SD-IoT MQTT/CoAP DDoS Dataset

Published: 24 November 2025| Version 1 | DOI: 10.17632/vzsg6rrscp.1
Contributors:
Fauzi Sumadi,

Description

The dataset comprises Mininet simulations of Distributed Denial of Service (DDoS) and standard traffic, utilizing public-domain IP addresses. These simulations were gathered from four distinct Internet of Things (IoT) networks managed by L3 Forwarding application, where the IoT servers facilitate MQTT and CoAP services. The DDoS attacks were executed using Tcpreplay on a Packet Capture (PCAP) file, and the dataset was compiled through a single Software-Defined IoT (SD-IoT) controller (RYU) in accordance with the OpenFlow standard. This process included the extraction of PacketIn header information as well as port statistics data. The dataset encompasses 26 features and 10 labels, concentrating specifically on MQTT services (CONNECT, SUBSCRIBE, and PUBLISH) and CoAP services (GET and POST).

Files

Institutions

  • King Abdulaziz University

Categories

Cybersecurity, Denial-of-Service Attack, Software Defined Network, Internet of Things, Data Analytics Cybersecurity

Licence