DARPA 1999 IDS Evaluation Data Set is the most common publicly available data set for intrusion detection. It consists of 5 sets from capturing the activities in a simulated environment. Those sets represent 5 weeks of the capturing process. The first and third week are attack free and usually used for training the intrusion detection, while the second, fourth, and fifth contain malicious traffic. This data set contains raw traffic data, stored in PCAP file. If you prefer to have the preprocessed version, there is KDD 1999 Cup Dataset which has preprocessed raw network traffic from DARPA 1998 Data Set and stores them in CSV files. However, those data sets might be obsolete, since they are now 18 years old. So, I found other data sets for intrusion detection that contain the raw network traffic and list them here.
This dataset contains 7 days of network traffic and stores them in PCAP format. The labels are stored individually in an XML format. I made a simple script to separate the malicious and benign traffic from a PCAP file. If you need the dataset, just email the author and they will give you temporary access to download the PCAP files.
This dataset consists of 2 days recorded traffic which has 100 GB. Apart from the PCAP files, the author also provides preprocessed CSV files, results from BRO and Argus.
This dataset contains HTTP traffic from various shellcode. It also has the traffic of morphed shellcodes. You can download and run their proposed IDS as well.
A set of 11 GB packet header traces, stored in PCAP format and anonymised.
Other interesting data sets
These data sets do not necessarily contain raw network traffic, but could still be useful for IDS related research.
ADFA Intrusion Detection Data Set (For Host-based IDS)