A comprehensive system for generating realistic, labeled MQTT attack logs from the client perspective for IoT-SIEM and log anomaly detection research. This tool addresses the gap between existing network-level attack datasets (PCAPs) and application-level syslogs needed for SIEM analysis.
This system implements the Hybrid Approach for MQTT log generation, combining:
- Instrumented Victim Clients - MQTT clients with built-in attack detection and syslog generation
- Attack Simulators - Multiple attack scenario generators (DoS, DDoS, Malformed Packets, etc.)
- Log Collector - Centralized log aggregation in multiple formats (JSON, CSV, syslog)
- Orchestrator - Automated experiment coordination with timeline labeling
Unlike existing tools that produce PCAPs or broker-side logs, this system generates:
- ✅ Application-level syslogs from client perspective
- ✅ Attack detection indicators (connection failures, resource exhaustion, malformed packets)
- ✅ Labeled datasets with precise attack timelines
- ✅ Multiple formats (syslog, JSON, CSV) for SIEM ingestion
- ✅ Normal baseline traffic for comparison
┌─────────────────────────────────────────┐
│ Attack Simulator │
│ - DoS/DDoS attacks │
│ - Malformed packets │
│ - Topic enumeration │
│ - Authentication attacks │
└──────────────┬──────────────────────────┘
│
↓ (attacks)
┌─────────────────────────────────────────┐
│ Victim MQTT Clients (Instrumented) │
│ - Detect attack patterns │
│ - Generate syslogs │
│ - Publish logs to MQTT topics │
└──────────────┬──────────────────────────┘
│
↓
┌─────────────────────────────────────────┐
│ MQTT Broker (Mosquitto) │
│ Topics: syslog/#, logs/# │
└──────────────┬──────────────────────────┘
│
↓
┌─────────────────────────────────────────┐
│ Log Collector │
│ - Aggregates all logs │
│ - Outputs: JSON, CSV, syslog │
│ - Generates statistics │
└─────────────────────────────────────────┘
The instrumented clients detect and log:
-
DoS Attacks
- Rapid connection failures
- CPU/Memory exhaustion
- Message flooding (>50 msg/s)
-
Malformed Packets
- Oversized payloads (>1MB)
- Non-ASCII topics
- Null bytes in payloads
- Malformed JSON
- Deep topic hierarchies (>10 levels)
-
Topic Enumeration
- Excessive subscriptions (>50 topics)
- Wildcard abuse
-
Resource Exhaustion
- CPU usage monitoring
- Memory usage monitoring
- Baseline deviation detection
- DoS Connection Flood - Rapid connect/disconnect to exhaust broker resources
- DoS Message Flood - High-rate message publishing to overwhelm subscribers
- DoS Large Payload - Sending multi-MB messages to exhaust bandwidth/memory
- DDoS Distributed Flood - Multiple attackers simultaneously flooding
- Malformed Packet Injection - Crafted packets with unusual characteristics
- Topic Enumeration - Reconnaissance via wildcard subscriptions
- Slowloris Attack - Slow connections to exhaust connection pool
- Authentication Brute Force - Password guessing attacks
- Python 3.7 or higher
- Linux system (tested on Ubuntu 20.04+)
- MQTT broker (Mosquitto recommended)
# Clone or navigate to the directory
cd /home/kevin/LogBERTVADE/Mqtt_generator
# Run setup script (installs dependencies and Mosquitto if needed)
./setup.sh
# Activate virtual environment
source venv/bin/activate# Install Mosquitto broker
sudo apt-get update
sudo apt-get install mosquitto mosquitto-clients
sudo systemctl enable mosquitto
sudo systemctl start mosquitto
# Create Python virtual environment
python3 -m venv venv
source venv/bin/activate
# Install Python dependencies
pip install -r requirements.txtRun the orchestrator to execute all attack scenarios with automatic labeling:
source venv/bin/activate
python orchestrator.pyThis will:
- Start the log collector
- Deploy victim MQTT clients
- Generate normal baseline traffic
- Execute all enabled attack scenarios in sequence
- Generate labeled dataset with attack timelines
- Save logs in multiple formats
Output location: /tmp/mqtt_logs/
Files generated:
mqtt_logs_TIMESTAMP.json- All logs in JSON formatmqtt_logs_TIMESTAMP.csv- Tabular format for analysismqtt_logs_TIMESTAMP.syslog- Standard syslog formatmqtt_logs_{severity}_TIMESTAMP.json- Severity-specific logsattack_labels.json- Attack timeline and labels
python mqtt_client_logger.py# DoS message flood
python attack_simulator.py --attack dos_message --topic test/target --duration 60
# DDoS distributed attack
python attack_simulator.py --attack ddos --topic test/target --duration 120
# All attacks in sequence
python attack_simulator.py --attack allpython log_collector.py --broker localhost --port 1883 --output /tmp/mqtt_logsEdit config.yaml to customize:
# Enable/disable specific attacks
attack_scenarios:
dos_connection_flood:
enabled: true
duration: 60
connection_rate: 10
# Adjust victim client count
victim_clients:
count: 5
# Change experiment parameters
experiment:
duration: 600
include_normal_traffic: trueThen run:
python orchestrator.py --config config.yamlJan 15 10:23:45 iot_device_001 mqtt_client: ALERT - DoS attack detected - rapid connection failures | {"type": "DoS", "indicator": "rapid_connection_failures", "failures": 7, "time_window": 8.3}
Jan 15 10:23:46 iot_device_002 mqtt_client: ALERT - Malformed or suspicious MQTT packet received | {"type": "MalformedPacket", "indicators": ["oversized_payload"], "topic": "test/target", "payload_size": 1048577}
{
"timestamp": "2026-01-15T10:23:45.123456",
"client_id": "iot_device_001",
"severity": "ALERT",
"message": "Message flooding attack detected",
"broker": "localhost:1883",
"attack_details": {
"type": "Flooding",
"indicator": "high_message_rate",
"rate_per_second": 127.5,
"threshold": 50
}
}timestamp,client_id,severity,message,broker,attack_type,attack_details
2026-01-15T10:23:45.123456,iot_device_001,ALERT,DoS attack detected,localhost:1883,DoS,"{""type"": ""DoS"", ""indicator"": ""cpu_exhaustion""}"# Analyze collected logs
python log_collector.py --analyze /tmp/mqtt_logs/mqtt_logs_20260115_102345.jsonOutput includes:
- Total log count
- Severity distribution
- Attack type distribution
- Client distribution
- Time-based statistics
- Average log rate
The generated logs can be ingested into:
- ELK Stack (Elasticsearch, Logstash, Kibana)
- Splunk
- Graylog
- Wazuh
- AlienVault OSSIM
Example Logstash configuration:
input {
file {
path => "/tmp/mqtt_logs/*.syslog"
type => "mqtt_syslog"
}
}
filter {
grok {
match => { "message" => "%{SYSLOGTIMESTAMP:timestamp} %{SYSLOGHOST:client_id} %{SYSLOGPROG:program}: %{LOGLEVEL:severity} - %{GREEDYDATA:log_message}" }
}
}
output {
elasticsearch {
hosts => ["localhost:9200"]
index => "mqtt-logs-%{+YYYY.MM.dd}"
}
}A typical full experiment generates:
- Duration: ~10-15 minutes
- Log count: 1,000 - 10,000+ logs
- Attack logs: 30-50% of total
- Normal logs: 50-70% of total
- Unique attack types: 8 scenarios
- File size:
- JSON: 1-10 MB
- CSV: 500 KB - 5 MB
- Syslog: 500 KB - 5 MB
The attack_labels.json file provides precise attack timelines:
{
"experiment_name": "mqtt_attack_dataset_generation",
"start_time": "2026-01-15T10:00:00.000000",
"total_duration": 645.3,
"attack_labels": [
{
"attack_name": "normal_traffic",
"start_time": "2026-01-15T10:00:00.000000",
"start_timestamp": 0.0,
"duration": 60,
"details": {
"type": "normal",
"description": "Baseline normal MQTT traffic"
}
},
{
"attack_name": "dos_connection_flood",
"start_time": "2026-01-15T10:01:00.123456",
"start_timestamp": 60.123,
"duration": 60,
"details": {
"enabled": true,
"duration": 60,
"connection_rate": 10
}
}
]
}This tool is designed for:
- IoT-SIEM Development - Training and testing SIEM systems on IoT-specific attacks
- Log Anomaly Detection - Training ML models (LogBERT, DeepLog, etc.) on labeled attack logs
- Attack Pattern Analysis - Studying client-side manifestations of network attacks
- Intrusion Detection Systems - Developing signature-based or anomaly-based IDS
- Dataset Generation - Creating reproducible, labeled datasets for research
| Dataset/Tool | Output Type | Perspective | Labels | Client Logs |
|---|---|---|---|---|
| IoT-Flock | PCAP | Network | No | ❌ |
| MQTTset | PCAP + CSV | Network | Yes | ❌ |
| MQTT-IoT-IDS2020 | PCAP | Network | Yes | ❌ |
| Broker Logs | JSON audit | Broker | Partial | ❌ |
| This Tool | Syslog/JSON/CSV | Client | Yes | ✅ |
# Check if broker is running
systemctl status mosquitto
# Test connectivity
mosquitto_sub -h localhost -t test &
mosquitto_pub -h localhost -t test -m "test"
# Check broker with orchestrator
python orchestrator.py --check-broker# Ensure output directory is writable
mkdir -p /tmp/mqtt_logs
chmod 777 /tmp/mqtt_logs
# Or change output directory in config.yamlThis is expected during attack scenarios (especially DDoS). To reduce:
- Decrease
num_attackersin DDoS scenarios - Reduce
messages_per_secondin flood attacks - Lower
victim_clients.count
- Verify broker is running
- Check victim clients connected successfully
- Ensure log collector subscribed to correct topics
- Check
/tmp/mqtt_client_*.logfor client-side logs
Create custom attack scripts:
from attack_simulator import MQTTAttackSimulator
simulator = MQTTAttackSimulator("localhost", 1883)
# Custom attack logic
def custom_attack():
client = simulator._create_client("custom_attacker")
client.connect("localhost", 1883)
# Your attack logic here
custom_attack()You can run IoT-Flock attacks alongside this system:
- Run victim clients with this tool
- Run IoT-Flock attacks against the broker
- Victim clients will detect and log the attacks
- Collect logs with log collector
Add custom detection logic to mqtt_client_logger.py:
def detect_custom_attack(self) -> Optional[Dict[str, Any]]:
# Your detection logic
if suspicious_condition:
return {
"type": "CustomAttack",
"indicator": "custom_indicator",
"details": {...}
}
return None# config.yaml
victim_clients:
count: 100 # More victims
attack_scenarios:
ddos_distributed:
num_attackers: 200 # More attackersvictim_clients:
count: 2
attack_scenarios:
dos_message_flood:
messages_per_second: 20 # Lower rate
ddos_distributed:
num_attackers: 10 # Fewer attackersIf you use this tool in your research, please cite:
@software{mqtt_log_generator,
title = {MQTT Attack Log Generator for IoT-SIEM Research},
author = {Your Name},
year = {2026},
description = {Application-level MQTT attack log generation from client perspective}
}- IoT-Flock: Network-level IoT attack traffic generation
- MQTTset: MQTT attack dataset (PCAP format)
- MQTT-IoT-IDS2020: Labeled MQTT intrusion dataset
- CICFlowmeter: Network flow feature extraction
- LogBERT: Log anomaly detection using BERT
Contributions welcome! Areas for enhancement:
- Additional attack scenarios (replay attacks, certificate attacks)
- More sophisticated detection algorithms
- Integration with additional SIEM platforms
- Performance optimizations
- Additional output formats
MIT License - Free for research and educational use
For issues, questions, or collaboration:
- Open an issue on GitHub
- Contact: [your email]
This tool was developed to address the gap in IoT-SIEM research datasets, specifically the lack of application-level client logs for MQTT attack scenarios. It complements existing network-level datasets by providing the client perspective necessary for comprehensive SIEM analysis.