MQTTEEB-D: A Real-World IoT Cybersecurity Dataset for AI-Powered Threat Detection in MQTT Networks
收藏资源简介:
This dataset accompanies the research article on MQTTEEB-D and is intended for public use in cybersecurity research. The MQTTEEB-D dataset is a practical real-world data set for intrusion detection improvement in Message Queuing Telemetry Transport (MQTT)-based Internet of Things (IoT) networks. In contrast to already existing datasets that are constructed on simulated network traffic, MQTTEEB-D is obtained from a real-time IoT deployment at the International University of Rabat (UIR), Morocco. Using MySignals IoT health sensors, Raspberry Pi 4, and an MQTT broker server, this dataset represents the actual complexity of the active IoT communication process, which synthetic data fails to offer. To narrow the gap between simulated and real-world attack scenarios, various cyberattacks including Denial of Service (DoS), Slow DoS against Internet of Things Environments (SlowITe), Malformed Data Injection, Brute Force, and MQTT publish flooding were carried out in real-time, permitting close monitoring of network traffic anomalies. The data was captured using Python wrapper for tshark (PyShark) and organized into multiple Comma-Separated Values (CSV) files. To ensure high data quality, we performed pre-processing steps, such as outlier removal, normalization, standardization, and class balance. Several processed forms (raw, cleaned, normalized, standardized, Synthetic Minority Over-sampling Technique (SMOTE)) applied for this dataset are provided, along with detailed metadata to facilitate ease of use in cybersecurity research. This dataset provides an opportunity for researchers to develop and validate intrusion detection models in a real-world MQTT environment - a critical ingredient in Artificial Intelligence (AI)-driven cybersecurity solutions for IoT networks. The dataset will support future research IoT security and anomaly detection domains.
本数据集配套于围绕MQTTEEB-D展开的研究论文,旨在供网络安全研究领域公开使用。MQTTEEB-D数据集是一款面向基于消息队列遥测传输(Message Queuing Telemetry Transport,简称MQTT)的物联网(Internet of Things,简称IoT)网络入侵检测优化任务的实用型真实世界数据集。与现有基于模拟网络流量构建的数据集不同,MQTTEEB-D的数据采集自摩洛哥拉巴特国际大学(International University of Rabat,简称UIR)的实时物联网部署环境。本数据集借助MySignals物联网健康传感器、树莓派4(Raspberry Pi 4)以及MQTT代理服务器完成采集,还原了活跃物联网通信流程的真实复杂度——这是合成数据无法实现的。为缩小模拟攻击场景与真实攻击场景之间的差距,研究团队在该环境中实时实施了多种网络攻击,包括拒绝服务(Denial of Service,简称DoS)、针对物联网环境的慢速拒绝服务(Slow DoS against Internet of Things Environments,简称SlowITe)、畸形数据注入、暴力破解(Brute Force)以及MQTT发布泛洪攻击,以此实现对网络流量异常的精准监测。研究人员使用Tshark的Python封装工具PyShark完成数据捕获,并将其整理为多个逗号分隔值(Comma-Separated Values,简称CSV)文件。为保障数据质量,研究团队执行了一系列预处理步骤,包括异常值剔除、归一化、标准化以及类别平衡处理。本数据集提供了多种预处理后的格式,包括原始数据、清洗后数据、归一化数据、标准化数据以及合成少数类过采样技术(Synthetic Minority Over-sampling Technique,简称SMOTE)处理后的数据,并附带详细的元数据,以方便网络安全研究中的便捷使用。本数据集为研究人员提供了在真实MQTT环境中开发并验证入侵检测模型的契机,而这类模型正是面向IoT网络的人工智能(Artificial Intelligence,简称AI)驱动型网络安全解决方案的核心组成部分。该数据集将为IoT安全与异常检测领域的未来研究提供有力支撑。




