Skip to main content
UCI

N-BaIoT: Real IoT Botnet Traffic from 9 Infected Devices [7M Records, Mirai & BASHLITE]

IoT Security & Intrusion Detection Cybersecurity
456 views
2 min read
License
Catalog metadata: This page is a discovery record, not publisher documentation. Verify the description, schema, provenance, version, licence, and citation at the linked source before use.

Catalog Summary

"Real IoT botnet traffic dataset from 9 commercial devices (webcams, routers, thermostats) authentically infected by Mirai and BASHLITE. Over 7M records, 115 statistical features. CSV format. Benchmark for deep-learning-based IoT anomaly and botnet detection."

Catalog Notes

Overview

N-BaIoT (Network-Based Detection of IoT Botnet Attacks) was created to address a critical gap in the field: the absence of real, device-level IoT botnet traffic in publicly available datasets. This dataset collects authentic traffic from nine commercial IoT devices genuinely infected by two of the most destructive botnet families ever observed — Mirai and BASHLITE.

The nine devices include a Danmini doorbell, Ecobee thermostat, Ennio doorbell, Philips B120N baby monitor, Provision PT-737E and PT-838 security cameras, Samsung SNH 1011 N webcam, and SimpleHome XCS7 1002 WHT and XCS7 1003 WHT webcams.

The dataset captures 115 statistical features engineered from raw network traffic including packet stream statistics (weight, mean, std, radius, magnitude, covariance, Pearson correlation) computed over multiple time windows. Mirai attack types: Scan, Ack flood, Syn flood, UDP flood, UDP-plain. BASHLITE attack types: Scan, Junk, UDP flood, TCP flood, COMBO.

Column Schema

ColumnDescription
MI_dir_L5_weightStatistical weight of last 5 packets from/to device.
MI_dir_L5_meanMean of last 5 packet stream statistics.
MI_dir_L5_varianceVariance of last 5 packet stream statistics.
H_L5_weightHost-level stream weight (last 5 packets).
HH_jit_L5_meanHost-host jitter mean over last 5 packets.
HH_jit_L5_stdHost-host jitter std deviation over last 5 packets.
[109 more features]Multi-window stream statistics (L5, L3, L1, L0.1, L0.01).

Key Statistics

  • Total Records: 7,062,606 across all 9 device sub-datasets
  • IoT Devices: 9 commercial devices
  • Botnet Families: Mirai (5 attack types) and BASHLITE (5 attack types)
  • Features: 115 statistical network flow features
  • File Format: CSV (one sub-dataset per device)
  • Donated to UCI: March 2018

Use Cases

  • Deep autoencoder-based IoT botnet detection
  • Anomaly detection benchmarking using real per-device IoT traffic
  • Transfer learning across device types for generalized IoT security models
  • Multi-class attack classification: Mirai vs BASHLITE vs Benign

Source and Attribution

Created by Yair Meidan et al. at Ben-Gurion University of the Negev. Published in IEEE Pervasive Computing (2018) and hosted on UCI Machine Learning Repository.

View Data Structure

To explore column names, data types, and sample rows, visit the official dataset page on UCI.

Preview on UCI

Cite This Dataset

Meidan, Yair, Bohadana, Michael, Mathov, Yael, Mirsky, Yisroel, Breitenbacher, Dominik, , Asaf,, & Shabtai, Asaf (2018). detection_of_IoT_botnet_attacks_N_BaIoT. [Dataset]. UCI. https://archive.ics.uci.edu/dataset/442/detection+of+iot+botnet+attacks+n+baiot

Source metadata: UCI (2018)

Indexed by IoTDataset.com on May 03, 2026

Review the Source Record

Confirm the licence, version, access conditions, file format, and provenance at the source before use.

Open Source Page

Related Topics & Keywords

Browse all IoT Security & Intrusion Detection datasets

Share This Research

More in IoT Security & Intrusion Detection

View All
Network Security University

CICIoT2023: Real-Time IoT Attack Dataset [47M+ Labeled Flows, 33 Attack Types]

Large-scale IoT cybersecurity dataset with 47M+ labeled network flows from 105 real IoT devices across 33 attack types in 7 categories. PCAP and CSV formats. Built for IDS/IPS development and ML-based IoT traffic classification research.

Apr 13, 2026
Network Security Kaggle

IoTID20: IoT Network Intrusion Dataset [625K Flows, 4 Attack Types, 83 Features]

Smart-home-derived IoT botnet dataset with 625,783 labeled flow records and 83 network features. Covers DoS, Mirai, MITM, and Scan attacks from EZVIZ and SKT NGU Wi-Fi cameras. CSV format. Supports binary, category, and sub-category IDS classification tasks.

Apr 13, 2026
Cybersecurity Zenodo

IoT-23; Labeled IoT Malware & Benign Traffic [325M Flows, 500+ Hours]

Real IoT malware traffic dataset with 325M labeled network flows from 20 malware and 3 benign device captures over 500+ hours. PCAP and Zeek conn.log formats. Used for IoT botnet detection, malware traffic classification, and ML security research.

Apr 13, 2026
Cybersecurity Kaggle

Edge-IIoTset: Comprehensive IoT & IIoT Cyber Security Dataset [~12 GB, 15 Attack Types]

Realistic IoT/IIoT cybersecurity dataset supporting centralized and federated learning with 15 attack types across network, application, and protocol layers. CSV and PCAP formats (~12 GB). Available via IEEE Dataport and Kaggle. Designed for edge computing IDS research.

Apr 13, 2026
Network Security UCI

RT-IoT2022: Real-Time IoT IDS Dataset [41 Features, Multi-Attack]

Real-time IoT network security dataset from a live IoT infrastructure with 41 bidirectional flow features. Includes ThingSpeak-LED, Wipro-Bulb, and MQTT-Temp devices with SSH brute force, DDoS (Hping/Slowloris), and Nmap attack scenarios. CSV format. Used for adaptive IDS development.

Apr 13, 2026
Network Security University

TON_IoT: UNSW Telemetry, Network & OS Attack Traces [Multi-Source IIoT]

Heterogeneous IoT/IIoT dataset from UNSW Canberra Cyber Range with network traffic, Windows/Linux OS traces, and IoT sensor telemetry. Labeled for 9 attack types including DoS, DDoS, ransomware, and XSS. CSV and PCAP formats. Benchmark for AI-based IDS evaluation.

Apr 13, 2026

Explore other topics

All topics →