Network Intrusion Datasets: A Survey, Limitations, and Recommendations
arXiv:2502.06688 · doi:10.1016/j.cose.2025.104510
Abstract
Data-driven cyberthreat detection has become a crucial defense technique in modern cybersecurity. Network defense, supported by Network Intrusion Detection Systems (NIDSs), has also increasingly adopted data-driven approaches, leading to greater reliance on data. Despite the importance of data, its scarcity has long been recognized as a major obstacle in NIDS research. In response, the community has published many new datasets recently. However, many of them remain largely unknown and unanalyzed, leaving researchers uncertain about their suitability for specific use cases. In this paper, we aim to address this knowledge gap by performing a systematic literature review (SLR) of 89 public datasets for NIDS research. Each dataset is comparatively analyzed across 13 key properties, and its potential applications are outlined. Beyond the review, we also discuss domain-specific challenges and common data limitations to facilitate a critical view on data quality. To aid in data selection, we conduct a dataset popularity analysis in contemporary state-of-the-art NIDS research. Furthermore, the paper presents best practices for dataset selection, generation, and usage. By providing a comprehensive overview of the domain and its data, this work aims to guide future research toward improving data quality and the robustness of NIDS solutions.
42 pages, 8 figures, 6 tables. Accepted version for the journal Computers & Security
References in corpus (14)
- Shortcut Learning in Deep Neural Networks
- A Survey of Network-based Intrusion Detection Data Sets
- IGRF-RFE: A Hybrid Feature Selection Method for MLP-based Network Intrusion Detection on UNSW-NB15 Dataset
- The Role of Machine Learning in Cybersecurity
- A Survey on Industrial Control System Testbeds and Datasets for Security Research
- Supervised Feature Selection Techniques in Network Intrusion Detection: a Critical Review
- SCADA System Testbed for Cybersecurity Research Using Machine Learning Approach
- Nori: Concealing the Concealed Identifier in 5G
- Evaluating Standard Feature Sets Towards Increased Generalisability and Explainability of ML-based Network Intrusion Detection
- Survey of Network Intrusion Detection Methods from the Perspective of the Knowledge Discovery in Databases Process
- NetML: A Challenge for Network Traffic Analytics
- Benchmarking the Benchmark -- Analysis of Synthetic NIDS Datasets
- Data-Driven Network Intrusion Detection: A Taxonomy of Challenges and Methods
- Using Large Language Models to Enrich the Documentation of Datasets for Machine Learning