HybRID-18: a realistic and feature-rich intrusion detection dataset for machine learning benchmarking
摘要
The growing sophistication of cyber threats has intensified the need for robust and realistic datasets to train and evaluate machine learning-based intrusion detection systems (IDS). Existing benchmark datasets–such as NSL-KDD, CICIDS 2017, UNSW-NB15, and ToN-IoT are often constrained by outdated attack scenarios, synthetic traffic artifacts, and imbalanced class distributions, limiting their effectiveness in real-world deployments. In this paper, we introduce HybRID-18, a novel, feature-rich network traffic dataset that addresses these limitations by integrating both real-world and emulated traffic across Internet of Things (IoT) and conventional network environments. HybRID-18 captures 18 diverse attack types and extracts 84 detailed flow-based features using tools like Wireshark and CICFlowMeter. Experimental validation using ML models, Random Forest, Support Vector Machine (SVM), Decision Tree, Multi-Layer Perceptron (MLP), and Long Short-Term Memory (LSTM), demonstrates superior detection performance, achieving a peak accuracy of 99.95% with LSTM. Compared to existing benchmarks, HybRID-18 consistently improves precision, recall, F1-score, and AUC-ROC, particularly for challenging attack classes such as zero-day and IoT-based threats. Its balanced class distribution, high realism, and detailed feature engineering make it a valuable benchmark for advancing IDS research. Future work will expand attack coverage, incorporate adversarial scenarios, and refine feature selection to further improve model generalizability.