[1] WANG Z H, FOK K W, THING V L L. Machine learning for encrypted malicious traffic detection: approaches, datasets and comparative study[J]. Computers & Security, 2022, 113: 102542. [2] 李志远, 吴安昊, 谭林, 等. 基于流序列特征融合与注意力机制的加密流量分类方法[J]. 小型微型计算机系统, 2025, 46(7): 1718-1726. LI Z Y, WU A H, TAN L, et al. Stream sequence feature fusion and attention mechanism based method for encrypted traffic classification[J]. Journal of Chinese Computer Systems, 2025, 46(7): 1718-1726. (in Chinese) [3] LIN K D, XU X L, GAO H H. TSCRNN: a novel classification scheme of encrypted traffic based on flow spatiotemporal features for efficient management of IIoT[J]. Computer Networks, 2021, 190: 107974. [4] PAPADOGIANNAKI E, IOANNIDIS S. A survey on encrypted network traffic analysis applications, techniques, and countermeasures[J]. ACM Computing Surveys, 2022, 54(6): 1-35. [5] 陈子涵, 程光, 徐子恒, 等. 互联网加密流量检测、分类与识别研究综述[J]. 计算机学报, 2023, 46(5): 1060-1085. CHEN Z H, CHENG G, XU Z H, et al. A survey on Internet encrypted traffic detection, classification and identification[J]. Chinese Journal of Computers, 2023, 46(5): 1060-1085. (in Chinese) [6] 康鹏, 杨文忠, 马红桥. TLS协议恶意加密流量识别研究综述[J]. 计算机工程与应用, 2022, 58(12): 1-11. KANG P, YANG W Z, MA H Q. TLS malicious encrypted traffic identification research[J]. Computer Engineering and Applications, 2022, 58(12): 1-11. (in Chinese) [7] 侯剑, 鲁辉, 刘方爱, 等. 加密恶意流量检测及对抗综述[J]. 软件学报, 2024, 35(1): 333-355. HOU J, LU H, LIU F A, et al. Detection and countermeasure of encrypted malicious traffic: a survey[J]. Journal of Software, 2024, 35(1): 333-355. (in Chinese) [8] 付钰, 刘涛涛, 王坤, 等. 基于机器学习的加密流量分类研究综述[J]. 通信学报, 2025, 46(1): 167-191. FU Y, LIU T T, WANG K, et al. Survey of research on encrypted traffic classification based on machine learning[J]. Journal on Communications, 2025, 46(1): 167-191. (in Chinese) [9] SHEKHAWAT A S, DI TROIA F, STAMP M. Feature analysis of encrypted malicious traffic[J]. Expert Systems with Applications, 2019, 125: 130-141. [10] ANDERSON B, MCGREW D. Identifying encrypted malware traffic with contextual flow data[C]//Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security. New York,USA:ACM Press,2016: 35-46. [11] WENG Z Q, CHEN T M, ZHU T T, et al. TLSmell: direct identification on malicious HTTPs encryption traffic with simple connection-specific indicators[J]. Computer Systems Science and Engineering, 2021, 37(1): 105-119. [12] YU T D, ZOU F T, LI L S, et al. An encrypted malicious traffic detection system based on neural network[C]//Proceedings of the International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC). Washington D.C.,USA:IEEE Press,2020: 62-70. [13] CHEN L C, GAO S, LIU B X, et al. THS-IDPC: a three-stage hierarchical sampling method based on improved density peaks clustering algorithm for encrypted malicious traffic detection[J]. The Journal of Supercomputing, 2020, 76(9): 7489-7518. [14] LIU J Y, ZENG Y Z, SHI J Y, et al. MalDetect: a structure of encrypted malware traffic detection[J]. Computers, Materials & Continua, 2019, 60(2): 721-739. [15] WANG W, ZHU M, ZENG X W, et al. Malware traffic classification using convolutional neural network for representation learning[C]//Proceedings of the International Conference on Information Networking (ICOIN). Washington D.C.,USA:IEEE Press,2017: 712-717. [16] ZHU S Z, XU X L, GAO H H, et al. CMTSNN: a deep learning model for multiclassification of abnormal and encrypted traffic of Internet of Things[J]. IEEE Internet of Things Journal, 2023, 10(13): 11773-11791. [17] 蒋彤彤, 尹魏昕, 蔡冰, 等. 基于层次时空特征与多头注意力的恶意加密流量识别[J]. 计算机工程, 2021, 47(7): 101-108. JIANG T T, YIN W X, CAI B, et al. Encrypted malicious traffic identification based on hierarchical spatiotemporal feature and multi-head attention[J]. Computer Engineering, 2021, 47(7): 101-108. (in Chinese) [18] LIN X J, XIONG G, GOU G P, et al. ET-BERT: a contextualized datagram representation with pre-training transformers for encrypted traffic classification[C]//Proceedings of the ACM Web Conference 2022. New York,USA:ACM Press,2022: 633-642. [19] DEVLIN J, CHANG M W, LEE K, et al. BERT: pre-training of deep bidirectional transformers for language understanding[EB/OL].[2024-12-05]. https://arxiv.org/abs/1810.04805. [20] 赵键锦, 李祺, 刘胜利, 等. 面向6G流量监控: 基于图神经网络的加密恶意流量检测方法[J]. 中国科学(信息科学), 2022, 52(2): 270-286. ZHAO J J, LI Q, LIU S L, et al. Towards traffic supervision in 6G: a graph neural network-based encrypted malicious traffic detection method[J]. Science in China (Information Sciences), 2022, 52(2): 270-286. (in Chinese) [21] ACETO G, CIUONZO D, MONTIERI A, et al. DISTILLER: encrypted traffic classification via multimodal multitask deep learning[J]. Journal of Network and Computer Applications, 2021, 183: 102985. [22] BADER O, LICHY A, HAJAJ C, et al. MalDIST: from encrypted traffic classification to malware traffic detection and classification[C]//Proceedings of the IEEE 19th Annual Consumer Communications & Networking Conference (CCNC). Washington D.C.,USA:IEEE Press,2022: 527-533. [23] 谷勇浩, 徐昊, 张晓青. 基于多粒度表征学习的加密恶意流量检测[J]. 计算机学报, 2023, 46(9): 1888-1899. GU Y H, XU H, ZHANG X Q. Multi-granularity representation learning for encrypted malicious traffic detection[J]. Chinese Journal of Computers, 2023, 46(9): 1888-1899. (in Chinese) [24] SHEN M, YE K, LIU X T, et al. Machine learning-powered encrypted network traffic analysis: a comprehensive survey[J]. IEEE Communications Surveys & Tutorials, 2023, 25(1): 791-824. [25] VASWANI A, SHAZEER N, PARMAR N, et al. Attention is all you need[EB/OL].[2024-12-05]. https://arxiv.org/abs/1706.03762. [26] HE H Y, YANG Z G, CHEN X N. PERT: payload encoding representation from transformer for encrypted traffic classification[C]//Proceedings of the ITU Kaleidoscope: Industry-Driven Digital Transformation (ITU K). Washington D.C.,USA:IEEE Press,2020: 1-8. [27] WU Y H, SCHUSTER M, CHEN Z F, et al. Google’s neural machine translation system: bridging the gap between human and machine translation[EB/OL].[2024-12-05]. https://arxiv.org/abs/1609.08144. [28] SHARMA A, KREIBICH C, WALA F B, et al. Zeek[EB/OL].[2024-12-05].https://download.zeek.org/zeek-6.0.4.tar.gz. [29] KADAVATH S, CONERLY T, ASKELL A, et al. Language models (mostly) know what they know[EB/OL].[2024-12-05].https://arxiv.org/abs/2207.05221. [30] NETO E C P, DADKHAH S, FERREIRA R, et al. CICIoT2023: a real-time dataset and benchmark for large-scale attacks in IoT environment[J]. Sensors, 2023, 23(13): 5941. [31] VAN EDE T, BORTOLAMEOTTI R, CONTINELLA A, et al. FlowPrint: semi-supervised mobile-App fingerprinting on encrypted network traffic[EB/OL].[2024-12-05]. https://www.ndss-symposium.org/ndss-paper/flowprint-semi-supervised-mobile-app-fingerprinting-on-encrypted-network-traffic/. [32] SHARAFALDIN I, HABIBI L A, GHORBANI A A. Toward generating a new intrusion detection dataset and intrusion traffic characterization[EB/OL].[2024-12-05]. http://cs.unb.ca/research-expo/expos/2018/submissions/20180403-14-56-isharafa-at-unb.ca-toward_generating_a_new_intrusion_detection_dataset_and_intrusion_traffic_characterization.pdf. [33] LIU C, WANG W Y, WANG M, et al. An efficient instance selection algorithm to reconstruct training set for support vector machine[J]. Knowledge-Based Systems, 2017, 116: 58-73. [34] NKORO E C, NWAKANMA C I, LEE J M, et al. Detecting cyberthreats in Metaverse learning platforms using an explainable DNN[J]. Internet of Things, 2024, 25: 101046. |