{"url":"/dataset/iot-benign-and-attack-traces","name":"IoT Benign and Attack Traces","full_name":"IoT Benign and Attack Traces -  Data Collected for ACM SOSR 2019","description_markdown":"**IOT BENIGN AND ATTACK TRACES**\r\n\r\n# Data Collected for ACM SOSR 2019\r\n\r\n# Attack & Benign Data\r\n\r\n# Instructions\r\n\r\n[Flow data](https://iotanalytics.unsw.edu.au/anomaly-data/flowdata.zip) contains flow counters of MUD flow, each instance in the file are collected every one minute.\r\n[Annotations](https://iotanalytics.unsw.edu.au/anomaly-data/annotations.zip) contains information about the start, end time of the attack and corresponsing MUD flows that are impacted through the Attack. More information about the device and the attacker can be found in [here](https://iotanalytics.unsw.edu.au/anomaly-data/attackinfo.xlsx)\r\n Below is an example of the annotations from the Samsung smart camera.\r\n eg: \"1527838552,1527839153,Localfeatures|Arpfeatures,ArpSpoof100L2D\"\r\n The above line indicates that the start time of the attack to be 1527838552 and end time is 1527839153. \"Localfeatures|Arpfeatures\" explains that it should impact the local communication and ARP protocol. \"ArpSpoof100L2D\" means that the attack was arpspoof lauched with the maximum rate of 100 packets per seconds. In order to identify the attack rows in flow stats you can use below condition.\r\n \"if (flowtime \\>= startTime\\*1000 and endTime\\*1000\\>=flowtime) then attack = true\" -- This corresponds to the line 4470 to 4479 in the samsung smart camera.\r\n\r\n# Cite our data\r\n\r\nA. Hamza, H. Habibi Gharakheili, T. Benson, V. Sivaraman, \"Detecting Volumetric Attacks on IoT Devices via SDN-Based Monitoring of MUD Activity\", ACM SOSR, San Jose, California, USA, Apr 2019.\r\n\r\n# Source code\r\n\r\n[https://github.com/ayyoob/mud-ie](https://github.com/ayyoob/mud-ie)\r\n\r\n# Contact\r\n\r\n[ayyoobhamza@student.unsw.edu.au](https://github.com/ayyoob/mud-ie)","description_withheld":null,"homepage":"https://iotanalytics.unsw.edu.au/attack-data.html","introduced_date":null,"introduced_date_note":null,"introduced_by":null,"license":null,"modalities":[],"tasks":[{"name":"Network Intrusion Detection","url":"/task/network-intrusion-detection","datasets_with_task":"/datasets/task/network-intrusion-detection"}],"languages":[],"variants":["IoT Benign and Attack Traces"],"data_loaders":[],"num_papers_in_archive":2,"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28"},"benchmarks":[],"papers_with_a_benchmark_row":[],"syntology_totals":{"read_at":"2026-09-24T18:15:14+00:00","papers_with_samples":0,"samples_harvested":0,"samples_ran":0,"samples_unverified":0,"pointer_only_for_licence":0,"papers_with_no_sample_that_ran":0,"note":"the per-paper counts above, summed; not a rate"},"papers_note":"The archive never published its papers-using-dataset list; these are papers with a leaderboard row on this dataset's benchmarks."}