CIC-YNU-IoTMal: A comprehensive multilayer dataset for static and dynamic analysis of IoT malware behavior
Sajjad Dadkhah, Ogobuchi Daniel Okey, Sebin Abraham Maret, Yen-Wu Lo, Amir Firouzi, Ryu Kuki, Takayuki Sasaki, Katsunari Yoshioka, Tao Ban, Seiichi Ozawa, Ali Akbar Ghorbani · Information Systems · 2026
Malware continues to pose a critical security threat to the Internet of Things (IoT) ecosystem, driven by the diversity and dynamics of network environments. These conditions introduce significant vulnerabilities, rendering IoT devices prime targets for sophisticated malware attacks. Honeypots have been employed to emulate IoT devices and generate comprehensive malware datasets, enabling the development of adaptive defense systems. However, existing approaches often rely solely on static or dynamic analysis, which fails to keep pace with the evolving nature of malware. Moreover, rigorous detection requires high-fidelity datasets that reflect real-world threats, yet publicly available, multi-architecture IoT malware datasets with recent signatures remain scarce. To address this gap, we present CIC-YNU-IoTMal, a well-researched dataset integrating static and dynamic malware behaviors. Leveraging IoTPOT data and simulated IoT devices, we captured raw network packets, system calls, and system activity logs. Specifically, 10,000 malware binaries were executed on simulated IoT devices within Docker containers and sandbox environments tailored to each architecture. The pipeline processes ARM, MIPS, MIPSEL, and x86 architectures, collecting network traffic (PCAP), system traces (STRACE), and system statistics (SAR). These files were converted to CSV, analyzed, and used to train machine learning algorithms for malware classification. CIC-YNU-IoTMal comprises 2.4M PCAP, 1.8M SAR, and 105M STRACE samples across architectures, representing families such as Mirai, Bashlite (Gafgyt), DarkNexus, Rudedevil, Agent, Generic, and Tsunami. Experimental validation demonstrates that dynamic malware behaviors can be effectively tracked and detected. CIC-YNU-IoTMal2026 is publicly available, advancing research toward a more secure IoT environment.