TON_IoT Network Dataset - UNSW Cyber Range Lab Collection
Catalog Summary
"Comprehensive network traffic dataset from UNSW Canberra Cyber Range Lab capturing benign and malicious flows in simulated IoT/IIoT smart environments using Argus and Zeek (Bro) tools."
Catalog Notes
Dataset Overview
The TON_IoT dataset is a flagship cybersecurity collection developed by the Cyber Range Lab of UNSW Canberra, specifically designed for IoT and Industrial IoT (IIoT) intrusion detection research. This dataset captures realistic network traffic from a sophisticated testbed simulating smart home and industrial environments.
Technical Specifications
- Total Records: 211,043 network flows
- Features: 44 detailed network attributes including packet statistics, byte counts, protocol flags, connection states, and timing metrics
- File Size: 29.9 MB (CSV format)
- Capture Tools: Argus flow analyzer and Zeek (formerly Bro) network security monitor
- Environment: Simulated smart home with IoT/IIoT devices including sensors, smart appliances, and industrial controllers
Attack Scenarios Included
The dataset contains labeled traffic for multiple attack vectors including DDoS attacks, backdoor exploits, injection attacks, scanning activities, and ransomware patterns. The dataset exhibits realistic class imbalance with 159,084 benign flows making it ideal for testing machine learning models under realistic conditions.
View Data Structure
To explore column names, data types, and sample rows, visit the official dataset page on Kaggle.
Preview on KaggleCite This Dataset
Arnob Bhowmik (2025). TON_IoT Network Dataset. [Dataset]. Kaggle. https://www.kaggle.com/datasets/arnobbhowmik/ton-iot-network-dataset
Source metadata: Kaggle (2025)
Indexed by IoTDataset.com on Jan 22, 2026
Review the Source Record
Confirm the licence, version, access conditions, file format, and provenance at the source before use.