Descriptor: UNSW IoT Traffic Data with Packets, Flows, and Protocols (UNSW-IoTraffic)
Savindu Wannigama, Arunan Sivanathan, Hassan Habibi Gharakheili · IEEE data descriptions. · 2025
This work describes UNSW IoT traffic data (UNSW-IoTraffic), a dataset comprising (a) raw network packet traces with full headers and payload, (b) flow-level metadata summarizing fine-grained bidirectional activity behaviors, and (c) protocol parameters describing network protocol characteristics. It also provides protocol data models for six dominant protocols (TLS, HTTP, DNS, DHCP, SSDP, and NTP). In addition, the dataset includes scripts for statistical summarization, visualization using state diagrams, and device fingerprinting using machine learning. The dataset contains 95.5 million packets of IoT communications captured over 203 days, organized into 27 per-device packet capture (PCAP) files. Derived flow data, categorized based on the 5-tuple attributes (source IP address, destination IP address, transport-layer protocol number, source port number, destination port number), are provided as 27 per-device CSV files. Finally, protocol-specific parameters for 70% flows are extracted and written into 450 CSV files across 27 device types, covering 25 protocols, each with request and response data. The three-level structure of our dataset, which encompasses packets, flows, and protocols, caters to a diverse range of users, from students learning data networking concepts to experienced researchers and industry professionals. It enables the behavioral analysis of consumer IoT devices, the detection of temporal anomalies, and the validation of protocols.