arXiv:2502.03134cs.CRcs.AI2025-02被引 16

构建了78设备的物联网安全数据集,支持真实攻击检测研究。

Gotham Dataset 2025: A Reproducible Large-Scale IoT Network Dataset for Intrusion Detection and Security Research

  • 用模拟环境生成78个设备的物联网流量,覆盖多种协议。
  • 包含正常与多种攻击流量,如拒绝服务、暴力破解等。
  • 适合做入侵检测系统训练,数据公开可复现。

本文提出一个物联网网络流量数据集。该数据集基于名为Gotham的仿真大规模物联网网络测试平台生成,旨在为网络安全研究提供真实且异构的环境。测试平台包含78个模拟物联网设备,运行多种协议(如MQTT、CoAP、RTSP)。使用tcpdump以PCAP格式捕获网络流量,记录正常及恶意流量。恶意流量通过脚本化攻击生成,涵盖拒绝服务(DoS)、Telnet暴力破解、网络扫描、CoAP放大攻击以及命令与控制(C&C)通信等多个阶段。数据经Python处理,利用Tshark工具提取特征,并转换为带标签的CSV格式。数据仓库包含原始流量(PCAP)和处理后的标签数据(CSV)。采集方式为分布式,每台设备的流量在网关与设备接口处独立捕获。该数据集具备多样化的流量模式与攻击场景,为开发面向复杂大规模物联网环境的入侵检测系统和安全机制提供了宝贵资源。数据集已公开于Zenodo。

原文摘要 · Abstract (English)

In this paper, a dataset of IoT network traffic is presented. Our dataset was generated by utilising the Gotham testbed, an emulated large-scale Internet of Things (IoT) network designed to provide a realistic and heterogeneous environment for network security research. The testbed includes 78 emulated IoT devices operating on various protocols, including MQTT, CoAP, and RTSP. Network traffic was captured in Packet Capture (PCAP) format using tcpdump, and both benign and malicious traffic were recorded. Malicious traffic was generated through scripted attacks, covering a variety of attack types, such as Denial of Service (DoS), Telnet Brute Force, Network Scanning, CoAP Amplification, and various stages of Command and Control (C&C) communication. The data were subsequently processed in Python for feature extraction using the Tshark tool, and the resulting data was converted to Comma Separated Values (CSV) format and labelled. The data repository includes the raw network traffic in PCAP format and the processed labelled data in CSV format. Our dataset was collected in a distributed manner, where network traffic was captured separately for each IoT device at the interface between the IoT gateway and the device. Our dataset was collected in a distributed manner, where network traffic was separately captured for each IoT device at the interface between the IoT gateway and the device. With its diverse traffic patterns and attack scenarios, this dataset provides a valuable resource for developing Intrusion Detection Systems and security mechanisms tailored to complex, large-scale IoT environments. The dataset is publicly available at Zenodo.

物联网安全入侵检测数据集仿真

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。