Orion 2026: An IP Flow Dataset for Network Traffic Analysis and DDoS Intrusion Detection
Abstract
The development of robust, modern network threat detection models is often hindered by the limitations of existing benchmark datasets. These often suffer from traffic class imbalance, poor documentation, and pervasive mislabeling. To address the identified gaps, this article introduces the Orion 2026, a novel benchmark dataset generated within an emulated network environment utilizing a spine-leaf topology. The proposed dataset incorporates 120 hours of traffic that mirrors the real-world diurnal volume variations observed at the Internet Exchange Point (IXP) of Londrina, Brazil, and includes eight single-source and distributed denial-of-service attack vectors with varying attacker-victim cardinalities. The collected data is evaluated through an exploratory data analysis that reduces the extracted attributes to 17 mutually non-redundant features without recourse to labels, and through five detection models spanning the supervised and semi-supervised paradigms. The results indicate that this subset suffices to separate malicious from legitimate flows. By providing comprehensive documentation, raw data captures, and a suggested train-test split, the Orion 2026 offers a flexible resource to streamline reproducible tests in the development of intrusion detection solutions.