Security Datasets for Intrusion Detection and Prevention: A Structured Review and Dataset-Selection Framework
| dc.contributor.author | Guler, Hakan | |
| dc.contributor.author | Boyaci, Aytug | |
| dc.contributor.author | Ulas, Mustafa | |
| dc.date.accessioned | 2026-09-08T07:11:53Z | |
| dc.date.issued | 2026 | |
| dc.department | Fırat Üniveristesi | |
| dc.description.abstract | Security datasets are central to the evaluation of intrusion detection and prevention systems, but their suitability differs substantially across domains, data sources, attack scenarios, labeling practices, and reproducibility conditions. This study presents a structured evidence-mapping review of security datasets reported in intrusion detection and prevention research between 2018 and 2025. The final evidence map includes 42 primary dataset-use publication records, 82 dataset or evidence-source mentions, and 69 unique datasets, corpora, or evidence sources after duplicate, retracted, and irrelevant records were removed. The review organizes datasets across network-based IDS, IPS, firewall, VPN, WAF, endpoint, email filtering, IAM, DDoS, Windows, Linux-Apache, NetFlow, cloud, and IoT/IIoT security settings. In addition to adoption-frequency analysis, the study assesses representative dataset families in terms of documentation, labeling information, feature representation, class balance, public availability, reproducibility, and practical usability limitations. The findings show that established benchmarks remain widely reused, but recent studies increasingly rely on domain-specific datasets for IoT/IIoT, DDoS, cloud, edge, host, and cyber-physical environments. The review also proposes and illustrates a dataset-selection framework that links dataset choice to security objectives, operational context, telemetry requirements, attack coverage, and evaluation protocol. The results support more transparent, context-aware, and reproducible dataset selection for intrusion detection and prevention research. | |
| dc.description.sponsorship | Firat University [MF.26.91] -- This study was supported by the Firat University Scientific Research Projects Coordination Unit under the Comprehensive Research Project program, with project number MF.26.91 titled Systematic Analysis of Data Sets Used in Cybersecurity and Artificial Intelligence Systems. | |
| dc.identifier.doi | 10.3390/app16157473 | |
| dc.identifier.issn | 2076-3417 | |
| dc.identifier.issue | 15 | |
| dc.identifier.scopus | 2-s2.0-105047225001 | |
| dc.identifier.scopusquality | Q1 | |
| dc.identifier.uri | https://doi.org/10.3390/app16157473 | |
| dc.identifier.uri | https://hdl.handle.net/11508/65202 | |
| dc.identifier.volume | 16 | |
| dc.identifier.wos | WOS:001846667500001 | |
| dc.identifier.wosquality | Q2 | |
| dc.indekslendigikaynak | Web of Science | |
| dc.indekslendigikaynak | Scopus | |
| dc.language.iso | en | |
| dc.publisher | Mdpi | |
| dc.relation.ispartof | Applied Sciences-Basel | |
| dc.relation.publicationcategory | Makale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı | |
| dc.rights | info:eu-repo/semantics/openAccess | |
| dc.snmz | KA_WOS_20250903 | |
| dc.subject | Security Datasets | |
| dc.subject | Intrusion Detection | |
| dc.subject | Intrusion Prevention | |
| dc.subject | Dataset Selection | |
| dc.subject | Cybersecurity Benchmarking | |
| dc.title | Security Datasets for Intrusion Detection and Prevention: A Structured Review and Dataset-Selection Framework | |
| dc.type | Review Article |







