遇见数据集

DynIoT-DDoS: a mobility-aware, multi-attack DDoS detection dataset for Smart City IoT

收藏
Zenodo2026-07-27 更新2026-08-02 收录
官方服务:

资源简介:

DynIoT-DDoS is a mobility-aware benchmark dataset for DDoS detection in Smart City IoT, generated with the NS-3 network simulator (v3.43). Unlike existing IoT intrusion-detection benchmarks, which record traffic from stationary topologies, DynIoT-DDoS captures a mobile IoT agent traversing a spatially heterogeneous field of 61 fixed nodes. As the agent moves, its neighbour count, and therefore its legitimate traffic, rises and falls continuously. Attacks are context-triggered: each malicious node transmits only while the mobile agent is inside its 20 m radio range, so adversarial traffic co-occurs with the legitimate, mobility-induced surge. This operationalises the flash-crowd ambiguity for a node in motion. Contents. Two complementary views derived from the same 184 simulation runs: a per-second time-series view of 11,084 labelled samples (18 columns) and a per-flow view of 795,683 records (14 columns, CICFlowMeter-style features) spanning 184 scenarios, balanced across four context-triggered attack types (UDP, TCP and ICMP floods, and MAC-layer channel jamming; 46 scenarios each). Scenario grid: start offset d ∈ {0, 20, 40} m, movement angle α in 15° steps, attacker count n ∈ {1, 3, 5}, along-path spacing s ∈ {8, 24} m. Features comprise four spatial-context attributes (position, movement angle, start offset, instantaneous node density) and four network-activity counters measured on the mobile agent's own interface, plus two oracle columns that document label derivation and must be excluded from training. Evaluation note. Rows within a scenario are temporally autocorrelated; always group by Scenario_ID (e.g. scikit-learn GroupKFold). A random row-wise split leaks near-duplicate rows into the test set and inflates scores. Caveats. Simulation-based, not validated against physical testbeds. The 72% attack prevalence follows from deliberate on-path attacker placement and represents a worst-case adversarial workload rather than a deployment-typical base rate. A single density-gradient topology and straight-line, constant-speed trajectories are used. Physical layer is IEEE 802.11n ad hoc (IBSS) only. A reproduction script is included that regenerates the reference detection and ablation results under leakage-free, scenario-grouped 5-fold cross-validation.

提供机构:
Zenodo
创建时间:
2026-07-27
二维码
社区交流群
二维码
科研交流群
商业服务