

IoT IDS dataset for distinguishing normal and malicious ICMP/Ping traffic generated from an ESP-01s embedded device. PCAP, Zeek logs, and labelled CSV files.

Jun 02, 2026
Network Security IoT Stratosphere Lab

IoT-23: A Labeled Dataset with Malicious and Benign IoT Network Traffic

Comprehensive dataset from Stratosphere Laboratory containing network traffic from 23 IoT malware captures including Mirai and Torii botnets, with over 325 million labeled connections for cybersecurity research and ML-based threat detection.

Jan 16, 2026
Cybersecurity UCI

N-BaIoT: Real IoT Botnet Traffic from 9 Infected Devices [7M Records, Mirai & BASHLITE]

Real IoT botnet traffic dataset from 9 commercial devices (webcams, routers, thermostats) authentically infected by Mirai and BASHLITE. Over 7M records, 115 statistical features. CSV format. Benchmark for deep-learning-based IoT anomaly and botnet detection.

May 03, 2026
Cybersecurity Kaggle

RT-IoT2022 - Real-Time IoT Infrastructure Intrusion Detection

A comprehensive dataset derived from real-time IoT infrastructure, designed for intrusion detection research and network security analysis.

Feb 19, 2026
Cybersecurity Kaggle

Gotham Dataset 2025: Large-Scale Federated IoT IDS Benchmark

The Gotham Dataset is a large-scale, reproducible benchmark for evaluating decentralized Intrusion Detection Systems (IDS) and Federated Learning in virtualized smart cities. It captures interface-level network traffic from 78 heterogeneous IoT devices, including complex attack vectors like Mirai botnets, Merlin C2 traffic, and CoAP amplification, preserving the non-IID nature of edge data for realistic AI security training.

Feb 05, 2026

Explore other topics

All topics →