Skip to main content
Kaggle

N-BaIoT Dataset - IoT Botnet Attack Detection from Network Traffic

IoT Security & Intrusion Detection Cybersecurity
1,560 views
2 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"Specialized dataset for detecting IoT botnet attacks using network traffic analysis. Captures behavior of 9 real IoT devices infected with Mirai and BASHLITE malware variants. Ideal for training ML models to identify compromised IoT devices through traffic patterns."

Catalog Notes

Dataset Introduction

The N-BaIoT dataset focuses specifically on detecting botnet-infected IoT devices through network traffic behavioral analysis. This dataset addresses the growing threat of IoT botnets like Mirai that compromised millions of devices worldwide for massive DDoS attacks.

Device Coverage - 9 Real IoT Devices

Network traffic captured from authentic commercial IoT devices:

  • Smart Home: Doorbell, baby monitor, security camera, thermostat
  • Entertainment: Smart TV, streaming device
  • Connectivity: WiFi extenders, network cameras
  • Storage: Network-attached storage (NAS) devices

Malware Variants Simulated

Mirai Botnet

The notorious malware that infected IoT devices using default credentials, creating the largest botnet in history responsible for record-breaking DDoS attacks. The dataset includes multiple Mirai attack variants:

  • UDP flooding
  • TCP connection flooding
  • HTTP flooding
  • Junk packet transmission

BASHLITE (Gafgyt)

Another prevalent IoT botnet exploiting shell vulnerabilities. Multiple BASHLITE variants captured with different attack patterns and command-and-control behaviors.

Behavioral Feature Extraction

Rather than raw packet analysis, the dataset provides extracted behavioral features characterizing device communication patterns:

  • Statistical Features: Packet size distributions, inter-arrival times, flow durations
  • Behavioral Metrics: Connection patterns, protocol usage, destination diversity
  • Temporal Patterns: Time-based traffic characteristics revealing botnet activity cycles

Binary Classification Focus

Each device has separate datasets for:

  • Benign Traffic: Normal operational behavior baseline
  • Infected Traffic: Behavior after malware infection for each variant

This structure enables training precise binary classifiers (normal vs compromised) for each device type.

Research Advantages

Real Device Traffic

Unlike simulated datasets, N-BaIoT uses actual commercial IoT devices, capturing authentic protocol implementations and manufacturer-specific behaviors.

Device-Specific Models

Separate datasets per device allow researchers to develop device-specific detection models that account for unique operational characteristics.

Lightweight Detection

Behavioral features enable efficient detection suitable for deployment on IoT gateways with limited computational resources.

Machine Learning Applications

  • Anomaly Detection: Identify deviations from normal device behavior
  • Binary Classification: Classify traffic as benign or botnet-infected
  • Multi-Class Classification: Identify specific malware variants
  • Ensemble Methods: Combine device-specific models for network-wide protection

Practical Deployment

Models trained on N-BaIoT can be deployed at network edge or on IoT gateways to provide real-time detection of compromised devices, enabling rapid quarantine before they participate in botnet attacks.

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on Kaggle.

Preview on Kaggle

Cite This Dataset

M. Kashif (2020). N-BaIoT Dataset to Detect IoT Botnet Attacks. [Dataset]. Kaggle. https://www.kaggle.com/datasets/mkashifn/nbaiot-dataset

Source metadata: Kaggle (2020)

Indexed by IoTDataset.com on Jan 23, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
IoT Cybersecurity UCI Machine Learning Repository

RT-IoT2022

Real-time network traffic dataset from diverse IoT devices including normal behavior and various attacks (DDoS, brute-force, scans) for developing intrusion detection systems.

Jan 26, 2026
Cybersecurity / IoT Network Security University (Canadian Institute for Cybersecurity)

CICIDS2017 - Comprehensive Network Intrusion Detection Dataset

The most cited cybersecurity dataset worldwide with 2.8+ million network flows capturing 14 types of realistic attack scenarios including DDoS, brute force, botnet, and web attacks alongside benign traffic for advanced intrusion detection systems.

Jan 20, 2026
Cybersecurity IoTSyn Generated

Synthetic IoT Intrusion Detection Dataset — 18% Attacks

Free CC0 synthetic dataset: 500 rows of labelled network flows covering DoS, DDoS, botnet and reconnaissance traffic. 18% Attacks.

Apr 04, 2026
Cybersecurity CIC Repository

CICIoT2023: Large-Scale IoT Attack Traffic Dataset

CICIoT2023 is a large-scale, flow-based network traffic dataset capturing real-time benign and malicious communications in an IoT environment composed of 105 physical devices. The dataset captures traffic traces for 33 attack scenarios grouped into seven categories: DDoS, DoS, Reconnaissance, web-based attacks, brute-force attempts, spoofing, and Mirai malware.

Feb 05, 2026
Cybersecurity University

RT-IoT2022: Real-Time IoT Intrusion Detection Dataset

123,117 network flow records with 83 features from real IoT devices (MQTT, ThingSpeak, Wipro) including DDoS, SSH brute-force, and Nmap attacks for IDS model training.

Jan 12, 2026
Cybersecurity Kaggle

Gotham Dataset 2025: Large-Scale Federated IoT IDS Benchmark

The Gotham Dataset is a large-scale, reproducible benchmark for evaluating decentralized Intrusion Detection Systems (IDS) and Federated Learning in virtualized smart cities. It captures interface-level network traffic from 78 heterogeneous IoT devices, including complex attack vectors like Mirai botnets, Merlin C2 traffic, and CoAP amplification, preserving the non-IID nature of edge data for realistic AI security training.

Feb 05, 2026

Explore other topics

All topics →