Skip to main content
Mendeley Data

MQTT DoS DDoS IoT Attack Dataset

IoT Security & Intrusion Detection IoT Security / MQTT DoS and DDoS
394 views
2 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"An MQTT DoS and DDoS IoT attack dataset collected on a Raspberry Pi 3B+ Mosquitto broker over 12 sessions, including three days of normal traffic and several minutes of attack traffic, totaling 424,716 labeled entries for machine learning-based IDS and IPS research."

Catalog Notes

Overview

The MQTT DoS DDoS IoT Attack dataset is a publicly available collection of MQTT traffic focusing on denial-of-service (DoS) and distributed denial-of-service (DDoS) attacks against IoT systems. It is published on Mendeley Data and provides labeled records suitable for intrusion detection and prevention research.

Data Collection Setup

  • Data collected on a Raspberry Pi 3B+ running a Mosquitto MQTT broker and acting as MQTT client host for four publishers and eight subscribers.
  • Traffic captured with Wireshark over 12 sessions using the Terminator terminal on Ubuntu 20.
  • Normal traffic generated over 72 hours (three days), producing approximately 142,000 data entries.
  • Attack traffic generated for 2–3 minutes using tools such as hping3 and LOIC, resulting in hundreds of thousands of records.
  • The complete dataset contains 424,716 harvested entries exported to a single labeled CSV file.

Features and Use

  • Dataset fields are chosen to reflect parameters most affected by DDoS attacks, emphasizing timing and volume-related characteristics.
  • Records are labeled as normal or attack, enabling supervised learning approaches.
  • Intended for research using machine learning and deep learning models for IDS and IPS in MQTT-based IoT networks.

Access and License

The dataset is hosted on Mendeley Data under DOI 10.17632/gt37rfwtb5.1. It is provided for research purposes; licensing and reuse conditions are specified on the Mendeley dataset page.

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on Mendeley Data.

Preview on Mendeley Data

Cite This Dataset

Elsevier (2022). MQTT DoS DDoS IoT Attack dataset. [Dataset]. Elsevier. https://doi.org/10.17632/gt37rfwtb5.1

Source metadata: Elsevier (2022) · DOI: 10.17632/gt37rfwtb5.1

Indexed by IoTDataset.com on Feb 03, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
IoT Security / MQTT Intrusion Detection Data in Brief (Elsevier) + Mendeley Data

MQTTEEB-D: A Real-World IoT Cybersecurity Dataset for AI-Powered Threat Detection in MQTT Networks

A real-world MQTT-based IoT cybersecurity dataset collected from the MQTTEEB testbed at the International University of Rabat, with benign traffic and five attack types (DoS, SlowITe, Malformed Data Injection, Brute Force, Publish Flooding), provided in multiple processed forms (raw, cleaned, normalized, standardized, SMOTE) for AI-driven intrusion detection research.

Feb 03, 2026
Cybersecurity IoTSyn Generated

Synthetic IoT Intrusion Detection Dataset — 18% Attacks

Free CC0 synthetic dataset: 500 rows of labelled network flows covering DoS, DDoS, botnet and reconnaissance traffic. 18% Attacks.

Apr 04, 2026
Cybersecurity Zenodo

Gotham Dataset 2025 - Large-Scale IoT Network Intrusion Detection

Reproducible large-scale IoT network dataset from 78 emulated devices using MQTT, CoAP, and RTSP protocols. Includes benign and malicious traffic with DoS, brute force, scanning, and C&C attacks in PCAP and CSV formats.

Mar 20, 2026
Cybersecurity Research Paper

MU-IoT - Comprehensive IoT Network Intrusion Dataset 2024

New realistic IoT network intrusion dataset (MU-IoT) with comprehensive attack scenarios for cybersecurity research. Published in IEEE 2024 with 4+ citations. Covers multiple IoT protocols and device types.

Jan 22, 2026
Network Security UCI

RT-IoT2022: Real-Time IoT IDS Dataset [41 Features, Multi-Attack]

Real-time IoT network security dataset from a live IoT infrastructure with 41 bidirectional flow features. Includes ThingSpeak-LED, Wipro-Bulb, and MQTT-Temp devices with SSH brute force, DDoS (Hping/Slowloris), and Nmap attack scenarios. CSV format. Used for adaptive IDS development.

Apr 13, 2026
Cybersecurity Kaggle

Edge-IIoTset: Comprehensive IoT & IIoT Cyber Security Dataset [~12 GB, 15 Attack Types]

Realistic IoT/IIoT cybersecurity dataset supporting centralized and federated learning with 15 attack types across network, application, and protocol layers. CSV and PCAP formats (~12 GB). Available via IEEE Dataport and Kaggle. Designed for edge computing IDS research.

Apr 13, 2026

Explore other topics

All topics →