ToN_IoT: Telemetry, Operating Systems, and Network Traffic
Catalog Summary
"ToN_IoT is a large-scale dataset featuring heterogeneous data from IoT sensors, operating systems, and network traffic for advanced intrusion detection research in Industry 4.0."
Catalog Notes
Comprehensive IoT/IIoT Security
The ToN_IoT datasets were collected from a realistic network designed at the Cyber Range and IoT Labs at UNSW Canberra. It integrates data from three distinct layers: IoT, Cloud, and Edge/Fog systems.
Data Sources and Formats
- Telemetry Data: Logged from 10+ sensors including weather and Modbus protocols in CSV/log formats.
- Network Traffic: Captured in PCAP and ZEEK logs, simulating DDoS and Ransomware attacks.
- OS Logs: Detailed audit traces from Windows 7/10 and Ubuntu systems for host-based analysis.
Research Applications
Ideal for training federated learning models and evaluating the efficiency of AI-based security systems across hybrid IoT environments.
View Data Structure
To explore column names, data types, and sample rows, visit the official dataset page on UNSW Canberra.
Preview on UNSW CanberraCite This Dataset
The dataset creators ask users of this dataset to cite the accompanying paper. Use one of the verified formats below.
Moustafa, N. (2021). A new distributed architecture for evaluating AI-based security systems: Network TON_IoT datasets. Sustainable Cities and Society. https://research.unsw.edu.au/projects/toniot-datasets
Source metadata: UNSW Canberra (2021)
Indexed by IoTDataset.com on Feb 15, 2026
Review the Source Record
Confirm the licence, version, access conditions, file format, and provenance at the source before use.